Give every exploit agent the same status, confidence, severity-reasoning, report-writing, credential-handling, and
scope contract.
Apply the same task-formation and SAST-enrichment procedure to the Miscellaneous lane.
Parse Agentic SAST SARIF into typed observations, enrich and route those observations, and reconcile them with pentest findings before exploitation.
Publish deterministic exploitation queues with stable lineage, exact-path Git commits, retry-safe manifests, named drop reasons, and confined task formation. Reject duplicate producer IDs before commit and adopt either legal provenance shape after a lost acknowledgement.