BLOCKED while the standalone finding still stands.
CLI
--mode CONFIRMED_ONLY|CONFIRMED_AND_LIKELY|INCLUDE_UNKNOWN--current/--blocked/--unknown/--critical/--shortest
--predictive— predictive surface signals (not findings)--what-if SCENARIO— counterfactual against the graph--diff PATH_A PATH_B— compare two savedattack-paths.jsonfiles (see Security Diff)
0. Soft-run during axguard audit.
Path statuses
CONFIRMED · LIKELY · UNVERIFIED · INVALID · BLOCKED
A path’s status follows its weakest hop plus barrier state. Unknown reachability stays UNVERIFIED — never a public exploit claim.
MCP
Slash command:
/axguard-paths.