The False Positive Adversary challenges Judge outcomes. It searches for counter-evidence and control effectiveness so triage prefers real bugs over volume.

CLI

Soft-run during axguard audit. Diagnostic exit 0.

Outcomes

Post-adversary statuses include: CONFIRMED · LIKELY · UNVERIFIED · FALSE_POSITIVE · REQUIRES_REVIEW The adversary does not invent “SAFE” without evidence, and it does not replace hunters.

When to use it

  • Too many findings after scan / audit
  • Agent or human triage (/axguard-triage) needs structured pushback
  • Before treating a LIKELY as a ship blocker

MCP

Use evidence tools after adversary / review:
  • axguard_get_counter_evidence
  • axguard_get_evidence / axguard_get_evidence_chain
Slash command: /axguard-adversary.