The Investigation agent deepens a suspicious candidate under a budget: gather evidence, explore related paths, and produce an investigation artifact — without inventing exploits.

CLI

Best-effort artifacts under .findings/axguard/investigation/ (also soft-run from audit when available).

MCP

Agent guidance

From skill axguard-security: after axguard_security_review, call axguard_investigate on suspicious / incomplete findings before declaring ship-ready. Keep predictive risks out of the verified count.