CLI
.findings/axguard/investigation/ (also soft-run from audit when available).
MCP
Agent guidance
From skillaxguard-security: after axguard_security_review, call axguard_investigate on suspicious / incomplete findings before declaring ship-ready. Keep predictive risks out of the verified count.