Judge is the verification stage after hunters run on candidates from scan / dataflow. It assigns a structured verdict AXguard owns — agents should not “declare vulnerable” without this path.

CLI

Soft-run during axguard audit. Diagnostic exit 0.

Verdicts

MCP

  • axguard_verify_finding — Hunter→Judge style check for one candidate
  • axguard_verify_fix — after a fix: RESOLVED / STILL_PRESENT / REGRESSED by fingerprint (approval-gated; never resolve on path rename alone)

Pipeline position

Slash command: /axguard-verify. Next stage: False Positive Adversary.