Predictive security surfaces risk expansion signals from observable change (PR/diff shape, architecture shifts, agent/MCP surface). It is explicitly not a confirmed vulnerability report.

CLI

Also: axguard paths . --predictive for graph-adjacent predictive hooks.

MCP

Rules for agents and CI

  • Label output as predictive / risk, never merge into verified finding counts
  • Do not fail a release on predictive-only noise unless you deliberately choose to
  • After fixes, verify with axguard_verify_fix / re-audit — predictive closure is not resolution