The Security Twin is a symbolic security architecture snapshot: controls, privileges, trust boundaries, and related structure you can query, compare, and stress with counterfactuals.

CLI

Artifacts land under the configured out directory (see twin docs in the repo: docs/twin/).

MCP

Important

What-if results are simulated — not live exploits. Twin analysis complements, and does not replace, verified findings from scan / audit / Judge.