| Code-level flaw, needs source analysis | secure-code-review | Source code available, injection/logic/auth pattern |
| Needs PoC development or exploit chain | exploit-validation | Suspected finding, S1-S2, needs confirmation |
| Insufficient info, attack surface unclear | indepth-recon-analysis | Missing context, needs enumeration |
| Server/infra configuration issue | web-misconfig-review | Headers, TLS, CORS, directory exposure |
| API-specific vulnerability | api-security-review | REST/GraphQL/WebSocket endpoint |
| Dependency or supply chain issue | dependency-and-secret-audit | CVE in library, outdated package, leaked secret |
| Cloud infrastructure misconfiguration | cloud-config-audit | IAM, storage, network, compute finding |
| Container or K8s issue | container-and-runtime-security | Image vuln, escape path, pod misconfiguration |
| CI/CD pipeline risk | ci-cd-supply-chain-security | Pipeline config, artifact integrity, registry |
| Mobile app finding | mobile-security-assessment | APK/IPA, mobile API, certificate pinning |
| AD/identity infrastructure | active-directory-and-identity-audit | Kerberos, LDAP, Azure AD finding |
| Network segmentation or infra | network-infrastructure-pentest | Firewall, VLAN, protocol-level finding |
| Architecture/design risk | threat-modeling | Design flaw, missing control, trust boundary |
| Fully validated, evidence complete | evidence-and-reporting | Confirmed + evidence + remediation clear |