--- name: attack-path-assess description: Assess evidenced blast radius and potential CIA consequences while keeping business ratings unresolved without an approved impact profile. --- # Consequence assessment Count distinct assets and services along supported route segments only. State coverage limits. Link potential confidentiality, integrity, or availability effects only to supported `read`, `modify`, or `disrupt` capabilities. Treat the business owner, service mapping, crown-jewel priority, CIA objectives, and impact thresholds as user inputs. The current release emits `unrated`; do not claim a NIST rating until a specified publication and organization-approved profile with criterion citations is installed. Record missing inputs under G5. Use the impact reviewer in `agents/impact-reviewer.md` only for a bounded advisory interpretation.