--- name: attack-path-trace description: Trace conditional routes from a supplied finding to a user-defined crown jewel in an evidence-linked local graph. --- # Path tracing Require a user-defined crown-jewel identifier and an identified starting finding. Use only scoped, time-compatible, typed relationships. A reachable or dependent asset is not automatically controlled. Keep `supported_structural` paths separate from `candidate` paths with missing capabilities or hypothetical relationships. Neither class confirms exploitation. Use G3 and G4 outputs in the JSON report. Cite every step's evidence ID and source pointer; keep excluded and partial paths with reasons. Do not replace a failed prerequisite with prose or agent judgment. See `docs/gates.md` for path and ranking rules.