The grounded surface path (Stage 5d) is validated live: against an absence-vuln
fixture it flags cra-ai-11 (unprotected login), cra-ai-24 (unlogged admin action),
and cra-ai-28/29/30 (unverified firmware update), each grounded + control-tagged.
- LUT: promote the 8 absence-based controls (cra-ai-6,11,12,24,27,28,29,30)
needs_tooling -> covered (grounded-control-check binding). CRA coverage is now
21 covered / 0 needs_tooling / 19 not_code_checkable.
- Enable both advanced LLM passes by default: semantic_mapping (validated in C5)
and grounded_control_checks (validated here). Both were gated only for cost /
verification; the GPU is in-house so cost isn't a constraint. Still no-ops
unless breakpilot base_url is set and the catalog is reachable.
- Gated regression tests (ignored, not run by CI --lib): c5_example2.rs (semantic,
4 varied vulns) and grounded_surface_live.rs (Stage 5d validation).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>