Cross-Surface Corroboration

After N findings — how much should I trust each one?

Every other AgentSmack meta-lens grades a DIFFERENT axis — the kill-chain chains stages into a path, the risk register ranks by exploitability, control-coverage grades defense layers, false-positive grades benign over-flagging. None grades the orthogonal axis a CISO actually asks after seeing a wall of findings: how much should I TRUST each one? Corroboration is the answer. When prompt-check, the harness data-exfil-lineage, AND the egress scanner all independently fail on the same underlying OWASP weakness (e.g. LLM02 sensitive-info-disclosure), that triple-confirmation is high-confidence. A finding that fires on ONE surface while a corroborating surface — one whose assessable scope includes that risk — was run-and-clean is contested (a possible false positive, surfaced for review, never silently suppressed). A lone finding on a risk no other present surface can assess is isolated. A surface absent from the input is UNKNOWN (default-deny): it can neither manufacture confirmation nor launder a finding out of attention. Duplicate findings from one surface count as one corroborator — distinct surfaces only. It consumes the same cross-surface findings envelope every scan emits, reuses the canonical OWASP mapping verbatim, and adds no new surface and no new scorecard dimension. The more lenses you've run, the more confidently this can confirm — or contest — each finding. Load a sample to watch the confidence grade with no live infra.

Related read-only meta-lenses over the same findings envelope: Attack-Path / Kill-Chain · Risk Register.