Risk Register
Across your whole campaign — what do I fix first?
Every other AgentSmack meta-layer stops one step short of the literal CISO question. The scorecard rolls surfaces into a number; fix-impact ranks surfaces; the kill-chain rates the chain; the remediation generator lists fixes only within a surface group. None answer: here is the single ordered list of what to fix first, each item scored on one defensible axis, flagged when it anchors a confirmed attack chain. This is that artifact. It consumes the same cross-surface findings envelope every scan emits and emits an exploitability-ranked remediation roadmap — each failed finding scored 0-100 on a closed, integer-only formula (severity · hard-blocker · chain-anchor · blast-radius breadth), severity and paste-able fix inherited verbatim from the remediation generator so the closed vocabulary cannot drift. A standalone critical hard blocker still gets a score (it ranks near the top even with no chain); a finding that both stands alone AND anchors a confirmed chain scores sticky-maximal (an adversary cannot reorder the queue by adding noise). It adds no new surface and no new scorecard dimension — a pure ranking OVER the others. Load a sample to watch the queue rank with no live infra.
Related read-only meta-lenses over the same findings envelope: Remediation Plan · Attack-Path / Kill-Chain · Cross-Surface Corroboration · Cyber-Risk Quantification (ALE) · Whole-Stack CI Governance Gate · Behavioral Safety Fingerprint.