feat(docs): Add comprehensive documentation for Vexer, Vulnerability Explorer, and Zastava modules
- Introduced AGENTS.md, README.md, TASKS.md, and implementation_plan.md for Vexer, detailing mission, responsibilities, key components, and operational notes. - Established similar documentation structure for Vulnerability Explorer and Zastava modules, including their respective workflows, integrations, and observability notes. - Created risk scoring profiles documentation outlining the core workflow, factor model, governance, and deliverables. - Ensured all modules adhere to the Aggregation-Only Contract and maintain determinism and provenance in outputs.
This commit is contained in:
		
							
								
								
									
										22
									
								
								docs/modules/advisory-ai/AGENTS.md
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										22
									
								
								docs/modules/advisory-ai/AGENTS.md
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,22 @@ | ||||
| # Advisory AI agent guide | ||||
|  | ||||
| ## Mission | ||||
| Advisory AI is the retrieval-augmented assistant that synthesizes advisory and VEX evidence into operator-ready summaries, conflict explanations, and remediation plans with strict provenance. | ||||
|  | ||||
| ## Key docs | ||||
| - [Module README](./README.md) | ||||
| - [Architecture](./architecture.md) | ||||
| - [Implementation plan](./implementation_plan.md) | ||||
| - [Task board](./TASKS.md) | ||||
|  | ||||
| ## How to get started | ||||
| 1. Review ./architecture.md for retrieval pipeline, guardrails, and profile support. | ||||
| 2. Open ../../implplan/SPRINTS.md and locate stories for this component. | ||||
| 3. Check ./TASKS.md and update status before/after work. | ||||
| 4. Read README/architecture for design context and update as the implementation evolves. | ||||
|  | ||||
| ## Guardrails | ||||
| - Uphold Aggregation-Only Contract boundaries when consuming ingestion data. | ||||
| - Preserve determinism and provenance in all derived outputs. | ||||
| - Document offline/air-gap pathways for any new feature. | ||||
| - Update telemetry/observability assets alongside feature work. | ||||
		Reference in New Issue
	
	Block a user