2026-09-23T0405Z-intel
One pipeline fire, in full · intel run of 2026-09-23 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-23/2026-09-23T0405Z-intel.md.
Run telemetry
- Items returned
- 4
- Duration
- 7m 53s
- Tool calls
- 4 WebFetch5 WebSearch20 bridge
- Cited sources
- 5 of 25 in slice
- Items returned
- 4
- Duration
- 7m 41s
- Tool calls
- 0 WebFetch2 WebSearch24 bridge
- Cited sources
- 3 of 29 in slice
- Items returned
- 2
- Duration
- 11m 06s
- Tool calls
- 15 WebFetch9 WebSearch20 bridge
- Cited sources
- 2 of 15 in slice
- Items returned
- 0
- Duration
- 4m 19s
- Tool calls
- 15 WebSearch9 bridge
- Cited sources
- 0 of 4 in slice
Verification
Deep dive
2026-09-23/gambit-ai-agent-retail-skimmer-campaign-strix-cairn-hermes
Entries this run published (8) and updated (2)
- CVE-2026-67279 / CVE-2026-86060, MikroTik RouterOS "MikroTrick": an SSH rekey-during- authentication state-confusion bypass chained with a crafted-username privilege escalation reaches unauthenticated full device takeover, actively exploited vulnerability critical correction
- Check Point Quantum Security Gateway / Management Server / Spark Firewall: two unauthenticated CVSS 9.8 pre-auth RCE flaws in VPN certificate processing (CVE-2026-85103 heap overflow, CVE-2026-85102 improper cert validation) vulnerability critical update
- CVE-2026-93616, Check Point Security Management: pre-authentication path traversal to arbitrary script execution, exploited as a zero-day since July (CVSS 9.8) vulnerability critical
- CVE-2026-93952, Arista VeloCloud Orchestrator: actively exploited, two release trains still have no fix vulnerability critical
- CVE-2026-94127, F5 BIG-IP APM: unauthenticated heap overflow in OAuth-profile processing reaches RCE on the TMM data plane (CVSS 9.8) vulnerability critical
- EU Court of Auditors: cyber-incident cooperation framework only partially effective, cross-border notification failed for the 2025 airport ransomware disruption policy notable
- Austria's NISG 2026 creates the Bundesamt für Cybersicherheit, 24h/72h incident-reporting clock live 1 October 2026 policy notable
- NCSC Switzerland: Google recovery-address abuse plus a Sites-hosted phishing page plants an OAuth app-password backdoor that survives a password reset threat routine
- Open-source AI pentesting harnesses (Strix, Cairn, Hermes) run an autonomous intrusion-and-skimmer campaign against online retailers for about $25 a target threat high
- Virtualizor VPS/hypervisor control panel: a login-page guard's own exemption for act=login lets an unauthenticated attacker reach root vulnerability high
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
No source-list edits recorded for this run.
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
| Source (uncovered) | URL tried | Method chain | Status / class | What the agent did instead |
|---|---|---|---|---|
| f5-my-f5-com covered via alternate · should NOT be in this list | https://my.f5.com/manage/s/article/K000162605 | bridge:extract → bridge:jina | 200 content-free-extract Salesforce Lightning community page returns only a loading-shell placeholder via both trafilatura extraction and the jina reader, the article never hydrated in | Corroborated every load-bearing quote via CERT-EU Security Advisory 2026-013 (national-CERT-class primary quoting F5 directly) plus two independent secondary wr |
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 12 findings (truth=9, editorial=1, advisory=2) · Claude Sonnet 5 · 14m 18s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | CVE-2026-85102 epss set to 0.33; FIRST.org's live API returns 0.003290000 | epss corrected to 0.0033 | |
| F4 hallucinated-fact | · | Gambit entry claimed Cloudflare involvement and 'repeatedly rebuilt' infrastructure; not in Gambit's own primary | sentence rewritten to match Gambit's own primary text (Shadowserver Foundation, Daniel Gordon, other industry partners) | |
| F4 hallucinated-fact | · | F5 entry claimed 'Appliance mode' is also vulnerable; unsupported by any of the entry's three cited sources | claim removed | |
| F4 hallucinated-fact | · | Arista entry's techniques[] carried T1543.002, supported only by an IOC excluded per no-IOC policy | T1543.002 removed from techniques[] | |
| F4 hallucinated-fact | · | Gambit entry's techniques[] carried T1189, naming no behavior distinct from T1659 already listed | T1189 removed from techniques[] | |
| F3 claim-not-supported | · | Gambit entry named 'Google Tag Manager'; primary describes the gtag.js global-site-tag snippet, a different product | corrected to gtag.js global-site-tag terminology | |
| F3 claim-not-supported | · | Check Point entry characterized CVE-2026-91843 as a 'stack-overflow' flaw; not stated by any of the entry's four cited sources | characterization removed, entry now names only the CVE id | |
| F5 missing-citation | · | Gambit entry's 79%/no-Swiss-cards claim lacked an inline citation; verifier could not find the figure in the standard text extraction of the primary | verified the figure is a literal HTML table in the primary page (recovered via raw-HTML fetch, not the standard extraction), added an inline citation and a sour | |
| F4 hallucinated-fact | · | MikroTrick correction record's fields list omitted 'sources', though sources[] changed this run (4 MITRE URLs removed, CERT Polska technical-analysis URL added) | added 'sources' to the record's fields list | |
| F14 ? | · | (low confidence) Gambit entry said Hermes was previously observed in 'two' unrelated intrusions; entities/registry.yaml records a third (actor:knaithe-knyuan) | verified against the registry; corrected to three prior intrusions (four total including this one) throughout the entry and the tool:hermes-ai-agent registry su | |
| F11 editorial-advisory | · | Run record's Verification & coverage notes used workflow-internal language (sub-agent labels, a memory-file path, PD-number shorthand) | notes rewritten in plain language | |
| F11 editorial-advisory | · | Run record's notes used 'single-source-other', not a valid verification enum value | corrected to plain-language description matching the entry's own valid 'single-source' value |
Iteration #2 NEEDS_FIXES · 8 findings (truth=3, editorial=4, advisory=1) · Claude Sonnet 5 · 11m 47s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F5 missing-citation | · | Arista entry's CVE-2026-16812/Security Advisory 0144/2026-07-27 detail carried no inline citation | re-fetched The Hacker News' 2026-07-28 article directly, added it as a corroborating source and an inline citation | |
| F5 missing-citation | · | Gambit entry's 'three unrelated intrusions' claim (Thailand, Taiwan, the knaithe/KnYuan campaign) was uncited | added dates and a citation for the third case, and added references[] linking the three prior store entries | |
| F4 hallucinated-fact | · | Virtualizor entry's body-quoted VulnCheck line carried an extra closing parenthesis not in the source | typo corrected | |
| F4 hallucinated-fact | · | Virtualizor entry stated 'VulnCheck reports no exploitation in the wild', overstating VulnCheck's actual silence on ITW status into an affirmative claim | reworded to state VulnCheck's post does not address ITW status, and added the omitted detail that VulnCheck published a public automated exploit module | |
| F3 claim-not-supported | · | EU ECA entry attributed the naming of Germany, Belgium and Ireland to the Court's own report text; the report's case study does not name the three states, heise online's reporting does | re-fetched heise's article directly, corrected the attribution to heise with an inline citation and evidence[] record | |
| F8 needs-more-research | · | Virtualizor entry omitted that VulnCheck published a public, automated exploit module (go-exploit) for this CVSS 9.8 unauthenticated root RCE | added the detail to the body and the poc-public tag/CVE status | |
| F6 strengthen-primary-source | · | (low confidence) Virtualizor entry's CVSS scores are sourced to NVD in the sourcing_note but NVD is not in sources[] and could not be verified by the verifier's own transports | independently re-verified all three CVSS scores directly against the NVD CVE 2.0 API (confirmed exact match: 9.8/9.3, 8.1/9.2, 7.5/8.7); sourcing_note clarified | |
| F11 editorial-advisory | · | 'sub-agent' still appeared once in the run record's Verification & coverage notes despite iteration 1's fix | remaining instance corrected to plain language |
Iteration #3 NEEDS_FIXES · 5 findings (truth=3, editorial=1, advisory=1) · Claude Sonnet 5 · 10m 45s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F9 surface-contradiction | · | Gambit's own primary states two unreconciled skimmer-victim counts ('five' and '19 of 27'); the entry silently used only 19 with no disclosure | added a Contradiction note to the run record explaining the primary's internal inconsistency and why the larger, dedicated-section figure was used | |
| F4 hallucinated-fact | · | Gambit entry's framing of the Thailand and Taiwan prior intrusions as 'apparently state-nexus' overstated both entries' own hedged attribution language | reworded to reflect each entry's own hedging (Thailand: low-to-medium-confidence assessment, not a firm nexus; Taiwan: a state-adjacent contractor/patriotic-hac | |
| F4 hallucinated-fact | · | (low confidence) NCSC-CH entry's evidence[] original field spliced the end of one HTML list item with the start of the next, dropping that item's own trailing sentence with no ellipsis | re-fetched the raw page, split into two separate evidence[] records respecting the list-item boundary, and adjusted the body quote to match | |
| F3 claim-not-supported | · | (low confidence) Gambit entry cited '(Unit 42, 2026-07-31)' but Unit 42's article is dated 2026-07-30; 2026-07-31 was the referenced store entry's own folder date, cited in a format implying it was th | corrected to the source's actual date (2026-07-30) and changed to a plain cross-reference to the existing entry rather than an inline external citation not fetc | |
| F11 editorial-advisory | · | Six new product registry entities created this run were not linked back via entities[] in the entries that name them | added the corresponding product entity key to each entry's entities[] field |
Iteration #4 NEEDS_FIXES · 7 findings (truth=5, editorial=0, advisory=2) · Claude Sonnet 5 · 11m 42s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | Gambit entry framed the knaithe/KnYuan operator behind the Unit 42 NetScaler campaign as a 'China-nexus exploit operator', inconsistent with the hedging just applied to the Thailand and Taiwan cases a | reworded to 'a self-described Zhuhai-based, Chinese-speaking operator... with no firm state-nexus attribution established', matching the referenced entry's own | |
| F4 hallucinated-fact | · | Virtualizor entry's frontmatter summary still stated 'no exploitation in the wild is reported' after iteration 2 had already corrected the body to note VulnCheck's post is silent on ITW status (not af | summary reworded to match the already-corrected body | |
| F4 hallucinated-fact | · | checkpoint-quantum-vpn update record's fields list omitted 'sourcing_note', though sourcing_note text changed this run (added the 2026-09-22 exploitation-confirmation sourcing detail) | added 'sourcing_note' to the record's fields list | |
| F4 hallucinated-fact | · | NCSC-CH entry's affected_products[] included 'Google Workspace'; the cited advisory and evidence describe only a personal Google account compromise, with Workspace named nowhere in the source | removed 'Google Workspace' from affected_products[], leaving 'Google Account' | |
| F15 ? | · | Arista entry's entities[] referenced 'product:arista-velocloud-orchestrator-vco-on-prem', a new registry key created this run for the same real-world product as the pre-existing 'product:arista-velocl | tombstoned the new key with merged_into pointing to the canonical older key, added the new key's name as an alias on the canonical record, and retargeted the en | |
| F8 needs-more-research | · | (advisory) Virtualizor entry's cves[] carried only CVSS3.1 scores; NVD's CVE 2.0 API record for each id also carries a CVSS4.0 score, consistent with this run's own convention of listing both versions | queried the NVD CVE 2.0 API directly for all three ids (9.8/9.3, 8.1/9.2, 7.5/8.7, confirmed exact match with iteration 2's independent verification), added the | |
| F11 editorial-advisory | · | (advisory) Check Point entry's entities[] linked only product:check-point-smartevent; the other four affected_products[] values (Security Management Server, Multi-Domain Security Management Server, Lo | added all four corresponding product entity keys to the entry's entities[] field |
Iteration #5 NEEDS_FIXES · 5 findings (truth=3, editorial=2, advisory=0) · Claude Sonnet 5 · 9m 25s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | F5 BIG-IP entry's body inline-cited a quote to CERT-EU, but that exact text is not on CERT-EU's page; it is verbatim from SecurityOnline, which the entry's own evidence[] block already correctly attri | corrected the inline citation to SecurityOnline / Daily CyberSecurity | |
| F4 hallucinated-fact | · | F5 BIG-IP entry invented an 'OAuth Authorization Server role' vs 'OAuth Client/Resource Server' distinction (in summary, immediate_action, cves[].affected, actions[] and body); none of the entry's fou | removed the invented role qualifier from all five locations, leaving the precondition as sources actually state it | |
| F5 missing-citation | · | (editorial) Check Point 93616 entry's LivePatch Take 28/29 / CVE-2026-91843 clause carried no inline citation, though the entry's own corroborating source (The Hacker News) states it | added the inline citation | |
| F5 missing-citation | · | (editorial) NCSC-CH entry's Triage section claimed 'the Workspace admin console can disable legacy app passwords organization-wide'; the entry's sole source describes only a personal-account compromis | reworded to generic Google-account guidance, removing the unsupported Workspace-specific claim | |
| F3 claim-not-supported | · | (low confidence) Virtualizor entry's body named the file carrying the mis-scoped act=login guard as enduser/index.php; re-fetching VulnCheck's primary directly confirmed its own Fix section and 'The e | corrected to enduser/admin.php at the guard description; left the source's own index.php phrasing intact in the separate php-fpm-pool paragraph, where it mirror |
Iteration #6 NEEDS_FIXES · 6 findings (truth=2, editorial=3, advisory=1) · Claude Sonnet 5 · 10m 10s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | Check Point 93616 entry's Detection-concept/Triage text invented a 'must correlate two signals' requirement and a 'routine misconfiguration' hedge, contradicting sk1000171, which treats its second ind | rewrote the Detection concept and Triage text to match the advisory's own two-indicator structure: the first indicator requires its own internal username+core-d | |
| F5 missing-citation | · | (editorial) EU ECA entry's four-airport disruption clause and the WannaCry/NotPetya/no-large-scale-since-2016/recommendations sentence both lacked their own inline citations, despite being separately | added inline citations to both, quoting the report's own text directly; also caught and corrected an inaccuracy of my own found while re-verifying; the recommen | |
| F5 missing-citation | · | (editorial, low confidence, merged with the finding above) same clause | covered by the same fix | |
| F18 ? | · | Arista entry's actions[] hedged with 'consider switching to PSK-based Edge authentication' and substantially restated the body's own Hardening sentence | split into two concrete, non-hedged, non-restating actions: patch the fixed trains now; restrict web-interface access on the unpatched trains now, dropped the h | |
| F11 editorial-advisory | · | (advisory, low confidence) Virtualizor entry's evidence[] quote about the act=login guard was verbatim only in the source page's SEO meta-description tag, not in the visible article body | replaced with a genuine visible-body quote stating the same fact ('the redirect that guards the admin panel fires for every action except one. That one is `logi | |
| F15 ? | · | (low confidence) entities/registry.yaml carried two pre-existing, un-tombstoned duplicate Check Point product keys (with/without the '-server' suffix: security-management and multi-domain-security-man | tombstoned both non-'-server' keys with merged_into pointing to their '-server' counterparts (Check Point's own advisory uses the '-server' names, and they are |
Iteration #7 NEEDS_FIXES · 2 findings (truth=1, editorial=1, advisory=0) · Claude Sonnet 5 · 10m 04s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | (low confidence) Arista entry stated as settled fact that 'PSK-mode deployments are not exposed to this flaw'; Arista's advisory never mentions PSK/Certificate-Deactivated mode, and the entry's own co | reworded both the immediate_action and body mentions to attribute the PSK-mode exemption to the advisory's own certificate-based precondition rather than a vend | |
| F8 needs-more-research | · | MikroTrick entry's own cited source (CERT Polska's technical analysis) states CVE-2026-67277 AND CVE-2026-86060 were both added to CISA KEV on 2026-09-10; the entry's frontmatter (cves[].status, top-l | added cisa-kev to CVE-2026-86060's (and, discovered while fixing, CVE-2026-67277's, which was also missing it) status array, added the cisa-kev tag at the top l |
Iteration #8 NEEDS_FIXES cap-breach · 5 findings (truth=1, editorial=1, advisory=3) · Claude Sonnet 5 · 8m 49s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | Virtualizor entry overstated VulnCheck's exploit module as a published, publicly available weaponization (tags[]/cves[].status carried poc-public, body said 'a fully automated, publicly available weap | removed poc-public from tags[] and cves[0].status[], reworded summary and body to describe an internal exploit module built on the publicly available go-exploit | |
| F5 missing-citation | · | (editorial) Austria NISG entry: a sentence on BCS's GovCERT/HealthCERT/CERT.at oversight and sector scope, and the closing sentence on district-authority enforcement, both carried no inline citation d | added inline citations to both sentences | |
| F11 editorial-advisory | · | (advisory) checkpoint-quantum-vpn entry (updated this run) had empty entities[] despite three affected_products[] values having exact-name registry keys; the same defect iteration 4 fixed on the sibli | linked all three product entity keys in entities[], added 'entities' to the update record's fields list | |
| F11 editorial-advisory | · | (advisory) Gambit entry omitted product:wordpress from entities[] despite an exact-name key and WordPress's role in the body | added product:wordpress to entities[] | |
| F11 editorial-advisory | · | (advisory, low confidence, pre-existing) MikroTrick entry omitted product:mikrotik-routeros from entities[] | added product:mikrotik-routeros to entities[], added 'entities' to the correction record's fields list |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-09-23T0405Z-intel · Sonnet 5 · window 25.92 h · 8 entries published
Verification & coverage notes
8 new entries, 2 updates, 1 deep dive. All three CISA KEV additions this run's mechanical sweep found without existing coverage (CVE-2026-93616, CVE-2026-93952, CVE-2026-94127) were published as new critical entries; a fourth in-window KEV addition, CVE-2026-85102, was already covered and shipped as an update record elevating that entry to critical. One parallel research task's first attempt was terminated mid-flight by a content-safety classifier reacting to raw advisory text (a known false-positive pattern); a retry with clearer defensive framing succeeded cleanly.
Duration note: this run's total elapsed time (~3.2 h) exceeds the usual range. The cause is the verification loop itself, not a stall: eight successive verification passes each found genuine, fixable defects (an inconsistent attribution hedge, an uncited detail, an overstated exploit-availability claim, unlinked entity references, a missing CISA KEV cross-reference, among others) and every finding across all eight iterations was remediated in place before the next pass or before publish; none was left unfixed. The loop reached its 8-iteration cap without achieving the double-CLEAN confirmation and published fail-open per the cap rule; verification_residual_count (2) is the capped final iteration's own truth+editorial tally at the moment it ran, logged for the audit trail as the rules require; it is not a count of unresolved content, since that iteration's findings were also fixed before this commit.
Correction: 2026-09-06/mikrotik-routeros-mikrotrick-ssh-auth-bypass-privesc-chain; CERT Polska's own 2026-09-22 technical write-up states plainly that CVE-2026-67276 was wrongly associated with the actively-exploited MikroTrick chain in earlier reporting (including this entry's own original text, which quoted CERT Polska's 2026-09-05 post describing it as the signature-forgery entry point). The real entry point is CVE-2026-67279 (SSH rekey-during-authentication state confusion). Corrected title, summary, both CVEs' exploitation status, and the body's mechanism description; does not float the entry (a correction, not a new development).
Deep dive: 2026-09-23/gambit-ai-agent-retail-skimmer-campaign-strix-cairn-hermes. Selected over the three same-day critical CVEs, which are single-flaw vendor disclosures already carrying full vendor-supplied detection guidance and did not need extended kill-chain treatment; this finding instead offered a substantive, fully-reconstructed multi-stage attack chain. Two claims from the corroborating secondary outlet were excluded from the entry because they do not appear in the primary research: a claim naming an additional AI model in the harness stack, and a payment-processor fraud-flag statistic. Specific attacker domains, a file hash and IP addresses present in the primary research were not reproduced, consistent with this pipeline's no-IOC policy.
Note on CVE-2026-93952 (Arista VeloCloud Orchestrator): the vendor advisory's indicator-of-compromise section (file paths, a file hash, two IP addresses) was not reproduced, consistent with the no-IOC policy.
Contradiction: Gambit Security's own primary research states two different counts for how many websites carried a live skimmer ("five" in its opening summary and "19 of 27" in its dedicated results section) without reconciling them. The retail-skimmer campaign entry uses the larger, more precise, dedicated-section figure (19 of 27), which a second outlet's reporting also uses independently.
Coverage backlog (the queue of previously-surfaced items awaiting corroboration): all 9 open items were re-checked; no material change on 8 of them. One item (a Bern hospital group's ServiceNow migration delay, sourced to a single paywalled article) is recommended for closure as unresolvable: over 20 consecutive daily checks since 2026-08-30 have hit the identical access block with zero independent corroboration found anywhere; it can be reopened if the article or a corroborating source becomes reachable.
Dropped as out of scope: a Bavarian university's disclosure of a roughly 52,000-record data exfiltration, no Swiss nexus, and no source names a mechanism or actor, so the finding could not carry an evidence-bound technique mapping; noted for awareness only, since several structurally identical items are already in the backlog. Also dropped: a leak-site defacement in an inter-gang extortion feud, genuinely fresh, but with no victim-facing technique, no constituency nexus and no detection lever.
Single-source entries: 2026-09-23/ncsc-ch-google-recovery-oauth-app-password-persistence (the national-CERT carve-out, NCSC Switzerland's own weekly advisory). 2026-09-23/gambit-ai-agent-retail-skimmer-campaign-strix-cairn-hermes (the research vendor is the sole technical assessor; the corroborating outlet reports on those findings rather than independently assessing the campaign). 2026-09-23/virtualizor-billing-hook-unauth-root-rce (the discovering researcher is also the CVE-assigning authority; no independent second analysis has been published yet).
Fetch gap: F5's own advisory (my.f5.com K000162605) is a client-rendered SPA unreachable via extract or jina (loading-shell only on both transports); covered via CERT-EU's Security Advisory 2026-013 (national-CERT-class primary quoting F5 directly) plus two independent secondaries quoting the same text.
Watchlist: products checked=0, hits=0; suppliers checked=0, hits=0, no product or supplier watchlist configured this deployment.
Coverage gaps: cert-at (403 on both attempted URLs, no working alternate found this run); dcod-ch (homepage is a static dashboard, not an article listing); csa-labs and paradigm-shift-research (both republish disclosures 3–7 days old under a fresh display date; recommend future runs treat their displayed date as a republish timestamp, not a recency signal, and always verify against the linked primary).
← Operations dashboard · run-record contract: docs/pipeline.md