Reads the failing code path during a live incident and produces a fast, ranked set of hypotheses with the cheapest check for each and the safest next action — so a leader can direct the response or dig in without thrashing. Optimised for speed and honesty under pressure, not completeness. Use when the user says "help me debug this incident", "what's causing this outage", "read this stack trace / error / code path", or is triaging a production failure in real time. Use this to form a hypothesis mid-incident — use incident-stakeholder-comms to update people during it, and incident-postmortem to analyse root cause after it's resolved.