Orchestrator for a source-to-sink static application security testing (SAST) engagement. Use this FIRST when asked to security-review, audit, or SAST a codebase. Defines scope, recon, the taint model, run order for the per-class detection skills, and how findings are written to per-vulnerability files before the final aggregated attack-chaining report.