Second-pass vulnerability research on a CVE or GHSA that already has a working PoC workspace. Use when Codex needs to verify whether a patch can still be bypassed, detect spread to related codebases, or escalate a NEW_ATTACK_SURFACE finding into the next exploit-generation cycle.