Disciplined investigation of unknowns in any context — codebases, tools, APIs, incidents, claims. Auto-load when the task is to investigate, research, verify, audit, or answer "why/how/whether" questions; when uncertainty exists about how a system behaves; or when findings will feed a decision. Enforces explicit hypotheses, disconfirming evidence, primary-source verification (code > docs > memory), explicit epistemic status labels (verified / inferred / hypothesis / requires verification), date-stamping of volatile findings, digest-form output, and explicit stopping criteria so research converges into action.