Breaks permission models by finding functions that violate the contract's own guard patterns — attacker-style exploitation of inconsistent guards, initialization hijacks, privilege escalation, confused deputies and delegatecall abuse, backed by the consistency-principle detection algorithm (state interaction matrix, guard dependency graph, anomaly detection with confidence thresholds). Use when auditing access control, missing requires, forgotten modifiers, or inconsistent pause/admin checks.