Domain-adaptive priming
Read the target artifact and preview the priming pass's derived, target-grounded attack plan before committing a run — warm context made visible. Each hypothesis cites a real endpoint/function, not a generic category.
A live preview runs one operator-triggered priming call. The per-hypothesis toggle is client-side selection; steering an edited plan into a run needs a launcher derived_plan seam (follow-up).