explain_rule
Retrieve the reasoning behind any detection rule: what it flags, why it matters, which audit it came from, and what it ignores. Read-only and offline.
Instructions
Return the reasoning behind one of the seven rules: what it detects, why it matters, the audit it came from, and what it deliberately does not fire on. Offline and read-only.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| rule | Yes | The rule identifier, as it appears in findings. |