EVAL-018: job3 shipped, 46/46 findings verified, 20/23 fixes applied (B1 blocked on sentinel scope, D2-D5+B6 skipped by decision), zero residual on final re-sweep. LRN-105: explorer subagents need an explicit ban on executing the subject-under-test's own CLI, not just "read-only" framing (caught mid-run: a subagent ran `graphify .`).