ee3f9b8aaa
Risk tier is now derived from the worst validation issue severity and the issues that drove it travel with the summary, so consumers can show operators why a tier was assigned instead of an opaque level. - Add RiskSummary.rationale (defaulted, backward-compatible) holding human-readable '[code] message' lines from the validation report - Pin severity -> risk mapping: ERROR->HIGH, WARNING->MEDIUM, INFO->LOW - DefaultRiskAssessor folds the validation-driven level into the summary