## 1. Detector Policy - [x] 1.1 Split Xai context-before and context-after alternatives into uniquely named single-regex detector entries. - [x] 1.2 Split ZaiGLM context-before and context-after alternatives into uniquely named single-regex detector entries. - [x] 1.3 Canonicalize the compatibility-only detector names before persistence and candidate extraction. ## 2. Compatibility Coverage - [x] 2.1 Add pure unit coverage for detector policy structure and canonical alias normalization. - [x] 2.2 Add an optional real-TruffleHog CLI regression test for both context directions and candidate routing. ## 3. Verification - [x] 3.1 Run the focused provider and scanner unit tests. - [x] 3.2 Run the real CLI compatibility test with the current Windows binary and a Linux binary where available. - [x] 3.3 Validate the OpenSpec change and confirm the patch is formatting-clean.