Review a workspace for software-supply-chain evidence relevant to SBOM and EU Cyber Resilience Act readiness. Check for machine-readable SBOMs, CycloneDX, SPDX, lockfiles, VEX/CSAF, vulnerability-disclosure evidence, provenance or attestations, and release records. Receive a deterministic Review Priority with clear guidance on what to review next. The workflow is local and read-only and does not certify compliance.