AI security agents are moving from passive summarizers to decision helpers, but they still inherit the same fractured inputs that make vulnerability triage hard to trust.