Add `flags` to the vulnerability struct for post-analyzer processing (!9)