Skip to main content
When an agent confirms an exploitable security weakness during a run, it creates a vulnerability with a description, severity, and supporting evidence. A vulnerability stays available after the run ends. Your team and agents can update its status, assignment, and evidence as they investigate the issue, prepare a fix, and verify the result.

Review a vulnerability

Open Vulnerabilities in the platform to view your vulnerabilities as a board or a list. Select a vulnerability to review:
  • Description: what the issue is and which systems it affects.
  • Severity: how serious the issue is.
  • Evidence: the requests, responses, screenshots, or other artifacts that demonstrate the weakness.
  • Status and assignment: where the work stands and who or which agent is responsible.
A vulnerability can have multiple evidence items. Together, they help your team understand and reproduce the issue.

Track the work

The vulnerability’s status, assignment, and supporting evidence can change as work progresses. For example, a remediation agent can prepare a fix, and a later run can add evidence showing whether that fix resolved the issue. These updates stay attached to the vulnerability, so your team can follow the work from the original discovery through verification. Hooks can trigger this work automatically. Your team reviews proposed changes and handles work that needs human input. See the vulnerability lifecycle for how statuses, assignments, and hooks coordinate this work.

Vulnerabilities in reports

A report captures the vulnerabilities and evidence relevant to an engagement at the time it is written. The report preserves those results while the vulnerabilities continue through their lifecycle.