Skip to main content
Use the SDK to retrieve vulnerabilities, review their details, and update their status and assignment. Vulnerabilities remain available after a run finishes. Your code works with the same vulnerabilities your team sees in the platform, including updates made by people and agents as remediation progresses.

List vulnerabilities

Call antigen.vulnerabilities.list() to retrieve vulnerabilities across your organization’s runs:
Filters apply together. This example returns vulnerabilities that are both critical and open. Omit the filters to include all severities and statuses.

Vulnerabilities from a run

Use the run’s collection to retrieve vulnerabilities associated with that run:
The returned vulnerabilities reflect their current status and assignment. A report preserves the results captured at the time it was written.

Read a vulnerability

Retrieve a vulnerability by its ID to inspect its description and supporting information:
The description explains the weakness and the affected system. Supporting evidence shows what the agent observed and helps your team reproduce the issue. See Evidence for retrieving requests, responses, screenshots, and other artifacts associated with a vulnerability.

Assign work

A vulnerability can be assigned to a team member or a registered agent. To assign it to a team member, pass their email address:
To use the pre-built remediation-agent, pass its SDK constant:
With the default remediation hook enabled, this assignment starts a run to prepare remediation steps.

Assign a custom agent

Pass the name of an agent your team has registered:
The assignment triggers an event for your configured webhooks. Your handler can retrieve the vulnerability and launch the agent when it is ready to start work. See Assigning to your own agents for registration and webhook setup.

Remove an assignment

Pass null to leave the vulnerability unassigned:

Update status

Use antigen.vulnerabilities.updateStatus() as work progresses:
Assign a person or agent before moving a vulnerability to in_progress. Accepting risk requires a note explaining the decision and an expiration time.

Request verification

Once the fix is deployed, move the vulnerability to remediated:
With the default verification hook enabled, this starts a tCell run to test the original exploit again. A successful verification moves the vulnerability to verified. If the exploit still succeeds, the vulnerability returns to open with new evidence. Merging a pull request may be one step toward remediation. Move the vulnerability to remediated when the fix is deployed to the affected system. The verified status is set through verification. It cannot be assigned directly with updateStatus().

Work on a vulnerability in a run

You can also retrieve a vulnerability and pass it directly to an agent:
This is the same pattern your webhook handler can use after an assignment event. See Runs for following progress and retrieving results.

Status and assignment hooks

Changes made through the SDK trigger the same hooks as changes made in the platform. Status-change events include the previous and new statuses. Assignment-change events include the previous and new assignees. Your service can use these values to decide what to do next. The update completes when the change has been saved. Work started by a hook, such as a remediation or verification run, continues separately.