Skip to main content
Each vulnerability has a status and can be assigned to a person or an agent. When the status or assignment changes, it triggers a hook. A hook is a function that runs in response to that change. It can launch an agent, notify your team, or start another workflow. When set up correctly, hooks and agents let you use Antigen as a security factory - agents investigate vulnerabilities, prepare fixes, and verify deployed changes, while your team reviews proposed changes and steps in where needed. You can manage this work from Vulnerabilities in the platform. The board groups vulnerabilities by status; the list shows the same vulnerabilities in a table.

Track status and assignment

Status tells you where the work stands. Assignment tells you who or which agent is responsible. A vulnerability does not have to pass through every status. For example, your team may accept the risk, or verification may return an unresolved vulnerability to Open.

Use hooks to start work

A hook responds when a vulnerability’s status or assignment changes. It can launch an agent, notify your team, or start another workflow. Antigen comes with hooks configured for triage, remediation, and verification. These connect the work automatically while your team reviews proposed changes and handles tasks that need human input.

How the default setup works

  1. A new vulnerability starts triage. When a vulnerability enters Open, a hook launches Antigen’s pre-built triage-agent. It investigates the issue and determines whether it has enough information and access for remediation to proceed.
  2. Assignment starts remediation. If triage can proceed, it moves the vulnerability to In progress and assigns it to Antigen’s pre-built remediation-agent. That assignment triggers a run to prepare remediation steps, such as a GitHub pull request or a proposed cloud configuration change. If triage needs help, it asks your team.
  3. Your team reviews and deploys the changes. Your team completes the proposed work through its usual tools. Once the fix is deployed, the vulnerability moves to Remediated.
  4. Verification tests the fix. Moving to Remediated triggers tCell to test the original exploit again. If it no longer succeeds, the vulnerability moves to Verified. If it still succeeds, the vulnerability returns to Open with new evidence, starting triage again.
See How triage works and How remediation works for details.

Connect your own agents and workflows

The default setup uses the same hooks available to your team. You can add a notification, replace an agent, or send work to an agent environment you already use. For example, you could send critical vulnerabilities to Slack or assign remediation to Cursor Cloud, Devin, or an agent assembled with the Antigen SDK. See Assigning to your own agents for how to customize this behavior.