Choose where your agent runs
Your service receives a webhook and decides when to launch the agent. The agent can run in an external environment or in a sandbox.Use an external agent
Your service can launch an agent through a tool such as Cursor Cloud or Devin. The agent runs in that environment and can use the Antigen API to retrieve vulnerabilities, read evidence, and update the work. For example, your webhook handler can check an assignment event, retrieve the vulnerability and its evidence, and start a Cursor Cloud agent against the relevant repository.Use a custom Antigen agent
Custom Antigen agents can use cyber-capable models from OpenAI and Anthropic through Antigen’s model gateway. The agents run in sandboxes and can only work on your approved targets or vulnerabilities.- Assemble your agent with the Antigen SDK. Choose its models, skills, guardrails, and tools.
- Register your agent to save its configuration. You can then select it from the assignment dropdown in the platform or assign vulnerabilities to it through the API.
- Set up a webhook handler in your own service to receive assignment changes. Check whether the vulnerability was assigned to your custom agent.
- Launch your agent from the handler. Retrieve the registered agent through the SDK and start a run with the vulnerability and its evidence.
Update the vulnerability
Your agent or the service running it can use the API to update the vulnerability as work progresses. It can change the status or assign work to someone else. These updates appear on the same vulnerability your team reviews in the platform. Status and assignment changes can trigger additional hooks, just as they do for the pre-built agents.Replace a default workflow
If you’re replacing triage, remediation, or verification with your own workflow, disable the corresponding default hook in the platform or via the API. This applies to both external agents and custom Antigen agents.- Your own triage: receive status changes to Open and launch your agent to investigate the vulnerability and determine how remediation should proceed.
- Your own remediation: receive assignment changes, check whether the vulnerability was assigned to your agent, and launch it to prepare remediation steps.
- Your own verification: receive status changes to Remediated and launch your agent with the vulnerability and its original evidence to test whether the fix worked.