Skip to main content
You can use your own agents to investigate vulnerabilities, prepare fixes, and verify deployed changes. These can be agents assembled with the Antigen SDK or agents running in another environment, such as Cursor Cloud or Devin. Antigen provides the pre-built triage-agent and remediation-agent by default, and uses tCell for verification. You can keep the defaults for some work and use your own agents for other tasks.

Choose where your agent runs

Your service receives a webhook and decides when to launch the agent. The agent can run in an external environment or in a sandbox.

Use an external agent

Your service can launch an agent through a tool such as Cursor Cloud or Devin. The agent runs in that environment and can use the Antigen API to retrieve vulnerabilities, read evidence, and update the work. For example, your webhook handler can check an assignment event, retrieve the vulnerability and its evidence, and start a Cursor Cloud agent against the relevant repository.

Use a custom Antigen agent

Custom Antigen agents can use cyber-capable models from OpenAI and Anthropic through Antigen’s model gateway. The agents run in sandboxes and can only work on your approved targets or vulnerabilities.
  1. Assemble your agent with the Antigen SDK. Choose its models, skills, guardrails, and tools.
  2. Register your agent to save its configuration. You can then select it from the assignment dropdown in the platform or assign vulnerabilities to it through the API.
  3. Set up a webhook handler in your own service to receive assignment changes. Check whether the vulnerability was assigned to your custom agent.
  4. Launch your agent from the handler. Retrieve the registered agent through the SDK and start a run with the vulnerability and its evidence.
You receive the webhook in your hosted environment, but the custom agent runs in a sandbox with its configured tools and access to your organization’s Asset Map. See SDK → Agents for assembling and registering agents, and SDK → Runs for launching them.

Update the vulnerability

Your agent or the service running it can use the API to update the vulnerability as work progresses. It can change the status or assign work to someone else. These updates appear on the same vulnerability your team reviews in the platform. Status and assignment changes can trigger additional hooks, just as they do for the pre-built agents.

Replace a default workflow

If you’re replacing triage, remediation, or verification with your own workflow, disable the corresponding default hook in the platform or via the API. This applies to both external agents and custom Antigen agents.
  • Your own triage: receive status changes to Open and launch your agent to investigate the vulnerability and determine how remediation should proceed.
  • Your own remediation: receive assignment changes, check whether the vulnerability was assigned to your agent, and launch it to prepare remediation steps.
  • Your own verification: receive status changes to Remediated and launch your agent with the vulnerability and its original evidence to test whether the fix worked.
You can keep any default hooks you are not replacing. For example, use your own remediation agent and keep the default verification hook to have tCell verify deployed fixes.

Request help from your team

Your agent can create a human task to request a review, additional access, or an infrastructure change. See Team workflows for how these requests reach your team and how agents continue after a response.