Skip to main content
Antigen’s pre-built remediation-agent prepares changes to address a vulnerability. It uses the investigation completed during triage, the original evidence, and your infrastructure context to determine what needs to change.

When remediation starts

With the default remediation hook enabled, assigning a vulnerability to remediation-agent starts a run. In the default setup, the triage agent makes this assignment when it determines that remediation can proceed. The agent receives the vulnerability, the triage investigation, and evidence from the run that discovered the issue. It can also use your Asset Map and connected integrations to understand the affected systems and their dependencies.

What the agent produces

remediation-agent produces remediation steps. Each step describes a concrete change needed to address the vulnerability. Steps can include:
  • Code changes: a GitHub pull request containing a proposed fix.
  • Infrastructure changes: instructions for updating cloud resources, permissions, or service configuration.
  • Work for your team: actions that require someone with the necessary access or context.
A single vulnerability may require several steps. For example, resolving exposed database credentials could require both a code change and a credential rotation.

Review and complete the work

The agent sends proposed work to your connected tools. It can open GitHub pull requests, create issues in Linear, Jira, or GitHub, and send requests through Slack. Your team reviews the proposed changes, merges pull requests, and completes infrastructure updates through its usual workflow. If the agent needs additional access or information, it explains what is missing and asks your team for help. Once the required changes are deployed, the vulnerability moves to Remediated.

Verify the fix

With the default verification hook enabled, entering Remediated starts a tCell run to test the original exploit against the approved target. If the exploit no longer succeeds, the vulnerability moves to Verified. If it still succeeds, the vulnerability returns to Open with new evidence. With the default triage hook enabled, this starts another investigation.

Use your own workflow

You can turn the default remediation hook on or off in the platform or via the API. To handle remediation through another system, add a webhook that responds to assignment changes. See Assigning to your own agents for details.