Skip to main content
Antigen’s pre-built triage-agent investigates a vulnerability and determines how remediation should proceed. It checks the available evidence, identifies the affected systems, and decides whether it has enough information and access to hand the work to Antigen’s pre-built remediation-agent.

When triage starts

With the default triage hook enabled, entering Open starts triage-agent. This happens when an agent creates a vulnerability or when verification finds that a previous fix did not resolve it.

What the agent investigates

triage-agent uses the vulnerability’s evidence, your Asset Map, and connected integrations to understand the issue. It investigates:
  • Which services, resources, and repositories are involved.
  • What changes could address the vulnerability.
  • Whether the required information and access are available.
  • Whether remediation-agent can handle the work or a person should investigate further.
For example, a vulnerability in an application may require access to its repository. A cloud configuration issue may require context from the provider integration.

What happens next

If remediation can proceed, triage-agent moves the vulnerability to In progress and assigns it to remediation-agent. Its investigation is passed along so remediation-agent can use it when preparing changes. If information or access is missing, triage-agent explains what it needs and asks your team for help through your connected tools. For example, it may ask you to update your GitHub integration to grant access to the repository containing the affected code. If the issue needs human investigation, the vulnerability stays Open. Your team can assign it to a person or another agent. See How remediation works for how the investigation becomes proposed changes.

Customize triage

You can turn the default triage hook on or off in the platform or via the API. To handle triage through your own system, register a webhook that responds when a vulnerability enters Open.