> For the complete documentation index, see [llms.txt](https://support.attackforge.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://support.attackforge.com/app/modules/ai-mcp-and-skills/count-remediation-notes.md).

# Count Remediation Notes

#### Description <a href="#description" id="description"></a>

Returns the number of remediation notes attached to one or more AttackForge vulnerabilities. A remediation note is a timestamped, authored comment recording remediation progress, guidance, or discussion for a single vulnerability. Use this when you only need a total - call `find_remediation_notes` to retrieve the records.

Supply the vulnerabilities to inspect via `vulnerability_ids`. Results are automatically scoped to notes on vulnerabilities the caller can see: released vulnerabilities require View access to a linked project, while pending (unreleased) vulnerabilities require Edit access. Notes on vulnerabilities the caller cannot see are silently omitted.

#### How To Enable <a href="#how-to-enable" id="how-to-enable"></a>

1. Go to `Users`
2. Select the user you would like to provide access to this tool
3. Click on `Access > MCP`
4. Click on `Add Tools`
5. Select the tool `count_remediation_notes` and click `Add`

#### Example Prompts <a href="#example-prompts" id="example-prompts"></a>

* *How many remediation notes are on vulnerability X?*
* *How many remediation notes have been added to these findings this year?*
* *How many remediation notes did I write on this vulnerability?*
* *How many remediation notes mention a patch?*

#### Parameters <a href="#parameters" id="parameters"></a>

| Parameter           | Type   | Required | Description                                                                                                                                                                                                                                                                                   |
| ------------------- | ------ | -------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `vulnerability_ids` | array  | Yes      | The vulnerabilities whose remediation notes you want to count (array of 24-hex ids). Source: `find_vulnerabilities`. Ids the caller cannot see under the `visibility` rule are silently dropped.                                                                                              |
| `filter`            | object | No       | A MongoDB-style filter. Supported fields are listed below.                                                                                                                                                                                                                                    |
| `visibility`        | string | No       | `'visible'` (default, notes on released vulnerabilities in projects the caller can View), `'pending'` (notes on unreleased vulnerabilities, restricted to projects the caller can Edit), or `'all'`. Notes on pending vulnerabilities in projects the caller can only View are never counted. |

**Supported `filter` fields:**

| Field                 | Type / Values                                           |
| --------------------- | ------------------------------------------------------- |
| `id`                  | `ObjectId('<24 hex>')`                                  |
| `created`, `modified` | ISO-8601 datetime                                       |
| `note`                | string (the note content)                               |
| `author_id`           | `ObjectId('<24 hex>')` - the user who authored the note |
| `vulnerability_id`    | `ObjectId('<24 hex>')` - the parent vulnerability       |

> Do NOT restrict which vulnerabilities are inspected via `filter` - use the `vulnerability_ids` parameter.

> Notes are stored as AttackForge richtext (HTML), so a `$regex` on `note` matches the markup as stored, not the rendered text. Keep patterns to plain words to avoid matching tags. Older notes with no richtext content are not matched.

#### Example Response

```json
{
  "count": 4
}
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://support.attackforge.com/app/modules/ai-mcp-and-skills/count-remediation-notes.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
