For the complete documentation index, see llms.txt. This page is also available as Markdown.

Count Remediation Notes

Description

Returns the number of remediation notes attached to one or more AttackForge vulnerabilities. A remediation note is a timestamped, authored comment recording remediation progress, guidance, or discussion for a single vulnerability. Use this when you only need a total - call find_remediation_notes to retrieve the records.

Supply the vulnerabilities to inspect via vulnerability_ids. Results are automatically scoped to notes on vulnerabilities the caller can see: released vulnerabilities require View access to a linked project, while pending (unreleased) vulnerabilities require Edit access. Notes on vulnerabilities the caller cannot see are silently omitted.

How To Enable

  1. Go to Users

  2. Select the user you would like to provide access to this tool

  3. Click on Access > MCP

  4. Click on Add Tools

  5. Select the tool count_remediation_notes and click Add

Example Prompts

  • How many remediation notes are on vulnerability X?

  • How many remediation notes have been added to these findings this year?

  • How many remediation notes did I write on this vulnerability?

  • How many remediation notes mention a patch?

Parameters

Parameter
Type
Required
Description

vulnerability_ids

array

Yes

The vulnerabilities whose remediation notes you want to count (array of 24-hex ids). Source: find_vulnerabilities. Ids the caller cannot see under the visibility rule are silently dropped.

filter

object

No

A MongoDB-style filter. Supported fields are listed below.

visibility

string

No

'visible' (default, notes on released vulnerabilities in projects the caller can View), 'pending' (notes on unreleased vulnerabilities, restricted to projects the caller can Edit), or 'all'. Notes on pending vulnerabilities in projects the caller can only View are never counted.

Supported filter fields:

Field
Type / Values

id

ObjectId('<24 hex>')

created, modified

ISO-8601 datetime

note

string (the note content)

author_id

ObjectId('<24 hex>') - the user who authored the note

vulnerability_id

ObjectId('<24 hex>') - the parent vulnerability

Do NOT restrict which vulnerabilities are inspected via filter - use the vulnerability_ids parameter.

Notes are stored as AttackForge richtext (HTML), so a $regex on note matches the markup as stored, not the rendered text. Keep patterns to plain words to avoid matching tags. Older notes with no richtext content are not matched.

Example Response

Last updated