For the complete documentation index, see llms.txt. This page is also available as Markdown.

Create Vulnerability

Description

Creates a new AttackForge vulnerability (also called a finding or issue) inside an existing project. Every vulnerability is linked to a project (project_id) and to a writeup template (writeup_id), which seeds its title/description/remediation.

A two-step workflow is required because the input shape is tenant-specific - see Two-Step Workflow for Write Tools:

  1. Call get_args_schema_for_tool(tool="create_vulnerability") to retrieve the current JSON Schema for args.

  2. Build args to match that schema and call this tool.

Preconditions: the caller needs Edit access to the target project, View access to the chosen writeup, the project must be under its per-project vulnerability-creation limit, and (for non-Cloud/Server licences) Client-role users cannot create vulnerabilities. Any rich-text field must use the AttackForge richtext format from the richtext_format block. On success the new vulnerability id is returned.

How To Enable

  1. Go to Users

  2. Select the user you would like to provide access to this tool

  3. Click on Access > MCP

  4. Click on Add Tools

  5. Select the tool create_vulnerability and click Add

Example Prompts

  • Create a High SQL Injection finding in project X using the "SQL Injection" writeup.

  • Add a new vulnerability to project X based on writeup Y with these steps to reproduce.

  • Log a critical finding against the login asset in the ACME project.

Parameters

Parameter
Type
Required
Description

args

object

Yes

The vulnerability-creation payload. Build it to satisfy get_args_schema_for_tool(tool="create_vulnerability"). At minimum requires a project_id (source: find_projects) and a writeup_id (source: find_writeups).

Example Response

Last updated