Create Vulnerability
Last updated
Creates a new AttackForge vulnerability (also called a finding or issue) inside an existing project. Every vulnerability is linked to a project (project_id) and to a writeup template (writeup_id), which seeds its title/description/remediation.
A two-step workflow is required because the input shape is tenant-specific - see Two-Step Workflow for Write Tools:
Call get_args_schema_for_tool(tool="create_vulnerability") to retrieve the current JSON Schema for args.
Build args to match that schema and call this tool.
Preconditions: the caller needs Edit access to the target project, View access to the chosen writeup, the project must be under its per-project vulnerability-creation limit, and (for non-Cloud/Server licences) Client-role users cannot create vulnerabilities. Any rich-text field must use the AttackForge richtext format from the richtext_format block. On success the new vulnerability id is returned.
Go to Users
Select the user you would like to provide access to this tool
Click on Access > MCP
Click on Add Tools
Select the tool create_vulnerability and click Add
Create a High SQL Injection finding in project X using the "SQL Injection" writeup.
Add a new vulnerability to project X based on writeup Y with these steps to reproduce.
Log a critical finding against the login asset in the ACME project.
args
object
Yes
The vulnerability-creation payload. Build it to satisfy get_args_schema_for_tool(tool="create_vulnerability"). At minimum requires a project_id (source: find_projects) and a writeup_id (source: find_writeups).
Last updated
{
"id": "656168055d7035a12ade4cb3"
}