For the complete documentation index, see llms.txt. This page is also available as Markdown.

Find Project Scope

Description

Lists Project Scope items belonging to one AttackForge project. A Project Scope item represents one thing within the testing scope of that project (a URL, host, application, etc.). Use this to retrieve the items themselves - call count_project_scope when only a total is needed. The caller must have at least View access to the project. The fields asset_id, asset_type, external_asset_id, and details are only populated when the Assets module is enabled (these come from the linked Asset). Results are paginated (default 10 per page, max 50).

How To Enable

  1. Go to Users

  2. Select the user you would like to provide access to this tool

  3. Click on Access > MCP

  4. Click on Add Tools

  5. Select the tool find_project_scope and click Add

Example Prompts

  • Show me the scope for project X.

  • List the in-scope hosts for the ACME project with their details.

  • Which scope items in project X are linked to assets?

  • Find scope items containing "api" in project X.

Parameters

Parameter
Type
Required
Description

project_id

string

Yes

The id (24-hex) of the project whose scope you want to list. Obtain it from find_projects. The caller must have View access or higher.

filter

object

No

A MongoDB-style filter. Supported fields are listed below.

fields

array

No

System fields to include (id is always returned). Supported values are listed below.

custom_field_keys

array

No

Custom field keys to include. Project Scope items inherit the custom fields of the underlying Asset model (requires the Assets module). Discover keys via get_field_structure(model="asset").

limit

integer

No

Maximum records to return in this page. Default 10, max 50.

skip

integer

No

Number of records to skip (offset). Default 0.

Supported filter fields:

Field
Type
Description

id

ObjectId('<24 hex>')

the Project Scope item id

name

string

the scope item name (URL, host, application, etc.)

asset_id

ObjectId('<24 hex>')

id of the linked Asset (only set when the Assets module is enabled and the scope item is linked to an Asset)

asset_id, asset_type, external_asset_id, and details require the Assets module to be enabled - they are empty otherwise.

Supported fields values:

Field
Type

id

string

name

string

asset_id

string

asset_type

string

external_asset_id

string

details

string

Example Response

Last updated