> For the complete documentation index, see [llms.txt](https://support.attackforge.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://support.attackforge.com/app/modules/ai-mcp-and-skills/find-remediation-notes.md).

# Find Remediation Notes

#### Description <a href="#description" id="description"></a>

Lists the remediation notes attached to one or more AttackForge vulnerabilities. A remediation note is a timestamped, authored comment recording remediation progress, guidance, or discussion for a single vulnerability. Use this when you need the actual records - call `count_remediation_notes` when only a total is needed.

Supply the vulnerabilities to inspect via `vulnerability_ids`. Results are automatically scoped to notes on vulnerabilities the caller can see (View access for released, Edit access for pending); notes the caller cannot see are silently omitted. Results are paginated (default 10 per page, max 50).

#### How To Enable <a href="#how-to-enable" id="how-to-enable"></a>

1. Go to `Users`
2. Select the user you would like to provide access to this tool
3. Click on `Access > MCP`
4. Click on `Add Tools`
5. Select the tool `find_remediation_notes` and click `Add`

#### Example Prompts <a href="#example-prompts" id="example-prompts"></a>

* *Show me the remediation notes on vulnerability X.*
* *What is the latest remediation progress on my critical findings?*
* *Who has commented on this vulnerability, and when?*
* *Find remediation notes mentioning a patch or workaround.*
* *Show me the remediation notes added since January.*
* *List the files attached to the remediation notes on this finding.*

#### Parameters <a href="#parameters" id="parameters"></a>

| Parameter           | Type    | Required | Description                                                                                                                                                                                     |
| ------------------- | ------- | -------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `vulnerability_ids` | array   | Yes      | The vulnerabilities whose remediation notes you want to list (array of 24-hex ids). Source: `find_vulnerabilities`. Ids the caller cannot see under the `visibility` rule are silently dropped. |
| `filter`            | object  | No       | A MongoDB-style filter. Supported fields are listed below.                                                                                                                                      |
| `visibility`        | string  | No       | `'visible'` (default), `'pending'`, or `'all'` - see `count_remediation_notes`.                                                                                                                 |
| `fields`            | array   | No       | Fields to include on each note (`id` is always returned). Supported values are listed below.                                                                                                    |
| `limit`             | integer | No       | Maximum records to return in this page. Default 10, max 50.                                                                                                                                     |
| `skip`              | integer | No       | Number of records to skip (offset). Default 0.                                                                                                                                                  |

**Supported `filter` fields:**

| Field                 | Type / Values                                           |
| --------------------- | ------------------------------------------------------- |
| `id`                  | `ObjectId('<24 hex>')`                                  |
| `created`, `modified` | ISO-8601 datetime                                       |
| `note`                | string (the note content)                               |
| `author_id`           | `ObjectId('<24 hex>')` - the user who authored the note |
| `vulnerability_id`    | `ObjectId('<24 hex>')` - the parent vulnerability       |

> Do NOT restrict which vulnerabilities are inspected via `filter` - use the `vulnerability_ids` parameter.

**Supported `fields` values:**

| Field                 | Type                                                                                             |
| --------------------- | ------------------------------------------------------------------------------------------------ |
| `id`                  | string                                                                                           |
| `created`, `modified` | ISO-8601 datetime                                                                                |
| `note`                | string (AttackForge richtext)                                                                    |
| `files`               | array of `{ id, created, modified, name, mimeType, hash, size, storage_name, storage_location }` |
| `author_id`           | string                                                                                           |
| `vulnerability_id`    | string                                                                                           |

> Fetch the binary contents of any attached file with `get_file`, using the `id` from `files`.

#### Example Response

```json
{
  "data": [
    {
      "id": "6981b0c4a1d3e45f77c20981",
      "created": "2026-03-04T09:12:44.021Z",
      "modified": "2026-03-04T09:12:44.021Z",
      "note": "&lt;p&gt;Vendor patch 4.2.1 has been applied to the affected hosts. Awaiting confirmation from the platform team before requesting a retest.&lt;/p&gt;",
      "author_id": "5ad737d6e576e6290aff1808",
      "vulnerability_id": "656168055d7035a12ade4cb3",
      "files": [
        {
          "id": "6981b0c4a1d3e45f77c20982",
          "created": "2026-03-04T09:12:44.500Z",
          "modified": "2026-03-04T09:12:44.500Z",
          "name": "patch-evidence.png",
          "mimeType": "image/png",
          "hash": "0f1c2a1e2f3c4b5a6978daf0e1b2c3d4e5f60718293a4b5c6d7e8f9012345678",
          "size": 84213,
          "storage_name": "kx8m2p4qw9r1t3y5u7i0o2a4s6d8f0g2h4j6k8l0z2x4c6v8b0n2m4q6w8e0r2t4",
          "storage_location": "test-attackforge-dev/issues/2026-3-4/656168055d7035a12ade4cb3"
        }
      ]
    }
  ],
  "count": 1,
  "total": 4
}
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://support.attackforge.com/app/modules/ai-mcp-and-skills/find-remediation-notes.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
