Find Remediation Notes
Description
Lists the remediation notes attached to one or more AttackForge vulnerabilities. A remediation note is a timestamped, authored comment recording remediation progress, guidance, or discussion for a single vulnerability. Use this when you need the actual records - call count_remediation_notes when only a total is needed.
Supply the vulnerabilities to inspect via vulnerability_ids. Results are automatically scoped to notes on vulnerabilities the caller can see (View access for released, Edit access for pending); notes the caller cannot see are silently omitted. Results are paginated (default 10 per page, max 50).
How To Enable
Go to
UsersSelect the user you would like to provide access to this tool
Click on
Access > MCPClick on
Add ToolsSelect the tool
find_remediation_notesand clickAdd
Example Prompts
Show me the remediation notes on vulnerability X.
What is the latest remediation progress on my critical findings?
Who has commented on this vulnerability, and when?
Find remediation notes mentioning a patch or workaround.
Show me the remediation notes added since January.
List the files attached to the remediation notes on this finding.
Parameters
vulnerability_ids
array
Yes
The vulnerabilities whose remediation notes you want to list (array of 24-hex ids). Source: find_vulnerabilities. Ids the caller cannot see under the visibility rule are silently dropped.
filter
object
No
A MongoDB-style filter. Supported fields are listed below.
visibility
string
No
'visible' (default), 'pending', or 'all' - see count_remediation_notes.
fields
array
No
Fields to include on each note (id is always returned). Supported values are listed below.
limit
integer
No
Maximum records to return in this page. Default 10, max 50.
skip
integer
No
Number of records to skip (offset). Default 0.
Supported filter fields:
id
ObjectId('<24 hex>')
created, modified
ISO-8601 datetime
note
string (the note content)
author_id
ObjectId('<24 hex>') - the user who authored the note
vulnerability_id
ObjectId('<24 hex>') - the parent vulnerability
Do NOT restrict which vulnerabilities are inspected via
filter- use thevulnerability_idsparameter.
Supported fields values:
id
string
created, modified
ISO-8601 datetime
note
string (AttackForge richtext)
files
array of { id, created, modified, name, mimeType, hash, size, storage_name, storage_location }
author_id
string
vulnerability_id
string
Fetch the binary contents of any attached file with
get_file, using theidfromfiles.
Example Response
Last updated