Heads up This site is currently under heavy development.
← all tools
◆ AI Coding Agents

Cotool

v0.66.0 commercial

Cotool is an AI-powered security tool that analyzes code for vulnerabilities and provides automated remediation recommendations for developers.

Summary

Cotool is a commercial AI agent platform for building and running security-focused automation, run as a hosted service that connects to third-party tools rather than as a library or standalone CLI. It is aimed at security teams looking to delegate investigation and remediation work — the integration list spans email security (Barracuda), endpoint and MSP tooling (Huntress, Kolide), application security (OX Security), and network detection (Darktrace) — alongside agent-builder features like instruction-aware integration recommendations and durable, restart-safe agent runs. It sits in the category of AI coding and automation agents rather than a fixed scanning or SIEM tool, letting teams wire agents into whatever systems they already run. With 33 releases in the window we track, spanning new integrations, audit-log detail, and agent-management controls, it shows active, continuous development.

Cotool is an AI-powered security tool that analyzes code for vulnerabilities and provides automated remediation recommendations for developers.

What Cotool answers

Which security tools can an agent actually take action on, not just read from?

integrations like Darktrace, Barracuda, and Kolide support write actions such as acknowledging breaches, remediating email threats, and running reports, not just lookups

Do I need to run any infrastructure to use this?

it runs as a hosted service you connect to your existing tools, with nothing to install or host yourself

What happens if an agent is mid-task when something fails?

runs, sub-agent handoffs, tool calls, and waiting prompts survive worker restarts instead of losing state

Can I tell which actions were run by a person versus run automatically?

audit logs distinguish API-triggered executions from interactive runs

How does the platform help me pick the right integration for a given task?

the agent builder recommends integrations based on the instructions you've written, rather than requiring you to know the catalog upfront

Can I trigger an agent from tools my team already uses day to day?

a Slack emoji reaction on a message can start an agent run, without a separate console or command

all 17 features, with the evidence for each →

Features

17 capabilities across 4 areas

Built from everything we hold on Cotool — every release we have summarised, its product documentation and how that documentation has changed, its README, its command-line surface and API, and runs we performed ourselves. Dates are when we first saw a capability, not when the vendor introduced it.

Capability area
Agent orchestration and lifecycle 5 capabilities Cotool provides the core infrastructure for building, running, and maintaining agents. This covers agent construction, durable execution across interruptions, context handling, and model management.
Agent builder shipped Lets operators build agents interactively, with recommendations on which integrations to include based on the agent's instructions. 1 release

release

  • Adds instruction-aware integration recommendations directly in the agent builder v0.62.0 · seen Aug 2026 · source · release history
Agent model management shipped Guides operators through upgrading the model powering an agent, using research-backed recommendations that require explicit approval before applying. 1 release

release

  • Adds guided, user-approved model upgrades for agents with supporting research for each recommendation v0.62.0 · seen Aug 2026 · source · release history
Conversation context management shipped Manages long conversations by compacting context in a provider-native way so the agent retains as much useful history as possible. 1 release

release

  • Improves long conversations with provider-native compaction that preserves more useful context v0.62.0 · seen Aug 2026 · source · release history
Durable agent execution shipped Keeps agent runs and all associated sub-tasks alive even when the underlying worker restarts, so no work is lost mid-execution. 1 release

release

  • Makes agent runs, delegated sub-agents, tool calls, waiting prompts, and handoffs durable across worker restarts v0.62.0 · seen Aug 2026 · source · release history
Skill version history shipped Records the history of skill versions so operators can review past iterations and roll back to an earlier version if needed. 1 release

release

  • Adds skill version history with the ability to inspect and restore earlier versions v0.62.0 · seen Aug 2026 · source · release history
Security tool integrations 5 capabilities Cotool connects agents to a set of dedicated cyber tools covering endpoint, email, network, and application security. Agents can query, investigate, and act on findings within each platform directly.
Barracuda email security integration shipped Connects agents to Barracuda so they can investigate and take remediation action on email threats. 1 release

release

  • Adds a Barracuda email security integration for investigating and remediating email threats. v0.63.0 · seen Aug 2026 · source · release history
Darktrace integration shipped Lets agents interact with Darktrace model breaches, including acknowledging, reopening, and adding comments. 1 release

release

  • Expands Darktrace with actions to acknowledge, reopen, and comment on model breaches v0.62.0 · seen Aug 2026 · source · release history
Huntress integration shipped Connects agents to Huntress for endpoint threat visibility, with support for MSP and MSSP account structures and optional scoping to a specific organization. 1 release

release

  • Expands Huntress support for MSP and MSSP accounts with optional organization scoping v0.62.0 · seen Aug 2026 · source · release history
OX Security integration shipped Lets agents search OX Security for applications, artifacts, and SBOMs, and investigate identified issues and attack paths. 1 release

release

  • Adds an OX Security integration to search applications, artifacts, and SBOMs and investigate issues and attack paths. v0.63.0 · seen Aug 2026 · source · release history
Supabase integration shipped Connects agents to Supabase so they can review an organization's project security posture, configuration settings, and logs. 1 release

release

  • Adds a Supabase integration for organization and project security posture, configuration review, and project logs. v0.63.0 · seen Aug 2026 · source · release history
Developer and productivity tool integrations 4 capabilities Cotool integrates agents with the collaboration and development platforms teams already use. This allows agents to retrieve context from and act within those systems as part of a broader workflow.
GitHub integration shipped Connects agents to GitHub, supporting multi-organization app scoping and the ability to upload files generated in the agent's sandbox. 2 releases

release

  • Adds multi-organization GitHub App installation scoping. v0.63.0 · seen Aug 2026 · source · release history
  • Adds support for GitHub tools to upload sandbox-generated files v0.62.0 · seen Aug 2026 · source · release history
Kolide integration shipped Lets agents query Kolide for device and fleet reports, handling parameters that accept multiple values. 1 release

release

  • Expands Kolide report queries with improved multi-value parameter handling v0.62.0 · seen Aug 2026 · source · release history
Linear integration shipped Lets agents search Linear issues using full-text queries, with filters for team, status, archive state, and comments. 1 release

release

  • Adds full-text Linear issue search with team, status, archive, and comment filters v0.62.0 · seen Aug 2026 · source · release history
Slack integration shipped Allows agents to be triggered from Slack, including by placing an emoji reaction on a message. 1 release

release

  • Adds Slack emoji-reaction triggers so reacting to a message can run an agent. v0.63.0 · seen Aug 2026 · source · release history
Administration, alerting, and audit 3 capabilities Cotool gives administrators controls over session behaviour, alert noise, and activity records. These capabilities support operational governance and accountability across the platform.
Alert notification filtering shipped Filters alert notifications so that only escalations at or above a configured severity threshold are surfaced to operators. 1 release

release

  • Adds a minimum-severity filter for escalated alert notifications. v0.63.0 · seen Aug 2026 · source · release history
Audit logging shipped Records agent activity in audit logs and distinguishes whether each run was triggered via the API or interactively. 1 release

release

  • Distinguishes API agent executions from interactive runs in audit logs v0.62.0 · seen Aug 2026 · source · release history
Session management shipped Lets administrators set a maximum session length on a per-organization basis. 1 release

release

  • Adds a per-organization session length setting in Settings. v0.63.0 · seen Aug 2026 · source · release history
Capability
Evidence

Lines in monospace are the tool's own words — help text parsed from its source, or an endpoint from its API document. Everything else is our summary of a dated release or documentation change, linked back to the source it came from.

Release history

  1. v0.66.0 Aug 31, 2026 · issue 012

    Cotool v0.66.0 adds Cloudflare, Auth0, 1Password, and Tailscale integrations for investigation and alert triage.

    • Adds a Cloudflare integration for investigating HTTP traffic, firewall events, Zero Trust Gateway activity, DNS, zones, and devices.
    • Adds an Auth0 integration for investigating identity configurations, users, audit events, and sign-ins.
    • Adds a 1Password integration for investigating sensitive item activity and audit events.
    • Adds a Tailscale integration for investigating devices, users, and configuration changes across tailnets.
    • Improves alert triage by attaching evidence to every detection hit, providing response agents with prior-alert context, duplicate handling, and escalation of uncertain cases for human review.
    +5 moreshow less
    • Enhances Slack alert notifications with concise evidence summaries, in-message status controls, and threaded follow-up with the assigned response agent.
    • Improves the Detections overview with infinite scrolling, compact filters, bulk disable, and consistent true-positive metrics.
    • Improves alert investigation with clearer source attribution, more readable structured payloads, and optional feedback when closing alerts as benign or false positives.
    • Expands Linear integration with duplicate issue handling and Notion integration with paginated database queries.
    • Improves threat models with safer regeneration, persistent progress, longer-running generation, and automatic availability to the default response agent.
  2. v0.65.0 Aug 24, 2026 · issue 007

    Cotool v0.65.0 adds Microsoft Sentinel, Control D, and GitHub Actions integrations for log querying, DNS investigation, and PR automation.

    • Adds a Microsoft Sentinel integration for querying logs, triaging incidents, managing analytics rules, and powering detection authoring and environment mapping.
    • Adds a Control D integration for investigating DNS activity and managing custom filtering rules across sub-organizations.
    • Adds GitHub Actions workflow tools for creating and updating pull requests, protected by explicit permissions.
    • Enhances structured outputs with table-based nested data views and drag-and-drop schema editing that preserves existing fields.
    • Improves detection coverage accuracy by linking external alerts to verified rules from connected security platforms.
  3. v0.50.0 seen Aug 19, 2026 · issue 001

    Cotool v0.50.0 adds private skills, Exa web search, and detection hit workflows for agents.

    • Adds private skills to scope organization-specific workflows to specific users and agents.
    • Adds Exa web search as a selectable agent tool for retrieving fresh web context.
    • Adds detection hit workflows that let detection agents inspect hits and call tools from hit context.
    • Adds agent run rate limiting and clearer reporting for API-triggered runs.
    • Improves skills pages with better private skill visibility and invocation counts.
  4. v0.51.0 seen Aug 19, 2026 · issue 001

    Cotool v0.51.0 adds FireHydrant and Glean integrations, detection hit denoising with subagents, and bulk agent deletion.

    • New FireHydrant incident response integration brings incident context into agent workflows.
    • New Glean search and document access integration as a knowledge source for agents.
    • Detection hit denoising via subagents to reduce noisy findings in detection workflows.
    • Bulk deletion for response agents to streamline cleanup at scale.
    • Detection agent workflows now support step reordering and a redesigned detection hits interface.
    +4 moreshow less
    • Agent run acceptance criteria now evaluate errored executions, ensuring failures still produce useful feedback.
    • Structured output generation now includes retries after interrupted generation for more consistent results.
    • Sumo Logic query validation upgraded to use a formal parser, improving detection query feedback and reliability.
    • Sumo Logic environment mapping now supports editable descriptions, runtime variable updates, and larger mappings.
  5. v0.52.0 seen Aug 19, 2026 · issue 001

    Cotool v0.52.0 adds Linear ticket output for detection agents, a Linear agent trigger endpoint, evidence capture, and bulk skill imports.

    • New Linear ticket output destination for detection agents, delivering generated detections directly into Linear.
    • New Linear agent trigger endpoint for starting Linear-linked agent workflows programmatically.
    • Adds detection hit evidence capture with cited tool calls, richer query result displays, and clearer evidence review.
    • Adds bulk skill imports from folders for faster large-scale skill library setup.
    • Enhances Wiz investigations by consolidating agent tools and streamlining principal activity handling.
    +5 moreshow less
    • Improves Datadog detection authoring with better rule generation, validation, and helper coverage.
    • Improves Sumo Logic compiler feedback with stronger parsing advisories and empty-result validation.
    • Refines structured output rendering with schema previews and a cleaner detection output viewer.
    • Improves custom RSS feed setup with URL validation before feeds are saved.
    • Enhances threat intelligence ingestion with cross-source deduplication, huntability filtering, and Socket Blog support.
  6. v0.53.0 seen Aug 19, 2026 · issue 001

    Cotool v0.53.0 adds ExtraHop, Semgrep, ClickHouse, and Obsidian Security integrations plus GitHub blame tools and IOC/MISP intel views.

    • Adds ExtraHop RevealX, Semgrep, ClickHouse, and Obsidian Security integrations.
    • Adds GitHub commit history and blame tools for richer repository investigations.
    • Adds IOC list views and MISP Hunt intel sources for easier threat intelligence review.
    • Adds organization-level notification settings for detection and response output delivery.
    • Enhances detection workflows with evidence on detail pages, agent type filtering, cleaner hit displays, and unified run pagination.
    +4 moreshow less
    • Improves Slack agent workflows with run-button configuration and support for user replies.
    • Improves threat intelligence management by combining sources, cleaning up MISP sync, and retrying failed API sync results.
    • Enhances audit logs with richer filters, user and tool filtering, native tool hiding, and infinite scroll.
    • Improves sub-agent UX with progress previews, drawer breadcrumbs, and clearer nested agent timelines.
  7. v0.54.0 seen Aug 19, 2026 · issue 001

    Cotool v0.54.0 adds persistent agent filesystems, Spacelift and Jira Service Management integrations, SCIM provisioning, and job dependencies.

    • Adds a Persistent Agent Filesystem so agents can save and reuse files across runs, enabling stateful workflows between executions.
    • Adds a Spacelift integration for infrastructure-as-code investigations directly from agent workflows.
    • Adds Jira Service Management alert creation as an agent output destination.
    • Adds a Linear team issue listing tool for richer ticket investigations inside agent runs.
    • Adds job dependencies so scheduled and chained jobs execute in the correct order.
    +3 moreshow less
    • Adds configurable SCIM provisioning with public SAML and SCIM identity provider documentation.
    • Adds support for sandbox file attachments in Slack messages sent from agents.
    • Enhances the executive dashboard with URL-encoded time windows, a one-year preset, and a refined date picker.
  8. v0.55.0 seen Aug 19, 2026 · issue 001

    Cotool v0.55.0 adds Darktrace, KnowBe4 PhishER, and Adaptive Shield integrations alongside agent versioning and inline chart rendering.

    • Adds a Darktrace integration for network detection and response investigations.
    • Adds a KnowBe4 integration with PhishER GraphQL support for phishing triage workflows.
    • Adds Adaptive Shield (Falcon Shield) SaaS security support to the CrowdStrike tool.
    • Adds custom Slack app integration setup.
    • Adds agent versioning to track and revert agent changes over time.
    +2 moreshow less
    • Adds inline chart rendering in the chat timeline with light and dark theming.
    • Adds the ability to reply to and follow up with built-in response agents.
  9. v0.56.0 seen Aug 19, 2026 · issue 001

    Cotool v0.56.0 adds Bugcrowd and ChartHop integrations plus Response Agents as Code with GitHub GitOps sync

    • New Bugcrowd integration with webhook triggers for vulnerability intake and response automation.
    • New ChartHop integration bringing people and organization context into investigations.
    • Response Agents as Code with GitHub GitOps sync, sample YAML agents, and managed-agent protections.
    • Adds configurable timeouts for unanswered Slack confirmations.
    • Enables response output delivery without a structured schema, making output destinations more flexible.
    +2 moreshow less
    • New sub-agent timeline drilldown in the agent execution panel.
    • Enhanced agent improvement generation to allow tool suggestions and richer review flows.
  10. v0.57.0 seen Aug 19, 2026 · issue 001

    Cotool v0.57.0 adds a full Alerts system for security triage, a HackerOne connector, new AI models, and MITRE coverage views.

    • Adds first-class Alerts for security triage, including an alert inbox, detail pages, activity timelines, comments, assignments, dispositions, bulk actions, and response-agent triage.
    • Adds a HackerOne connector with webhook-triggered alert intake for vulnerability response workflows.
    • Adds Claude Opus 4.8 and GPT-5.5 models; GPT-5.5 is now the default chat model.
    • Adds a MITRE coverage view for environment-level threat model analysis.
    • Adds detection notification severity filters so teams can control which detection hits trigger downstream destination notifications.
    +2 moreshow less
    • Improves Response Agents as Code with API-based schema validation, canonical YAML imports, and support for multiple GitHub sync repositories per organization.
    • Adds Tines record retrieval tools and expands VirusTotal relationship pagination for deeper investigations.
    └──▷ BREAKING ON UPGRADE
    • !GPT-5.5 replaces the previous model as the default chat model; existing workflows relying on the prior default will now use GPT-5.5.
  11. v0.58.0 seen Aug 19, 2026 · issue 001

    Cotool v0.58.0 adds OpenCTI threat intel enrichment, GitHub-synced Agent Skills as code, and a Dismissed alert status.

    • Adds an OpenCTI threat intelligence integration for enriching investigations with threat intel.
    • Adds Agent Skills as code — skills can be managed and synced from GitHub, mirroring the existing agents-as-code workflow.
    • Adds a Dismissed status (human-only) that archives alerts without closing them.
    • Adds a Slack reply scope setting so triggers can respond to anyone in a thread or only to Cotool users.
    • Adds a service account authentication option for Jira.
    +3 moreshow less
    • Adds support for closing alerts in Obsidian.
    • Adds the ability to test output destinations directly from the UI by sending an example payload.
    • Reworks the notifications page with tabs and adds escalated-alert notifications.
  12. v0.59.0 seen Aug 19, 2026 · issue 001

    Cotool v0.59.0 launches Hunt V2 continuous threat intelligence, slash commands in chat, GPT-5.6 models, and a canonical audit-log event catalog endpoint.

    • Adds a canonical audit-log event catalog endpoint with documentation, giving practitioners a single authoritative source for audit event types.
    • Introduces Hunt V2: continuously assesses incoming threat intelligence against your environment, hunts for exposure, and raises alerts with a verdict when a threat is relevant to your organization.
    • Adds slash commands to chat with persisted commands for detection agents and a refreshed command header in the chat input.
    • Adds GPT-5.6 models and makes GPT-5.6 Sol the default chat model.
    • Adds separate personal and organization skill namespaces.
    +5 moreshow less
    • Adds Linear label support.
    • Adds bulk dismiss for detection suggestions.
    • Webhook URLs and secrets are now visible on GitOps-managed triggers.
    • Sub-agent tool chips now link to the agent details page.
    • Adds contextual Cmd+K status commands to the bulk selection experience on the Alerts page.
  13. v0.60.0 seen Aug 19, 2026 · issue 001

    Cotool v0.60.0 adds /hunt-intel, TAXII 2.1, four new integrations, CrowdStrike Spotlight, new AI models, and Auto Model Routing.

    • Adds /hunt-intel slash command to ingest a threat report URL through the Hunt pipeline, with a dedicated timeline in chat.
    • Adds Recorded Future, Silobreaker, and TAXII 2.1 as threat intelligence sources.
    • Adds Huntress, Railway, Kolide, and Cloudsmith integrations.
    • Adds CrowdStrike Spotlight vulnerability-management actions.
    • Adds Auto Model Routing for chat and agents, letting Cotool automatically select the model backing a task.
    +7 moreshow less
    • Adds Claude Opus 5 and open-weight models including Kimi K3 and GLM 5.2, with the same data residency and ZDR guarantees as proprietary models.
    • Adds a Duplicate alert status and faster indexed alert search.
    • Adds support for creating draft GitHub pull requests.
    • Adds audit logs for agent status changes.
    • Renders CLI-based tool calls (gcloud/aws) with terminal-style visuals in chat.
    • Makes agent tag counts clickable in the UI.
    • Adds status-explainer tooltips on Threats group headers.
  14. v0.61.0 seen Aug 19, 2026 · issue 001

    Cotool v0.61.0 adds StepSecurity integration for GitHub Actions supply-chain security and a new Expired alert status with 14-day inactivity checks.

    • Adds a StepSecurity integration for investigating GitHub Actions security posture, runtime detections, network and process activity, policy evaluations, compromised components, and supply-chain threats.
    • Adds an 'Expired' alert status and 14-day inactivity checks to surface and manage stale alerts.
    • Expands the Recorded Future integration with alert and alert-rule search plus full alert detail retrieval.
    • Unifies suggested detection agents with detection-rule suggestions, adding investigation-plan review and direct acceptance into the detection builder.
    • Redesigns model settings with a searchable provider catalog, clearer Cotool Auto routing, and dedicated custom endpoint management.
    +3 moreshow less
    • Redesigns the integrations directory with search, category and connection-status filters, and clearer integration details.
    • Improves Cloudsmith setup with connect-time credential validation and owner-aware tool errors.
    • Improves sub-agent handoffs with reusable execution receipts that preserve successful tool calls and output files, reducing duplicate lookups.
  15. v0.62.0 seen Aug 19, 2026 · issue 001

    Cotool v0.62.0 adds full-text Linear search, GitHub sandbox file uploads, durable agent runs, and expanded Huntress/Darktrace/Kolide integrations.

    • Adds full-text Linear issue search with team, status, archive, and comment filters.
    • Adds support for GitHub tools to upload sandbox-generated files.
    • Distinguishes API agent executions from interactive runs in audit logs.
    • Adds guided, user-approved model upgrades for agents, including supporting research for each recommendation.
    • Adds skill version history with the ability to inspect and restore earlier versions.
    +6 moreshow less
    • Makes agent runs, delegated sub-agents, tool calls, waiting prompts, and handoffs durable across worker restarts.
    • Expands Huntress support for MSP and MSSP accounts with optional organization scoping.
    • Expands Darktrace integration with actions to acknowledge, reopen, and comment on model breaches.
    • Expands Kolide report queries and improves multi-value parameter handling.
    • Adds instruction-aware integration recommendations directly in the agent builder.
    • Adds provider-native compaction for long conversations to preserve more useful context.
  16. v0.63.0 seen Aug 19, 2026 · issue 001

    Cotool v0.63.0 adds Barracuda, OX Security, and Supabase integrations plus Slack emoji-reaction agent triggers.

    • New Barracuda email security integration for investigating and remediating email threats.
    • New OX Security integration to search applications, artifacts, and SBOMs and investigate issues and attack paths.
    • New Supabase integration for organization and project security posture, configuration review, and project logs.
    • Adds Slack emoji-reaction triggers so reacting to a message can run an agent.
    • Adds multi-organization GitHub App installation scoping.
    +2 moreshow less
    • Adds a per-organization session length setting in Settings.
    • Adds a minimum-severity filter for escalated alert notifications.
  17. v0.64.0 seen Aug 19, 2026 · issue 001

    Cotool v0.64.0 adds Zscaler and Darktrace integrations, response agents from chat or templates, and a redesigned navigation.

    • Adds a Zscaler integration covering ZIA, ZPA, ZDX, and Client Connector tools, with detection-rule sync, alert triggers, and permission validation.
    • Adds first-class Darktrace webhook triggers so response agents can run immediately on model-breach and AI Analyst alerts.
    • Enables creating response agents directly from chat or from templates.
    • Redesigns navigation and page layouts around Home, Detect, Hunt, Respond, Knowledge, Platform, and Settings sections, with consistent breadcrumbs and backward-compatible existing links.
    • Adds live progress from delegated agents to chat and agent timelines.
    +1 moreshow less
    • Expands Linear, Silobreaker, and Notion integrations with parent-child issue updates, broader threat-intelligence research, and complete nested page content.
  18. v0.59.0 seen Aug 19, 2026 · issue 001

    Cotool v0.59.0 launches Hunt V2 continuous threat intelligence, slash commands in chat, GPT-5.6 models, and a canonical audit-log event catalog endpoint.

    • Adds a canonical audit-log event catalog endpoint with documentation, giving practitioners a single authoritative source for audit event types.
    • Introduces Hunt V2: continuously assesses incoming threat intelligence against your environment, hunts for exposure, and raises alerts with a verdict when a threat is relevant to your organization.
    • Adds slash commands to chat with persisted commands for detection agents and a refreshed command header in the chat input.
    • Adds GPT-5.6 models and makes GPT-5.6 Sol the default chat model.
    • Adds separate personal and organization skill namespaces.
    +5 moreshow less
    • Adds Linear label support.
    • Adds bulk dismiss for detection suggestions.
    • Webhook URLs and secrets are now visible on GitOps-managed triggers.
    • Sub-agent tool chips now link to the agent details page.
    • Adds contextual Cmd+K status commands to the bulk selection experience on the Alerts page.
  19. v0.64.0 seen Aug 19, 2026 · issue 001

    Cotool v0.64.0 adds Zscaler and Darktrace integrations, response agents from chat or templates, and a redesigned navigation.

    • Adds a Zscaler integration covering ZIA, ZPA, ZDX, and Client Connector tools, with detection-rule sync, alert triggers, and permission validation.
    • Adds first-class Darktrace webhook triggers so response agents can run immediately on model-breach and AI Analyst alerts.
    • Enables creating response agents directly from chat or from templates.
    • Redesigns navigation and page layouts around Home, Detect, Hunt, Respond, Knowledge, Platform, and Settings sections, with consistent breadcrumbs and backward-compatible existing links.
    • Adds live progress from delegated agents to chat and agent timelines.
    +1 moreshow less
    • Expands Linear, Silobreaker, and Notion integrations with parent-child issue updates, broader threat-intelligence research, and complete nested page content.
  20. v0.57.0 seen Aug 19, 2026 · issue 001

    Cotool v0.57.0 adds a full Alerts system for security triage, a HackerOne connector, new AI models, and MITRE coverage views.

    • Adds first-class Alerts for security triage, including an alert inbox, detail pages, activity timelines, comments, assignments, dispositions, bulk actions, and response-agent triage.
    • Adds a HackerOne connector with webhook-triggered alert intake for vulnerability response workflows.
    • Adds Claude Opus 4.8 and GPT-5.5 models; GPT-5.5 is now the default chat model.
    • Adds a MITRE coverage view for environment-level threat model analysis.
    • Adds detection notification severity filters so teams can control which detection hits trigger downstream destination notifications.
    +2 moreshow less
    • Improves Response Agents as Code with API-based schema validation, canonical YAML imports, and support for multiple GitHub sync repositories per organization.
    • Adds Tines record retrieval tools and expands VirusTotal relationship pagination for deeper investigations.
    └──▷ BREAKING ON UPGRADE
    • !GPT-5.5 replaces the previous model as the default chat model; existing workflows relying on the prior default will now use GPT-5.5.
  21. v0.63.0 seen Aug 19, 2026 · issue 001

    Cotool v0.63.0 adds Barracuda, OX Security, and Supabase integrations plus Slack emoji-reaction agent triggers.

    • New Barracuda email security integration for investigating and remediating email threats.
    • New OX Security integration to search applications, artifacts, and SBOMs and investigate issues and attack paths.
    • New Supabase integration for organization and project security posture, configuration review, and project logs.
    • Adds Slack emoji-reaction triggers so reacting to a message can run an agent.
    • Adds multi-organization GitHub App installation scoping.
    +2 moreshow less
    • Adds a per-organization session length setting in Settings.
    • Adds a minimum-severity filter for escalated alert notifications.
  22. v0.62.0 seen Aug 19, 2026 · issue 001

    Cotool v0.62.0 adds full-text Linear search, GitHub sandbox file uploads, durable agent runs, and expanded Huntress/Darktrace/Kolide integrations.

    • Adds full-text Linear issue search with team, status, archive, and comment filters.
    • Adds support for GitHub tools to upload sandbox-generated files.
    • Distinguishes API agent executions from interactive runs in audit logs.
    • Adds guided, user-approved model upgrades for agents, including supporting research for each recommendation.
    • Adds skill version history with the ability to inspect and restore earlier versions.
    +6 moreshow less
    • Makes agent runs, delegated sub-agents, tool calls, waiting prompts, and handoffs durable across worker restarts.
    • Expands Huntress support for MSP and MSSP accounts with optional organization scoping.
    • Expands Darktrace integration with actions to acknowledge, reopen, and comment on model breaches.
    • Expands Kolide report queries and improves multi-value parameter handling.
    • Adds instruction-aware integration recommendations directly in the agent builder.
    • Adds provider-native compaction for long conversations to preserve more useful context.
  23. v0.61.0 seen Aug 19, 2026 · issue 001

    Cotool v0.61.0 adds StepSecurity integration for GitHub Actions supply-chain security and a new Expired alert status with 14-day inactivity checks.

    • Adds a StepSecurity integration for investigating GitHub Actions security posture, runtime detections, network and process activity, policy evaluations, compromised components, and supply-chain threats.
    • Adds an 'Expired' alert status and 14-day inactivity checks to surface and manage stale alerts.
    • Expands the Recorded Future integration with alert and alert-rule search plus full alert detail retrieval.
    • Unifies suggested detection agents with detection-rule suggestions, adding investigation-plan review and direct acceptance into the detection builder.
    • Redesigns model settings with a searchable provider catalog, clearer Cotool Auto routing, and dedicated custom endpoint management.
    +3 moreshow less
    • Redesigns the integrations directory with search, category and connection-status filters, and clearer integration details.
    • Improves Cloudsmith setup with connect-time credential validation and owner-aware tool errors.
    • Improves sub-agent handoffs with reusable execution receipts that preserve successful tool calls and output files, reducing duplicate lookups.
  24. v0.60.0 seen Aug 19, 2026 · issue 001

    Cotool v0.60.0 adds /hunt-intel, TAXII 2.1, four new integrations, CrowdStrike Spotlight, new AI models, and Auto Model Routing.

    • Adds /hunt-intel slash command to ingest a threat report URL through the Hunt pipeline, with a dedicated timeline in chat.
    • Adds Recorded Future, Silobreaker, and TAXII 2.1 as threat intelligence sources.
    • Adds Huntress, Railway, Kolide, and Cloudsmith integrations.
    • Adds CrowdStrike Spotlight vulnerability-management actions.
    • Adds Auto Model Routing for chat and agents, letting Cotool automatically select the model backing a task.
    +7 moreshow less
    • Adds Claude Opus 5 and open-weight models including Kimi K3 and GLM 5.2, with the same data residency and ZDR guarantees as proprietary models.
    • Adds a Duplicate alert status and faster indexed alert search.
    • Adds support for creating draft GitHub pull requests.
    • Adds audit logs for agent status changes.
    • Renders CLI-based tool calls (gcloud/aws) with terminal-style visuals in chat.
    • Makes agent tag counts clickable in the UI.
    • Adds status-explainer tooltips on Threats group headers.
  25. v0.58.0 seen Aug 19, 2026 · issue 001

    Cotool v0.58.0 adds OpenCTI threat intel enrichment, GitHub-synced Agent Skills as code, and a Dismissed alert status.

    • Adds an OpenCTI threat intelligence integration for enriching investigations with threat intel.
    • Adds Agent Skills as code — skills can be managed and synced from GitHub, mirroring the existing agents-as-code workflow.
    • Adds a Dismissed status (human-only) that archives alerts without closing them.
    • Adds a Slack reply scope setting so triggers can respond to anyone in a thread or only to Cotool users.
    • Adds a service account authentication option for Jira.
    +3 moreshow less
    • Adds support for closing alerts in Obsidian.
    • Adds the ability to test output destinations directly from the UI by sending an example payload.
    • Reworks the notifications page with tabs and adds escalated-alert notifications.
  26. v0.56.0 seen Aug 19, 2026 · issue 001

    Cotool v0.56.0 adds Bugcrowd and ChartHop integrations plus Response Agents as Code with GitHub GitOps sync

    • New Bugcrowd integration with webhook triggers for vulnerability intake and response automation.
    • New ChartHop integration bringing people and organization context into investigations.
    • Response Agents as Code with GitHub GitOps sync, sample YAML agents, and managed-agent protections.
    • Adds configurable timeouts for unanswered Slack confirmations.
    • Enables response output delivery without a structured schema, making output destinations more flexible.
    +2 moreshow less
    • New sub-agent timeline drilldown in the agent execution panel.
    • Enhanced agent improvement generation to allow tool suggestions and richer review flows.
  27. v0.55.0 seen Aug 19, 2026 · issue 001

    Cotool v0.55.0 adds Darktrace, KnowBe4 PhishER, and Adaptive Shield integrations alongside agent versioning and inline chart rendering.

    • Adds a Darktrace integration for network detection and response investigations.
    • Adds a KnowBe4 integration with PhishER GraphQL support for phishing triage workflows.
    • Adds Adaptive Shield (Falcon Shield) SaaS security support to the CrowdStrike tool.
    • Adds custom Slack app integration setup.
    • Adds agent versioning to track and revert agent changes over time.
    +2 moreshow less
    • Adds inline chart rendering in the chat timeline with light and dark theming.
    • Adds the ability to reply to and follow up with built-in response agents.
  28. v0.54.0 seen Aug 19, 2026 · issue 001

    Cotool v0.54.0 adds persistent agent filesystems, Spacelift and Jira Service Management integrations, SCIM provisioning, and job dependencies.

    • Adds a Persistent Agent Filesystem so agents can save and reuse files across runs, enabling stateful workflows between executions.
    • Adds a Spacelift integration for infrastructure-as-code investigations directly from agent workflows.
    • Adds Jira Service Management alert creation as an agent output destination.
    • Adds a Linear team issue listing tool for richer ticket investigations inside agent runs.
    • Adds job dependencies so scheduled and chained jobs execute in the correct order.
    +3 moreshow less
    • Adds configurable SCIM provisioning with public SAML and SCIM identity provider documentation.
    • Adds support for sandbox file attachments in Slack messages sent from agents.
    • Enhances the executive dashboard with URL-encoded time windows, a one-year preset, and a refined date picker.
  29. v0.53.0 seen Aug 19, 2026 · issue 001

    Cotool v0.53.0 adds ExtraHop, Semgrep, ClickHouse, and Obsidian Security integrations plus GitHub blame tools and IOC/MISP intel views.

    • Adds ExtraHop RevealX, Semgrep, ClickHouse, and Obsidian Security integrations.
    • Adds GitHub commit history and blame tools for richer repository investigations.
    • Adds IOC list views and MISP Hunt intel sources for easier threat intelligence review.
    • Adds organization-level notification settings for detection and response output delivery.
    • Enhances detection workflows with evidence on detail pages, agent type filtering, cleaner hit displays, and unified run pagination.
    +4 moreshow less
    • Improves Slack agent workflows with run-button configuration and support for user replies.
    • Improves threat intelligence management by combining sources, cleaning up MISP sync, and retrying failed API sync results.
    • Enhances audit logs with richer filters, user and tool filtering, native tool hiding, and infinite scroll.
    • Improves sub-agent UX with progress previews, drawer breadcrumbs, and clearer nested agent timelines.
  30. v0.52.0 seen Aug 19, 2026 · issue 001

    Cotool v0.52.0 adds Linear ticket output for detection agents, a Linear agent trigger endpoint, evidence capture, and bulk skill imports.

    • New Linear ticket output destination for detection agents, delivering generated detections directly into Linear.
    • New Linear agent trigger endpoint for starting Linear-linked agent workflows programmatically.
    • Adds detection hit evidence capture with cited tool calls, richer query result displays, and clearer evidence review.
    • Adds bulk skill imports from folders for faster large-scale skill library setup.
    • Enhances Wiz investigations by consolidating agent tools and streamlining principal activity handling.
    +5 moreshow less
    • Improves Datadog detection authoring with better rule generation, validation, and helper coverage.
    • Improves Sumo Logic compiler feedback with stronger parsing advisories and empty-result validation.
    • Refines structured output rendering with schema previews and a cleaner detection output viewer.
    • Improves custom RSS feed setup with URL validation before feeds are saved.
    • Enhances threat intelligence ingestion with cross-source deduplication, huntability filtering, and Socket Blog support.
  31. v0.51.0 seen Aug 19, 2026 · issue 001

    Cotool v0.51.0 adds FireHydrant and Glean integrations, detection hit denoising with subagents, and bulk agent deletion.

    • New FireHydrant incident response integration brings incident context into agent workflows.
    • New Glean search and document access integration as a knowledge source for agents.
    • Detection hit denoising via subagents to reduce noisy findings in detection workflows.
    • Bulk deletion for response agents to streamline cleanup at scale.
    • Detection agent workflows now support step reordering and a redesigned detection hits interface.
    +4 moreshow less
    • Agent run acceptance criteria now evaluate errored executions, ensuring failures still produce useful feedback.
    • Structured output generation now includes retries after interrupted generation for more consistent results.
    • Sumo Logic query validation upgraded to use a formal parser, improving detection query feedback and reliability.
    • Sumo Logic environment mapping now supports editable descriptions, runtime variable updates, and larger mappings.
  32. v0.50.0 seen Aug 19, 2026 · issue 001

    Cotool v0.50.0 adds private skills, Exa web search, and detection hit workflows for agents.

    • Adds private skills to scope organization-specific workflows to specific users and agents.
    • Adds Exa web search as a selectable agent tool for retrieving fresh web context.
    • Adds detection hit workflows that let detection agents inspect hits and call tools from hit context.
    • Adds agent run rate limiting and clearer reporting for API-triggered runs.
    • Improves skills pages with better private skill visibility and invocation counts.
my-toolchain — 0 tools
paste an install list to detect your tools

A brew list, a Brewfile, requirements.txt, a Dockerfile — or just the product names, free-form. Nothing leaves your browser.

    browse all tools →