Cotool
v0.66.0 commercialCotool is an AI-powered security tool that analyzes code for vulnerabilities and provides automated remediation recommendations for developers.
Summary
Cotool is a commercial AI agent platform for building and running security-focused automation, run as a hosted service that connects to third-party tools rather than as a library or standalone CLI. It is aimed at security teams looking to delegate investigation and remediation work — the integration list spans email security (Barracuda), endpoint and MSP tooling (Huntress, Kolide), application security (OX Security), and network detection (Darktrace) — alongside agent-builder features like instruction-aware integration recommendations and durable, restart-safe agent runs. It sits in the category of AI coding and automation agents rather than a fixed scanning or SIEM tool, letting teams wire agents into whatever systems they already run. With 33 releases in the window we track, spanning new integrations, audit-log detail, and agent-management controls, it shows active, continuous development.
Cotool is an AI-powered security tool that analyzes code for vulnerabilities and provides automated remediation recommendations for developers.
What Cotool answers
Which security tools can an agent actually take action on, not just read from?
integrations like Darktrace, Barracuda, and Kolide support write actions such as acknowledging breaches, remediating email threats, and running reports, not just lookups
Do I need to run any infrastructure to use this?
it runs as a hosted service you connect to your existing tools, with nothing to install or host yourself
What happens if an agent is mid-task when something fails?
runs, sub-agent handoffs, tool calls, and waiting prompts survive worker restarts instead of losing state
Can I tell which actions were run by a person versus run automatically?
audit logs distinguish API-triggered executions from interactive runs
How does the platform help me pick the right integration for a given task?
the agent builder recommends integrations based on the instructions you've written, rather than requiring you to know the catalog upfront
Can I trigger an agent from tools my team already uses day to day?
a Slack emoji reaction on a message can start an agent run, without a separate console or command
Release history
- v0.66.0
Cotool v0.66.0 adds Cloudflare, Auth0, 1Password, and Tailscale integrations for investigation and alert triage.
- ›Adds a Cloudflare integration for investigating HTTP traffic, firewall events, Zero Trust Gateway activity, DNS, zones, and devices.
- ›Adds an Auth0 integration for investigating identity configurations, users, audit events, and sign-ins.
- ›Adds a 1Password integration for investigating sensitive item activity and audit events.
- ›Adds a Tailscale integration for investigating devices, users, and configuration changes across tailnets.
- ›Improves alert triage by attaching evidence to every detection hit, providing response agents with prior-alert context, duplicate handling, and escalation of uncertain cases for human review.
+5 moreshow less
- ›Enhances Slack alert notifications with concise evidence summaries, in-message status controls, and threaded follow-up with the assigned response agent.
- ›Improves the Detections overview with infinite scrolling, compact filters, bulk disable, and consistent true-positive metrics.
- ›Improves alert investigation with clearer source attribution, more readable structured payloads, and optional feedback when closing alerts as benign or false positives.
- ›Expands Linear integration with duplicate issue handling and Notion integration with paginated database queries.
- ›Improves threat models with safer regeneration, persistent progress, longer-running generation, and automatic availability to the default response agent.
- v0.65.0
Cotool v0.65.0 adds Microsoft Sentinel, Control D, and GitHub Actions integrations for log querying, DNS investigation, and PR automation.
- ›Adds a Microsoft Sentinel integration for querying logs, triaging incidents, managing analytics rules, and powering detection authoring and environment mapping.
- ›Adds a Control D integration for investigating DNS activity and managing custom filtering rules across sub-organizations.
- ›Adds GitHub Actions workflow tools for creating and updating pull requests, protected by explicit permissions.
- ›Enhances structured outputs with table-based nested data views and drag-and-drop schema editing that preserves existing fields.
- ›Improves detection coverage accuracy by linking external alerts to verified rules from connected security platforms.
- v0.50.0
Cotool v0.50.0 adds private skills, Exa web search, and detection hit workflows for agents.
- ›Adds private skills to scope organization-specific workflows to specific users and agents.
- ›Adds Exa web search as a selectable agent tool for retrieving fresh web context.
- ›Adds detection hit workflows that let detection agents inspect hits and call tools from hit context.
- ›Adds agent run rate limiting and clearer reporting for API-triggered runs.
- ›Improves skills pages with better private skill visibility and invocation counts.
- v0.51.0
Cotool v0.51.0 adds FireHydrant and Glean integrations, detection hit denoising with subagents, and bulk agent deletion.
- ›New FireHydrant incident response integration brings incident context into agent workflows.
- ›New Glean search and document access integration as a knowledge source for agents.
- ›Detection hit denoising via subagents to reduce noisy findings in detection workflows.
- ›Bulk deletion for response agents to streamline cleanup at scale.
- ›Detection agent workflows now support step reordering and a redesigned detection hits interface.
+4 moreshow less
- ›Agent run acceptance criteria now evaluate errored executions, ensuring failures still produce useful feedback.
- ›Structured output generation now includes retries after interrupted generation for more consistent results.
- ›Sumo Logic query validation upgraded to use a formal parser, improving detection query feedback and reliability.
- ›Sumo Logic environment mapping now supports editable descriptions, runtime variable updates, and larger mappings.
- v0.52.0
Cotool v0.52.0 adds Linear ticket output for detection agents, a Linear agent trigger endpoint, evidence capture, and bulk skill imports.
- ›New Linear ticket output destination for detection agents, delivering generated detections directly into Linear.
- ›New Linear agent trigger endpoint for starting Linear-linked agent workflows programmatically.
- ›Adds detection hit evidence capture with cited tool calls, richer query result displays, and clearer evidence review.
- ›Adds bulk skill imports from folders for faster large-scale skill library setup.
- ›Enhances Wiz investigations by consolidating agent tools and streamlining principal activity handling.
+5 moreshow less
- ›Improves Datadog detection authoring with better rule generation, validation, and helper coverage.
- ›Improves Sumo Logic compiler feedback with stronger parsing advisories and empty-result validation.
- ›Refines structured output rendering with schema previews and a cleaner detection output viewer.
- ›Improves custom RSS feed setup with URL validation before feeds are saved.
- ›Enhances threat intelligence ingestion with cross-source deduplication, huntability filtering, and Socket Blog support.
- v0.53.0
Cotool v0.53.0 adds ExtraHop, Semgrep, ClickHouse, and Obsidian Security integrations plus GitHub blame tools and IOC/MISP intel views.
- ›Adds ExtraHop RevealX, Semgrep, ClickHouse, and Obsidian Security integrations.
- ›Adds GitHub commit history and blame tools for richer repository investigations.
- ›Adds IOC list views and MISP Hunt intel sources for easier threat intelligence review.
- ›Adds organization-level notification settings for detection and response output delivery.
- ›Enhances detection workflows with evidence on detail pages, agent type filtering, cleaner hit displays, and unified run pagination.
+4 moreshow less
- ›Improves Slack agent workflows with run-button configuration and support for user replies.
- ›Improves threat intelligence management by combining sources, cleaning up MISP sync, and retrying failed API sync results.
- ›Enhances audit logs with richer filters, user and tool filtering, native tool hiding, and infinite scroll.
- ›Improves sub-agent UX with progress previews, drawer breadcrumbs, and clearer nested agent timelines.
- v0.54.0
Cotool v0.54.0 adds persistent agent filesystems, Spacelift and Jira Service Management integrations, SCIM provisioning, and job dependencies.
- ›Adds a Persistent Agent Filesystem so agents can save and reuse files across runs, enabling stateful workflows between executions.
- ›Adds a Spacelift integration for infrastructure-as-code investigations directly from agent workflows.
- ›Adds Jira Service Management alert creation as an agent output destination.
- ›Adds a Linear team issue listing tool for richer ticket investigations inside agent runs.
- ›Adds job dependencies so scheduled and chained jobs execute in the correct order.
+3 moreshow less
- ›Adds configurable SCIM provisioning with public SAML and SCIM identity provider documentation.
- ›Adds support for sandbox file attachments in Slack messages sent from agents.
- ›Enhances the executive dashboard with URL-encoded time windows, a one-year preset, and a refined date picker.
- v0.55.0
Cotool v0.55.0 adds Darktrace, KnowBe4 PhishER, and Adaptive Shield integrations alongside agent versioning and inline chart rendering.
- ›Adds a Darktrace integration for network detection and response investigations.
- ›Adds a KnowBe4 integration with PhishER GraphQL support for phishing triage workflows.
- ›Adds Adaptive Shield (Falcon Shield) SaaS security support to the CrowdStrike tool.
- ›Adds custom Slack app integration setup.
- ›Adds agent versioning to track and revert agent changes over time.
+2 moreshow less
- ›Adds inline chart rendering in the chat timeline with light and dark theming.
- ›Adds the ability to reply to and follow up with built-in response agents.
- v0.56.0
Cotool v0.56.0 adds Bugcrowd and ChartHop integrations plus Response Agents as Code with GitHub GitOps sync
- ›New Bugcrowd integration with webhook triggers for vulnerability intake and response automation.
- ›New ChartHop integration bringing people and organization context into investigations.
- ›Response Agents as Code with GitHub GitOps sync, sample YAML agents, and managed-agent protections.
- ›Adds configurable timeouts for unanswered Slack confirmations.
- ›Enables response output delivery without a structured schema, making output destinations more flexible.
+2 moreshow less
- ›New sub-agent timeline drilldown in the agent execution panel.
- ›Enhanced agent improvement generation to allow tool suggestions and richer review flows.
- v0.57.0
Cotool v0.57.0 adds a full Alerts system for security triage, a HackerOne connector, new AI models, and MITRE coverage views.
- ›Adds first-class Alerts for security triage, including an alert inbox, detail pages, activity timelines, comments, assignments, dispositions, bulk actions, and response-agent triage.
- ›Adds a HackerOne connector with webhook-triggered alert intake for vulnerability response workflows.
- ›Adds Claude Opus 4.8 and GPT-5.5 models; GPT-5.5 is now the default chat model.
- ›Adds a MITRE coverage view for environment-level threat model analysis.
- ›Adds detection notification severity filters so teams can control which detection hits trigger downstream destination notifications.
+2 moreshow less
- ›Improves Response Agents as Code with API-based schema validation, canonical YAML imports, and support for multiple GitHub sync repositories per organization.
- ›Adds Tines record retrieval tools and expands VirusTotal relationship pagination for deeper investigations.
└──▷ BREAKING ON UPGRADE- !GPT-5.5 replaces the previous model as the default chat model; existing workflows relying on the prior default will now use GPT-5.5.
- v0.58.0
Cotool v0.58.0 adds OpenCTI threat intel enrichment, GitHub-synced Agent Skills as code, and a Dismissed alert status.
- ›Adds an OpenCTI threat intelligence integration for enriching investigations with threat intel.
- ›Adds Agent Skills as code — skills can be managed and synced from GitHub, mirroring the existing agents-as-code workflow.
- ›Adds a Dismissed status (human-only) that archives alerts without closing them.
- ›Adds a Slack reply scope setting so triggers can respond to anyone in a thread or only to Cotool users.
- ›Adds a service account authentication option for Jira.
+3 moreshow less
- ›Adds support for closing alerts in Obsidian.
- ›Adds the ability to test output destinations directly from the UI by sending an example payload.
- ›Reworks the notifications page with tabs and adds escalated-alert notifications.
- v0.59.0
Cotool v0.59.0 launches Hunt V2 continuous threat intelligence, slash commands in chat, GPT-5.6 models, and a canonical audit-log event catalog endpoint.
- ›Adds a canonical audit-log event catalog endpoint with documentation, giving practitioners a single authoritative source for audit event types.
- ›Introduces Hunt V2: continuously assesses incoming threat intelligence against your environment, hunts for exposure, and raises alerts with a verdict when a threat is relevant to your organization.
- ›Adds slash commands to chat with persisted commands for detection agents and a refreshed command header in the chat input.
- ›Adds GPT-5.6 models and makes GPT-5.6 Sol the default chat model.
- ›Adds separate personal and organization skill namespaces.
+5 moreshow less
- ›Adds Linear label support.
- ›Adds bulk dismiss for detection suggestions.
- ›Webhook URLs and secrets are now visible on GitOps-managed triggers.
- ›Sub-agent tool chips now link to the agent details page.
- ›Adds contextual Cmd+K status commands to the bulk selection experience on the Alerts page.
- v0.60.0
Cotool v0.60.0 adds
/hunt-intel, TAXII 2.1, four new integrations, CrowdStrike Spotlight, new AI models, and Auto Model Routing.- ›Adds
/hunt-intelslash command to ingest a threat report URL through the Hunt pipeline, with a dedicated timeline in chat. - ›Adds Recorded Future, Silobreaker, and TAXII 2.1 as threat intelligence sources.
- ›Adds Huntress, Railway, Kolide, and Cloudsmith integrations.
- ›Adds CrowdStrike Spotlight vulnerability-management actions.
- ›Adds Auto Model Routing for chat and agents, letting Cotool automatically select the model backing a task.
+7 moreshow less
- ›Adds Claude Opus 5 and open-weight models including Kimi K3 and GLM 5.2, with the same data residency and ZDR guarantees as proprietary models.
- ›Adds a Duplicate alert status and faster indexed alert search.
- ›Adds support for creating draft GitHub pull requests.
- ›Adds audit logs for agent status changes.
- ›Renders CLI-based tool calls (
gcloud/aws) with terminal-style visuals in chat. - ›Makes agent tag counts clickable in the UI.
- ›Adds status-explainer tooltips on Threats group headers.
- ›Adds
- v0.61.0
Cotool v0.61.0 adds StepSecurity integration for GitHub Actions supply-chain security and a new Expired alert status with 14-day inactivity checks.
- ›Adds a StepSecurity integration for investigating GitHub Actions security posture, runtime detections, network and process activity, policy evaluations, compromised components, and supply-chain threats.
- ›Adds an 'Expired' alert status and 14-day inactivity checks to surface and manage stale alerts.
- ›Expands the Recorded Future integration with alert and alert-rule search plus full alert detail retrieval.
- ›Unifies suggested detection agents with detection-rule suggestions, adding investigation-plan review and direct acceptance into the detection builder.
- ›Redesigns model settings with a searchable provider catalog, clearer Cotool Auto routing, and dedicated custom endpoint management.
+3 moreshow less
- ›Redesigns the integrations directory with search, category and connection-status filters, and clearer integration details.
- ›Improves Cloudsmith setup with connect-time credential validation and owner-aware tool errors.
- ›Improves sub-agent handoffs with reusable execution receipts that preserve successful tool calls and output files, reducing duplicate lookups.
- v0.62.0
Cotool v0.62.0 adds full-text Linear search, GitHub sandbox file uploads, durable agent runs, and expanded Huntress/Darktrace/Kolide integrations.
- ›Adds full-text Linear issue search with team, status, archive, and comment filters.
- ›Adds support for GitHub tools to upload sandbox-generated files.
- ›Distinguishes API agent executions from interactive runs in audit logs.
- ›Adds guided, user-approved model upgrades for agents, including supporting research for each recommendation.
- ›Adds skill version history with the ability to inspect and restore earlier versions.
+6 moreshow less
- ›Makes agent runs, delegated sub-agents, tool calls, waiting prompts, and handoffs durable across worker restarts.
- ›Expands Huntress support for MSP and MSSP accounts with optional organization scoping.
- ›Expands Darktrace integration with actions to acknowledge, reopen, and comment on model breaches.
- ›Expands Kolide report queries and improves multi-value parameter handling.
- ›Adds instruction-aware integration recommendations directly in the agent builder.
- ›Adds provider-native compaction for long conversations to preserve more useful context.
- v0.63.0
Cotool v0.63.0 adds Barracuda, OX Security, and Supabase integrations plus Slack emoji-reaction agent triggers.
- ›New Barracuda email security integration for investigating and remediating email threats.
- ›New OX Security integration to search applications, artifacts, and SBOMs and investigate issues and attack paths.
- ›New Supabase integration for organization and project security posture, configuration review, and project logs.
- ›Adds Slack emoji-reaction triggers so reacting to a message can run an agent.
- ›Adds multi-organization GitHub App installation scoping.
+2 moreshow less
- ›Adds a per-organization session length setting in Settings.
- ›Adds a minimum-severity filter for escalated alert notifications.
- v0.64.0
Cotool v0.64.0 adds Zscaler and Darktrace integrations, response agents from chat or templates, and a redesigned navigation.
- ›Adds a Zscaler integration covering ZIA, ZPA, ZDX, and Client Connector tools, with detection-rule sync, alert triggers, and permission validation.
- ›Adds first-class Darktrace webhook triggers so response agents can run immediately on model-breach and AI Analyst alerts.
- ›Enables creating response agents directly from chat or from templates.
- ›Redesigns navigation and page layouts around Home, Detect, Hunt, Respond, Knowledge, Platform, and Settings sections, with consistent breadcrumbs and backward-compatible existing links.
- ›Adds live progress from delegated agents to chat and agent timelines.
+1 moreshow less
- ›Expands Linear, Silobreaker, and Notion integrations with parent-child issue updates, broader threat-intelligence research, and complete nested page content.
- v0.59.0
Cotool v0.59.0 launches Hunt V2 continuous threat intelligence, slash commands in chat, GPT-5.6 models, and a canonical audit-log event catalog endpoint.
- ›Adds a canonical audit-log event catalog endpoint with documentation, giving practitioners a single authoritative source for audit event types.
- ›Introduces Hunt V2: continuously assesses incoming threat intelligence against your environment, hunts for exposure, and raises alerts with a verdict when a threat is relevant to your organization.
- ›Adds slash commands to chat with persisted commands for detection agents and a refreshed command header in the chat input.
- ›Adds GPT-5.6 models and makes GPT-5.6 Sol the default chat model.
- ›Adds separate personal and organization skill namespaces.
+5 moreshow less
- ›Adds Linear label support.
- ›Adds bulk dismiss for detection suggestions.
- ›Webhook URLs and secrets are now visible on GitOps-managed triggers.
- ›Sub-agent tool chips now link to the agent details page.
- ›Adds contextual Cmd+K status commands to the bulk selection experience on the Alerts page.
- v0.64.0
Cotool v0.64.0 adds Zscaler and Darktrace integrations, response agents from chat or templates, and a redesigned navigation.
- ›Adds a Zscaler integration covering ZIA, ZPA, ZDX, and Client Connector tools, with detection-rule sync, alert triggers, and permission validation.
- ›Adds first-class Darktrace webhook triggers so response agents can run immediately on model-breach and AI Analyst alerts.
- ›Enables creating response agents directly from chat or from templates.
- ›Redesigns navigation and page layouts around Home, Detect, Hunt, Respond, Knowledge, Platform, and Settings sections, with consistent breadcrumbs and backward-compatible existing links.
- ›Adds live progress from delegated agents to chat and agent timelines.
+1 moreshow less
- ›Expands Linear, Silobreaker, and Notion integrations with parent-child issue updates, broader threat-intelligence research, and complete nested page content.
- v0.57.0
Cotool v0.57.0 adds a full Alerts system for security triage, a HackerOne connector, new AI models, and MITRE coverage views.
- ›Adds first-class Alerts for security triage, including an alert inbox, detail pages, activity timelines, comments, assignments, dispositions, bulk actions, and response-agent triage.
- ›Adds a HackerOne connector with webhook-triggered alert intake for vulnerability response workflows.
- ›Adds Claude Opus 4.8 and GPT-5.5 models; GPT-5.5 is now the default chat model.
- ›Adds a MITRE coverage view for environment-level threat model analysis.
- ›Adds detection notification severity filters so teams can control which detection hits trigger downstream destination notifications.
+2 moreshow less
- ›Improves Response Agents as Code with API-based schema validation, canonical YAML imports, and support for multiple GitHub sync repositories per organization.
- ›Adds Tines record retrieval tools and expands VirusTotal relationship pagination for deeper investigations.
└──▷ BREAKING ON UPGRADE- !GPT-5.5 replaces the previous model as the default chat model; existing workflows relying on the prior default will now use GPT-5.5.
- v0.63.0
Cotool v0.63.0 adds Barracuda, OX Security, and Supabase integrations plus Slack emoji-reaction agent triggers.
- ›New Barracuda email security integration for investigating and remediating email threats.
- ›New OX Security integration to search applications, artifacts, and SBOMs and investigate issues and attack paths.
- ›New Supabase integration for organization and project security posture, configuration review, and project logs.
- ›Adds Slack emoji-reaction triggers so reacting to a message can run an agent.
- ›Adds multi-organization GitHub App installation scoping.
+2 moreshow less
- ›Adds a per-organization session length setting in Settings.
- ›Adds a minimum-severity filter for escalated alert notifications.
- v0.62.0
Cotool v0.62.0 adds full-text Linear search, GitHub sandbox file uploads, durable agent runs, and expanded Huntress/Darktrace/Kolide integrations.
- ›Adds full-text Linear issue search with team, status, archive, and comment filters.
- ›Adds support for GitHub tools to upload sandbox-generated files.
- ›Distinguishes API agent executions from interactive runs in audit logs.
- ›Adds guided, user-approved model upgrades for agents, including supporting research for each recommendation.
- ›Adds skill version history with the ability to inspect and restore earlier versions.
+6 moreshow less
- ›Makes agent runs, delegated sub-agents, tool calls, waiting prompts, and handoffs durable across worker restarts.
- ›Expands Huntress support for MSP and MSSP accounts with optional organization scoping.
- ›Expands Darktrace integration with actions to acknowledge, reopen, and comment on model breaches.
- ›Expands Kolide report queries and improves multi-value parameter handling.
- ›Adds instruction-aware integration recommendations directly in the agent builder.
- ›Adds provider-native compaction for long conversations to preserve more useful context.
- v0.61.0
Cotool v0.61.0 adds StepSecurity integration for GitHub Actions supply-chain security and a new Expired alert status with 14-day inactivity checks.
- ›Adds a StepSecurity integration for investigating GitHub Actions security posture, runtime detections, network and process activity, policy evaluations, compromised components, and supply-chain threats.
- ›Adds an 'Expired' alert status and 14-day inactivity checks to surface and manage stale alerts.
- ›Expands the Recorded Future integration with alert and alert-rule search plus full alert detail retrieval.
- ›Unifies suggested detection agents with detection-rule suggestions, adding investigation-plan review and direct acceptance into the detection builder.
- ›Redesigns model settings with a searchable provider catalog, clearer Cotool Auto routing, and dedicated custom endpoint management.
+3 moreshow less
- ›Redesigns the integrations directory with search, category and connection-status filters, and clearer integration details.
- ›Improves Cloudsmith setup with connect-time credential validation and owner-aware tool errors.
- ›Improves sub-agent handoffs with reusable execution receipts that preserve successful tool calls and output files, reducing duplicate lookups.
- v0.60.0
Cotool v0.60.0 adds
/hunt-intel, TAXII 2.1, four new integrations, CrowdStrike Spotlight, new AI models, and Auto Model Routing.- ›Adds
/hunt-intelslash command to ingest a threat report URL through the Hunt pipeline, with a dedicated timeline in chat. - ›Adds Recorded Future, Silobreaker, and TAXII 2.1 as threat intelligence sources.
- ›Adds Huntress, Railway, Kolide, and Cloudsmith integrations.
- ›Adds CrowdStrike Spotlight vulnerability-management actions.
- ›Adds Auto Model Routing for chat and agents, letting Cotool automatically select the model backing a task.
+7 moreshow less
- ›Adds Claude Opus 5 and open-weight models including Kimi K3 and GLM 5.2, with the same data residency and ZDR guarantees as proprietary models.
- ›Adds a Duplicate alert status and faster indexed alert search.
- ›Adds support for creating draft GitHub pull requests.
- ›Adds audit logs for agent status changes.
- ›Renders CLI-based tool calls (
gcloud/aws) with terminal-style visuals in chat. - ›Makes agent tag counts clickable in the UI.
- ›Adds status-explainer tooltips on Threats group headers.
- ›Adds
- v0.58.0
Cotool v0.58.0 adds OpenCTI threat intel enrichment, GitHub-synced Agent Skills as code, and a Dismissed alert status.
- ›Adds an OpenCTI threat intelligence integration for enriching investigations with threat intel.
- ›Adds Agent Skills as code — skills can be managed and synced from GitHub, mirroring the existing agents-as-code workflow.
- ›Adds a Dismissed status (human-only) that archives alerts without closing them.
- ›Adds a Slack reply scope setting so triggers can respond to anyone in a thread or only to Cotool users.
- ›Adds a service account authentication option for Jira.
+3 moreshow less
- ›Adds support for closing alerts in Obsidian.
- ›Adds the ability to test output destinations directly from the UI by sending an example payload.
- ›Reworks the notifications page with tabs and adds escalated-alert notifications.
- v0.56.0
Cotool v0.56.0 adds Bugcrowd and ChartHop integrations plus Response Agents as Code with GitHub GitOps sync
- ›New Bugcrowd integration with webhook triggers for vulnerability intake and response automation.
- ›New ChartHop integration bringing people and organization context into investigations.
- ›Response Agents as Code with GitHub GitOps sync, sample YAML agents, and managed-agent protections.
- ›Adds configurable timeouts for unanswered Slack confirmations.
- ›Enables response output delivery without a structured schema, making output destinations more flexible.
+2 moreshow less
- ›New sub-agent timeline drilldown in the agent execution panel.
- ›Enhanced agent improvement generation to allow tool suggestions and richer review flows.
- v0.55.0
Cotool v0.55.0 adds Darktrace, KnowBe4 PhishER, and Adaptive Shield integrations alongside agent versioning and inline chart rendering.
- ›Adds a Darktrace integration for network detection and response investigations.
- ›Adds a KnowBe4 integration with PhishER GraphQL support for phishing triage workflows.
- ›Adds Adaptive Shield (Falcon Shield) SaaS security support to the CrowdStrike tool.
- ›Adds custom Slack app integration setup.
- ›Adds agent versioning to track and revert agent changes over time.
+2 moreshow less
- ›Adds inline chart rendering in the chat timeline with light and dark theming.
- ›Adds the ability to reply to and follow up with built-in response agents.
- v0.54.0
Cotool v0.54.0 adds persistent agent filesystems, Spacelift and Jira Service Management integrations, SCIM provisioning, and job dependencies.
- ›Adds a Persistent Agent Filesystem so agents can save and reuse files across runs, enabling stateful workflows between executions.
- ›Adds a Spacelift integration for infrastructure-as-code investigations directly from agent workflows.
- ›Adds Jira Service Management alert creation as an agent output destination.
- ›Adds a Linear team issue listing tool for richer ticket investigations inside agent runs.
- ›Adds job dependencies so scheduled and chained jobs execute in the correct order.
+3 moreshow less
- ›Adds configurable SCIM provisioning with public SAML and SCIM identity provider documentation.
- ›Adds support for sandbox file attachments in Slack messages sent from agents.
- ›Enhances the executive dashboard with URL-encoded time windows, a one-year preset, and a refined date picker.
- v0.53.0
Cotool v0.53.0 adds ExtraHop, Semgrep, ClickHouse, and Obsidian Security integrations plus GitHub blame tools and IOC/MISP intel views.
- ›Adds ExtraHop RevealX, Semgrep, ClickHouse, and Obsidian Security integrations.
- ›Adds GitHub commit history and blame tools for richer repository investigations.
- ›Adds IOC list views and MISP Hunt intel sources for easier threat intelligence review.
- ›Adds organization-level notification settings for detection and response output delivery.
- ›Enhances detection workflows with evidence on detail pages, agent type filtering, cleaner hit displays, and unified run pagination.
+4 moreshow less
- ›Improves Slack agent workflows with run-button configuration and support for user replies.
- ›Improves threat intelligence management by combining sources, cleaning up MISP sync, and retrying failed API sync results.
- ›Enhances audit logs with richer filters, user and tool filtering, native tool hiding, and infinite scroll.
- ›Improves sub-agent UX with progress previews, drawer breadcrumbs, and clearer nested agent timelines.
- v0.52.0
Cotool v0.52.0 adds Linear ticket output for detection agents, a Linear agent trigger endpoint, evidence capture, and bulk skill imports.
- ›New Linear ticket output destination for detection agents, delivering generated detections directly into Linear.
- ›New Linear agent trigger endpoint for starting Linear-linked agent workflows programmatically.
- ›Adds detection hit evidence capture with cited tool calls, richer query result displays, and clearer evidence review.
- ›Adds bulk skill imports from folders for faster large-scale skill library setup.
- ›Enhances Wiz investigations by consolidating agent tools and streamlining principal activity handling.
+5 moreshow less
- ›Improves Datadog detection authoring with better rule generation, validation, and helper coverage.
- ›Improves Sumo Logic compiler feedback with stronger parsing advisories and empty-result validation.
- ›Refines structured output rendering with schema previews and a cleaner detection output viewer.
- ›Improves custom RSS feed setup with URL validation before feeds are saved.
- ›Enhances threat intelligence ingestion with cross-source deduplication, huntability filtering, and Socket Blog support.
- v0.51.0
Cotool v0.51.0 adds FireHydrant and Glean integrations, detection hit denoising with subagents, and bulk agent deletion.
- ›New FireHydrant incident response integration brings incident context into agent workflows.
- ›New Glean search and document access integration as a knowledge source for agents.
- ›Detection hit denoising via subagents to reduce noisy findings in detection workflows.
- ›Bulk deletion for response agents to streamline cleanup at scale.
- ›Detection agent workflows now support step reordering and a redesigned detection hits interface.
+4 moreshow less
- ›Agent run acceptance criteria now evaluate errored executions, ensuring failures still produce useful feedback.
- ›Structured output generation now includes retries after interrupted generation for more consistent results.
- ›Sumo Logic query validation upgraded to use a formal parser, improving detection query feedback and reliability.
- ›Sumo Logic environment mapping now supports editable descriptions, runtime variable updates, and larger mappings.
- v0.50.0
Cotool v0.50.0 adds private skills, Exa web search, and detection hit workflows for agents.
- ›Adds private skills to scope organization-specific workflows to specific users and agents.
- ›Adds Exa web search as a selectable agent tool for retrieving fresh web context.
- ›Adds detection hit workflows that let detection agents inspect hits and call tools from hit context.
- ›Adds agent run rate limiting and clearer reporting for API-triggered runs.
- ›Improves skills pages with better private skill visibility and invocation counts.