Conversation
Document the psirt toolset of the DefectDojo Pro MCP Server on the MCP Server page (toolset and URL tables, a PSIRT Toolset section with the 12 read tools, 6 write tools, 2 resources and 3 prompts, and the resource, prompt and troubleshooting lists) and cross-link it from the PSIRT chapter index. Amp-Thread-ID: https://ampcode.com/threads/T-01a08eca-ec9b-72d9-a1a6-58858715eabd Co-authored-by: Amp <amp@ampcode.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Documentation only. The DefectDojo Pro MCP Server gains a fifth toolset,
psirt, on top of the always-oncoretoolset and the existinghierarchy,reportinganddashboardstoolsets. The MCP Server page already explains how toolsets are selected (?toolsets=…) and gated (Feature Flags), but has no mention of PSIRT. This PR adds the toolset to the existing tables and lists, adds a section describing what it does, and adds one cross-link from the PSIRT chapter so readers of those pages learn the toolset exists.Changes in
docs/content/metrics_reports/ai/mcp_server_pro.md:psirtrow (Feature Flag MCP: PSIRT, which can only be enabled while the PSIRT flag is on — itself dependent on Locations and the PSIRT Advisory Engine licence entitlement) and example URLs for?toolsets=psirtand the all-toolsets combination?toolsets=hierarchy,reporting,dashboards,psirt./api/v2/psirt/routes, and the View PSIRT / Change PSIRT permissions the read and write tools run under); a call-out separating the two things the UI calls "advisories" — feed items from external publishers (feed_item_id) and advisories your own team authors (advisory_id) — since every tool name and argument follows that split; a call-out that feed content is third-party text the assistant must not treat as instructions; a table of the 12 read tools (psirt_triage_summary,psirt_get_feed_items,psirt_get_feed_item,psirt_get_feed_sources,psirt_get_rules,psirt_get_rule,psirt_preview_rule,psirt_assess_rule,psirt_get_matches,psirt_get_cases,psirt_get_authored_advisories,psirt_get_sla_clocks); a table of the 6 write tools (psirt_triage_feed_item,psirt_write_rule,psirt_write_prefilter,psirt_set_match_status,psirt_manage_case,psirt_manage_advisory); the shared write-result envelope; the two resources (mcp://resource/psirt/rule-schema.json,mcp://resource/psirt/workflow-guide.md); the three prompts (psirt_daily_triage,psirt_explain_match,psirt_design_rule); and example requests. The write call-out follows the pattern of the other toolsets — one REST write per call under DefectDojo's own permission checks, no preview/approval/undo in the server — and adds the PSIRT-specific point that scheduling or publishing an authored advisory cannot be undone, which is whypsirt_manage_advisoryis marked destructive as a whole and the assistant is instructed to publish only on explicit request.psirtadditions alongside the other add-on toolsets' resources and prompts.psirtflag and its prerequisite feature, as it already does for the other three toolsets.Change in
docs/content/psirt/_index.md:?toolsets=psirt) and noting it runs under the same permissions as the PSIRT pages.Each PSIRT page the new section links to (
psirt/,psirt/feeds/,psirt/feed-rules/,psirt/matching-rules/,psirt/feed-findings/,psirt/cases/,psirt/advisories/) already exists onbugfix; the section links into their existing headings rather than repeating UI behaviour.Tool names, arguments, counts, resource URIs, prompt names and the destructive/irreversible wording were checked against the MCP Server source for this release (
psirt.go,psirt_write.go,resources/psirt/), and the permission and flag statements against the DefectDojo Pro PSIRT API permission class and feature-flag registry that ship in 3.4.100.Test results
No code changes. The site was built with Hugo from
docs/with no errors; the rendered MCP page contains the new#psirt-toolsetanchor, both tool tables and the three call-outs render as tables/blockquotes (no raw Markdown), and all 23 links from the new section — including every anchor into the PSIRT chapter pages — resolve to an existing page and heading id in the rendered output. The new link frompsirt/tometrics_reports/ai/mcp_server_pro/#psirt-toolsetalso resolves.Documentation
This PR is the documentation.
Checklist
bugfix(patch line; docs for a feature shipping in a patch release)docs/docs