Skip to content

Regression Testing Agent

When you attach a previous pentest report, Escape tests the reported vulnerabilities against the current target to check whether they're still reproducible. This complements issue replay, which re-checks findings from previous Escape assessments.

It's designed for retesting after a fix, before release, or during recurring security validation campaigns.

What It Does

  • Consumes uploaded pentest reports: Uses uploaded report files as replay source material
  • Builds executable replay plans: Extracts reproducible vulnerabilities and converts them into ordered action checklists
  • Replays each plan item: Executes one vulnerability at a time on the current target asset
  • Validates replay signals: Confirms findings with concrete evidence before reporting
  • Publishes replay issues: Produces findings with report context and execution evidence

Supported Assets

  • Frontend web applications (frontend)
  • REST API services (api_service_rest)
  • GraphQL API services (api_service_graphql)

The agent automatically switches to browser-driven replay for frontend assets and HTTP-driven replay for API assets.

How It's Used

In the New Profile form, open Fine-Tune (Optional), then Artifacts. Upload the PDF or Markdown pentest reports you want the Regression Testing Agent to replay.

Uploaded artifacts are attached to the pentest workflow and surfaced to the scanner. The agent lists the workflow's attached files and uses them as source material for replay planning.

The Regression Testing Agent runs automatically when uploaded artifacts provide replay material for the assessment. Configure that material through Artifacts in the New Profile form; the agent page has no separate execution controls.

Authentication and Scope

Replay execution honors the standard authentication and scope configuration of the asset under assessment:

  • Frontend replay uses frontend auth and frontend scope settings
  • API replay uses REST/GraphQL scope settings and authenticated HTTP client execution

Replay Scope

  • Use PDF and Markdown (.md, .markdown) reports for replay plan extraction. Other artifact types can provide assessment context; a Replay file type not supported warning identifies files this stage can't process
  • Provide actionable reproduction steps in the original report so Escape can build executable replay plans
  • All actions stay within configured scope boundaries
  • Replay execution remains bounded by assessment timeout and model budget limits

Best Practices

  • Upload pentest reports with clear, step-by-step reproduction instructions
  • Include expected signals (error messages, DOM changes, outbound callbacks) in reports
  • Run replay assessments after remediation to confirm closure
  • Keep scope precise to reduce noisy or irrelevant replays