Escape Copilot¶
Overview¶
Escape Copilot uses the Model Context Protocol (MCP) to give you natural language access to application management, security scanning, and vulnerability analysis.
Key Benefits:
- Natural Language Interface: Interact with the Escape platform using conversational queries
- Context-Aware Responses: Receive tailored recommendations based on your specific security data
- Workflow Automation: Automate complex security operations through simple commands
- Intelligent Analysis: Get AI-powered insights into vulnerability findings and security posture
Copilot Capabilities¶
Profile Management¶
Read, create, and update scan profiles through the available platform tools. Tool access depends on your account permissions.
Scan Management¶
Start Scans¶
Initiate security scans through natural language commands. Specify application names, scan types, or use defaults for quick execution.
Check Scan Status¶
Monitor the progress and status of ongoing or completed scans. Receive real-time updates on scan phases and completion estimates.
List Scan Issues¶
Access detailed reports highlighting vulnerabilities and security issues detected during scans. Filter by severity, category, or affected component.
List Scan Events¶
Review chronological events associated with scans, providing insights into the scanning process, authentication flow, and discovered endpoints.
Domain Management¶
Create Domains¶
Add new fully qualified domain names (FQDNs) to your attack surface management scope through conversational commands.
Delete Domains¶
Remove unnecessary or obsolete domains from your managed list using natural language.
List Domains¶
View a comprehensive list of all domains under management, including discovery status, DNS records, and associated vulnerabilities.
Get Domain Details¶
Retrieve detailed information about specific domains, including subdomains, certificates, services, and security findings.
Issues and Workflows¶
List issues, update their status or severity, and add comments through available tools. You can also inspect and manage workflows, subject to your permissions.
Coverage, Reasoning, and Documentation¶
Ask which surfaces were tested and which users reached them, or inspect assessment reasoning. Copilot can answer Escape documentation and Public API questions. It receives page context, so you can refer to the profile or assessment you're viewing.
When enabled for your organization, the Reasoning tab includes Ask anything about this assessment, a Copilot entry point.
Usage Examples¶
Starting a scan:
Checking vulnerabilities:
"Show me critical issues from the last scan"
"What XSS vulnerabilities were found in my application?"
Managing applications:
"Create a new REST API application for https://api.example.com"
"Update the scan schedule for my staging environment"
Domain management:
Privacy and Security¶
Data Scope¶
Your Copilot interactions are entirely scoped to your Public API access level. The Copilot can only access and modify resources that your user account has permissions for.
Hosting¶
See the AI Policy for how Copilot data is handled.
Data Handling¶
- Secure Processing: All queries and responses are transmitted over encrypted connections
- Conversation History: Conversations are persisted per-user so you can resume previous chats. You can delete any conversation from the history sidebar at any time.
- Access Control: API operations are subject to your organization's role-based access controls
- Audit Trail: All operations performed through the Copilot are logged in your organization's audit log
Best Practices¶
- Share Minimal Data: Provide only the information necessary for the Copilot to complete your request
- Avoid Sensitive Information: Don't share production credentials, API keys, or other sensitive data in queries
- Verify Operations: Review suggested actions before confirming destructive operations (deletions, configuration changes)
Scope and Usage¶
Operational Scope¶
Copilot operates on Escape resources through platform tools. The following tasks are outside its tool scope:
- General programming assistance or code generation
- Non-security-related queries
- Access to external systems or third-party APIs
- File system access or local environment operations
Usage Controls¶
- Public API Controls: Copilot uses the Public API's rate limits and constraints
- Feature Access: Available tools determine which operations you can perform
- Clear Requests: Specify the resource and action you want. Rephrase complex or ambiguous queries if Copilot needs clarification
- Conversation Context: For very long conversations, start a new chat to give Copilot a fresh context
Getting Started¶
In the Escape Platform¶
The Copilot is built into the Escape platform. Press ⌘K (macOS) or Ctrl+K (Windows/Linux) to open the unified command palette, then switch to the AI Copilot tab to start a conversation. Your chat history is preserved across sessions: use the sidebar to browse, search, or delete past conversations.
Via MCP in Your IDE¶
To access the Copilot from your development environment:
- Configure MCP Integration: Follow the MCP overview guide to understand authentication requirements
- Set Up Your Environment: Use the IDE Integration Guide to connect your development environment
- Authenticate: Use OAuth where your client supports it, or obtain an API key from your User Settings for the static-key flow
- Start Interacting: Begin asking questions and executing operations through your AI assistant
Related Documentation¶
- MCP Overview - Introduction to the Model Context Protocol
- IDE Integration Guide - Configure MCP in your development environment
- Public API Documentation - Complete API reference
- Application Management - Application security scanning
- Business Logic Aware DAST Scanning - Dynamic application security testing
Feedback and Support¶
- Share your experience and suggestions through the Escape dashboard
- Report issues or unexpected behavior to support
- Request new capabilities or improvements through your customer success contact
For technical support or questions about the Copilot, consult the MCP troubleshooting guide or contact Escape support.