Skip to content

#190 · MCP, API, and CLI: Agents and Pipelines Finish the Fix Loop

Availability: General Availability

Your coding agent and your pipeline now run the whole triage-and-fix loop through Escape. Retests start from the MCP, and a failed scan finally fails the build.

Breaking Changes

  • Tag update (API): PUT /tags/{tagId}/{tagId} is gone. Use PUT /tags/{tagId}. escape-cli tags update returns a 404 until you upgrade the CLI.
  • Audit log filters (API): action and actor on GET /audit/logs match exactly, and actor matches the ID, not the email. Filters combine, so calls return fewer rows. Move partial and email searches to search.
  • Project slug (API): PUT /projects/{id} now validates slug (lowercase alphanumerics and hyphens, up to 256 characters). It used to ignore it.
  • Scan watching (CLI): scans watch and scans start --watch exit non-zero on failed, canceled, or unfinished scans, and errors print to stderr. The GitHub Action now enforces fail_on_severities (default HIGH).
  • Lists (MCP): List tools return 50 results plus nextCursor. scans_watch is removed: poll with scans_get.

What's New

  • Fix loop: Start and read retests, cancel scans, read problems, run manual workflows, and record a reason with severity changes.
  • Reliable tools: Schemas match inputs and outputs, and long waits return a pollable result.
  • More reach: Stats, audit logs, tags, asset updates, and role bindings are tools. Deletes and bulk changes need confirm: true.
  • API and CI: DELETE /projects/{id} and DELETE /roles/{id} respond, audit logs filter by target, and --fail-on-severity gates a scan.

MCP Server Docs → Scans CLI Docs →

What's next: AI remediation from the MCP, schema upload and conversion, and target validation before a scan.

Questions?

Have a question? Reach out on your dedicated support channel, or email us at support@escape.tech.