{"generated_at":"2026-08-25T03:28:32.071Z","feeds":{"manifest":"/marketplace-control-plane.json","catalog":"/marketplace-catalog.json","input_channels":"/marketplace-input-channels.json","output_channels":"/marketplace-output-channels.json","report_profiles":"/marketplace-report-profiles.json","workflow_templates":"/marketplace-workflow-templates.json","readiness":"/marketplace-readiness.json"},"schemas":{"index":"/marketplace-schemas/index.json","input_channel_contribution":"/marketplace-schemas/input-channel-contribution.schema.json","output_channel_contribution":"/marketplace-schemas/output-channel-contribution.schema.json","report_profile_contribution":"/marketplace-schemas/report-profile-contribution.schema.json","workflow_template_contribution":"/marketplace-schemas/workflow-template-contribution.schema.json","local_library":"/marketplace-schemas/local-library.schema.json","case_file":"/marketplace-schemas/case-file.schema.json","case_library":"/marketplace-schemas/case-library.schema.json","asset_library":"/marketplace-schemas/asset-library.schema.json","operations_history":"/marketplace-schemas/operations-history.schema.json","operations_session":"/marketplace-schemas/operations-session.schema.json","portfolio_coverage":"/marketplace-schemas/portfolio-coverage.schema.json","routing_policy":"/marketplace-schemas/routing-policy.schema.json","routing_library":"/marketplace-schemas/routing-library.schema.json"},"catalog":{"schema_version":"1.0","last_reviewed":"2026-05-05","positioning":{"name":"SecurityRecipes client-side marketplace","summary":"A BYO-token browser control plane for AI security work: connect GitHub, GitLab, Azure DevOps, local scan artifacts, Snyk issues, Defender XDR incidents, Sentinel incidents, DefectDojo findings, Tenable exports, CrowdStrike detections, Prisma Cloud alerts, Security Hub findings, Confluence runbooks, and recipe context; surface source freshness, classify source failures, refresh browser-safe sources inline, and route manual uploads back to local setup before the next run; surface navigator mission-control cards for due schedules, queue head, source issues, open cases, portfolio gaps, and saved-case handoff drift; export a browser-local daily ops brief as markdown or JSON; keep a browser-local operations ledger for source syncs, chat sessions, agent runs, case actions, and report exports; group correlated source pulls, AI runs, case captures, and handoff exports into browser-local investigation sessions; filter the ledger by category, state, or free-text; inspect either one record or one grouped session as JSON; and jump back into the linked browser surface without leaving the navigator; register browser-local assets, owner teams, criticality, service portfolios, and lightweight asset relationships; turn imported findings into a prioritized browser-local Exposure Board; roll related repositories, services, APIs, and data stores into a portfolio-aware service map; score each service portfolio by owner coverage, case coverage, routing coverage, and live-delivery blockers; open a Reports desk that can seed a normalized handoff packet from a saved case, exposure queue item, or grouped investigation session; generate normalized reports with both current handoff readiness and source-case readiness provenance, and compare the current handoff context to the captured run before anything is routed downstream; hand results to downstream systems like Teams, ServiceNow, Linear, GitLab, Azure DevOps, Splunk, Elastic, PagerDuty, Google Chat, Cortex XSOAR, IBM SOAR, Sentinel playbooks, or custom webhooks without server-side secret storage; author private workflow, report, or integration packs locally with schema-backed validation; carry versioned pack governance, docs linkage, review cadence, and explicit pack dependencies alongside those contracts; capture reviewed runs as reusable browser-local case files with evidence timeline, replayable planner state, and captured launch-readiness provenance; author owner-aware and portfolio-aware routing policies that prefill downstream routes, approvals, and ticket metadata; inspect auditable routing analysis that shows which policy matched, which defaults were recommended, and where the planner still diverges before anything leaves the browser; audit the active planner for missing provider credentials, target-scope gaps, stale evidence, workflow-pack blockers, and route prerequisites before a run is generated; export portfolio coverage evidence alongside normalized report bundles so downstream review can see which services are still unrouted or only handoff-ready; and move validated case, asset, routing, marketplace, operations-history, or operations-session libraries between browser profiles before contributing anything back to Hugo.","browser_model":"Provider credentials, connector settings, and selected workflow state stay in browser storage. Recipes and marketplace templates are open Hugo content. Live API calls are explicit and same-origin or direct-to-provider/direct-to-approved-SaaS APIs from the browser.","contribution_model":"Marketplace entries are Hugo data files and docs content so teams can fork, contribute, review, and publish new channels and workflows through normal pull requests."},"market_signals":[{"date":"2025-07-21","source":"Harness STO SARIF ingestion","url":"https://developer.harness.io/docs/security-testing-orchestration/custom-scanning/ingest-sarif-data","signal":"Security teams increasingly expect scanner outputs to land in a common interchange format, which makes browser-side SARIF and JSON normalization a practical baseline instead of a niche feature."},{"date":"2026-02-26","source":"Airia MCP Gateway","url":"https://airia.com/airias-mcp-gateway-surpasses-1000-pre-configured-integrations-delivering-the-largest-enterprise-ready-mcp-catalog/","signal":"Enterprises now expect large governed integration catalogs with change detection, version pinning, and audit logging."},{"date":"2026-01-28","source":"Cortex XSOAR content pack installation","url":"https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Administrator-Guide/Content-Pack-Installation","signal":"Security marketplaces now treat version history plus required and optional pack dependencies as first-class operating constraints, which supports explicit pack governance and dependency health in the browser marketplace."},{"date":"2026-04-29","source":"Command Zero APIs + MCP","url":"https://www.prnewswire.com/news-releases/command-zero-accelerates-secops-pipelines-with-apis-and-mcp-server-302755893.html","signal":"Security teams want AI investigation and remediation surfaces that can slot into existing pipelines instead of forcing a greenfield workflow."},{"date":"2026-04-29","source":"Wiz State of AI in the Cloud 2026","url":"https://www.wiz.io/reports/state-of-ai-in-the-cloud-2026","signal":"AI is now core operational infrastructure, 2026 is the year of integration, and agents plus MCP servers have become a new control-plane attack surface that needs explicit governance."},{"date":"2026-01-28","source":"Tines Voice of Security 2026","url":"https://www.tines.com/downloads/Tines-Voice-Of-Security-2026-Report.pdf","signal":"Security teams still spend large amounts of time on repetitive manual work, which increases the value of normalized report bundles and reusable workflow templates that fit existing handoff systems."},{"date":"2026-04-08","source":"Salt Security 1H 2026 report","url":"https://www.prnewswire.com/news-releases/salt-security-research-as-ai-agents-outpace-security-most-organizations-face-an-unsecured-api-surge-302736506.html","signal":"APIs, MCP servers, and data access now form one attack surface, so scan/report/output contracts need to be explicit and inspectable."},{"date":"2026-03-06","source":"2026 State of Browser Security","url":"https://www.scworld.com/brief/2026-state-of-browser-security-report-highlights-ai-integration-and-evolving-threats","signal":"The browser is a meaningful AI operating surface, which supports a client-side BYO-token model but requires clear guardrails around extensions, personal accounts, and data egress."},{"date":"2026-05-04","source":"Tines templates docs","url":"https://explained.tines.com/en/articles/12709787-templates-in-tines","signal":"Public and private reusable templates are now a product baseline, which supports private local pack labs before public contribution."},{"date":"2026-05-04","source":"Cortex XDR report templates","url":"https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-5.x-Documentation/Run-or-schedule-reports","signal":"Security platforms now treat report templates as importable and exportable JSON artifacts, which supports making report profiles first-class browser-authored marketplace contracts instead of leaving output shape hard-coded."},{"date":"2026-01-15","source":"Microsoft Security Copilot Export Activity API","url":"https://learn.microsoft.com/en-us/copilot/security/activity-export-api","signal":"Security Copilot now exposes explicit export contracts for prompts, responses, and sessions, which supports treating browser-local session packs and report handoffs as durable artifacts instead of disposable UI state."},{"date":"2026-05-04","source":"Cortex XSOAR content pack contributions","url":"https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.10/Cortex-XSOAR-On-prem-Documentation/Content-pack-contributions","signal":"Security operators expect integration and workflow bundles to be contributed, reviewed, and optionally downloaded for Git-backed submission rather than authored only in a vendor-managed marketplace."},{"date":"2026-05-05","source":"Cortex XSOAR create or update incident API","url":"https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR-8-API/Create-or-update-an-incident","signal":"Cortex XSOAR still exposes direct incident creation with API key plus x-xdr-auth-id headers and a createInvestigation switch, which supports a BYO-token browser route instead of keeping XSOAR at starter-contract status."},{"date":"2025-09-02","source":"Using the Splunk SOAR REST API","url":"https://help.splunk.com/en/splunk-soar/soar-on-premises/rest-api-reference/6.4.0/using-the-splunk-soar-rest-api/using-the-rest-api-reference-for-splunk-soar-on-premises","signal":"Splunk SOAR still documents ph-auth-token authentication together with POST /rest/container, which keeps a BYO-token browser container route feasible for reviewed remediation and incident packets."},{"date":"2026-05-04","source":"Torq integration builder docs","url":"https://kb.torq.io/en/articles/10662506-integration-builder-create-custom-integrations","signal":"Custom integration builders now expose auth parameters, documentation links, and test setup as first-class authoring inputs, which supports adding a browser-side input/output pack studio instead of hard-coding only vendor-owned routes."},{"date":"2026-04-12","source":"Cortex XSOAR content validation","url":"https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.10/Cortex-XSOAR-On-prem-Documentation/Content-pack-contributions","signal":"Marketplace contribution systems now treat validation as part of authoring, including pre-submit checks and exportable raw error details, which supports schema-backed browser validation before a SecurityRecipes marketplace PR."},{"date":"2026-05-04","source":"Elastic Security cases docs","url":"https://www.elastic.co/docs/solutions/security/investigate/security-cases","signal":"Modern security workbenches treat cases as the place to collect investigation context, metrics, attachments, and external escalations, which supports adding a browser-local Caseboard instead of leaving runs stranded as one-off prompts."},{"date":"2026-04-26","source":"Cortex XSOAR War Room docs","url":"https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-SaaS-Documentation/Use-the-War-Room-in-an-investigation","signal":"Incident handling products continue to emphasize an audit trail of automatic and manual actions inside each investigation, which supports capturing browser-run timelines and delivery events as first-class local case history."},{"date":"2026-04-27","source":"Cortex XSIAM War Room docs","url":"https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Documentation/Use-the-War-Room-in-an-investigation","signal":"Major SecOps workbenches keep automatic and manual actions tied to one incident-local audit trail, which supports surfacing saved-case handoff drift and revalidation work directly inside the browser case and report surfaces."},{"date":"2026-05-04","source":"Microsoft Sentinel incident investigation docs","url":"https://learn.microsoft.com/en-us/azure/sentinel/incident-investigation","signal":"SecOps platforms still differentiate on giving analysts one place to review the chronology, evidence, and task context of an investigation, which supports making SecurityRecipes feel like a complete application rather than just a chat surface."},{"date":"2026-03-23","source":"Elastic Workflows launch","url":"https://www.elastic.co/blog/workflows-soar","signal":"Security platforms are increasingly collapsing alerts, investigations, workflows, and response into one surface, which supports treating portable case libraries and replayable run context as first-class application primitives instead of disposable chat output."},{"date":"2026-05-04","source":"Wiz Exposure Management","url":"https://www.wiz.io/solutions/exposure-management","signal":"Exposure-management platforms now differentiate by correlating findings across tools, removing alert silos, and turning prioritized risk into owner-ready action, which supports adding a browser-local Exposure Board on top of the existing scanner and case primitives."},{"date":"2026-05-04","source":"Wiz ASM","url":"https://www.wiz.io/solutions/asm","signal":"Attack-surface and exposure products now explicitly promise business-impact and owner-aware prioritization, which supports adding a browser-local asset and ownership layer instead of leaving queue items detached from the team that should fix them."},{"date":"2025-09-08","source":"Microsoft Security Exposure Management critical assets","url":"https://learn.microsoft.com/en-us/security-exposure-management/classify-critical-assets","signal":"Critical-asset programs now combine cyber-role, production context, and system importance to drive prioritization, which supports capturing local asset criticality and environment metadata alongside browser-first remediation queues."},{"date":"2025-01-13","source":"Microsoft Security Exposure Management initiative metrics","url":"https://learn.microsoft.com/en-gb/security-exposure-management/security-metrics","signal":"Exposure programs now expose state, progress, affected assets, weighted impact, and linked recommendations in one scored initiative view, which supports deriving a browser-local portfolio coverage score and gap snapshot instead of leaving service maps as passive reference data."},{"date":"2026-05-04","source":"Elastic asset criticality","url":"https://www.elastic.co/docs/solutions/security/advanced-entity-analytics/asset-criticality","signal":"Mature SecOps tools now bulk-import criticality from inventory files and enrich downstream alerts with that context, which supports schema-backed browser import/export for asset ownership and criticality libraries."},{"date":"2026-05-04","source":"Elastic entity risk scoring","url":"https://www.elastic.co/docs/solutions/security/advanced-entity-analytics/entity-risk-scoring","signal":"Risk engines increasingly combine alerts and asset criticality into a recurring service or entity score, which supports adding portfolio coverage scoring that blends exposure queue state, owner gaps, and route readiness inside the browser workbench."},{"date":"2026-03-12","source":"ServiceNow CMDB-based mapping","url":"https://www.servicenow.com/docs/r/it-operations-management/service-mapping/cmdb-based-mapping.html","signal":"Service mapping products now expect application services to be derived from related hosts, traffic, and dependency context, which supports adding lightweight browser-local portfolio and relationship fields instead of treating every asset as an isolated record."},{"date":"2026-03-12","source":"ServiceNow link application services","url":"https://www.servicenow.com/docs/r/servicenow-platform/configuration-management-database-cmdb/link-services-to-services.html","signal":"Application-service maps now explicitly model service-to-service dependencies for impact monitoring, which supports deriving dependency fan-out and downstream blast radius from linked browser-local portfolios instead of only scoring each service in isolation."},{"date":"2026-05-04","source":"Atlassian Assets","url":"https://support.atlassian.com/assets/docs/what-is-assets-in-jira-service-management-cloud/","signal":"Asset-management surfaces now emphasize linking incidents and changes to the relationships between applications, services, infrastructure, and dependencies, which supports surfacing a portfolio-aware service map directly in the browser workbench."},{"date":"2025-09-15","source":"Microsoft Security Exposure Management attack surface map","url":"https://learn.microsoft.com/en-us/security-exposure-management/enterprise-exposure-map","signal":"Exposure-management platforms continue to differentiate on exploring asset connections, critical paths, and choke points in one map view, which supports adding dependency-aware route coverage and fan-out analytics to the browser Router instead of only listing flat queue counts."},{"date":"2026-05-04","source":"Microsoft Sentinel automation rules","url":"https://learn.microsoft.com/en-us/azure/sentinel/automate-incident-handling-with-automation-rules","signal":"Mainstream SecOps tools now centralize trigger, condition, owner-assignment, severity-change, and playbook-routing logic in one automation layer, which supports adding browser-local routing policies instead of leaving downstream handling fully manual."},{"date":"2026-05-04","source":"Elastic security workflows","url":"https://www.elastic.co/docs/explore-analyze/workflows/use-cases/security","signal":"Security workflow surfaces now explicitly combine automatic response, case creation, severity-based notification routing, and AI-assisted investigation, which supports treating routing defaults as a first-class control-plane layer between exposures, cases, and downstream outputs."},{"date":"2026-05-04","source":"ServiceNow flow execution details","url":"https://www.servicenow.com/docs/r/build-workflows/workflow-studio/flow-execution-details.html?contentId=TQmEZT4017Q7XcTIkebtNA","signal":"Mainstream workflow platforms expose runtime state, input and output values, and execution logs in a dedicated audit view, which supports surfacing routing match reasons, default injection, and readiness blockers directly in the browser planner."},{"date":"2026-05-04","source":"Tines intelligent workflow platform","url":"https://www.tines.com/","signal":"Tines now explicitly positions deterministic workflows as the right surface for triage, routing, and explainability, which supports adding a first-class routing audit layer instead of treating browser-local policy matches as hidden background logic."},{"date":"2026-03-18","source":"Microsoft Security Copilot plugins overview","url":"https://learn.microsoft.com/en-us/copilot/security/plugin-overview","signal":"Security AI platforms now expose plugin and tool catalogs directly to operators, including enablement state and purchased capabilities, which supports a public readiness matrix instead of burying integration prerequisites inside hidden setup flows."},{"date":"2026-03-18","source":"Microsoft Security Copilot prompting and promptbooks","url":"https://learn.microsoft.com/en-us/copilot/security/prompting-security-copilot","signal":"Security AI products now surface reusable promptbooks and role-based starting flows directly from the home experience, which supports adding a first-class mission-control layer instead of hiding daily work behind separate tabs."},{"date":"2025-11-25","source":"Microsoft Security Exposure Management prerequisites","url":"https://learn.microsoft.com/en-us/security-exposure-management/prerequisites","signal":"Exposure-management products now document explicit freshness windows and current-snapshot retention for connector-driven graph data, which supports showing stale-source warnings and navigator refresh actions instead of assuming imported context stays trustworthy forever."},{"date":"2026-01-07","source":"Google SecOps Health Hub","url":"https://docs.cloud.google.com/chronicle/docs/reports/data-health-monitoring-and-troubleshooting-dashboard","signal":"Modern SecOps consoles now centralize failed sources, ingestion health, and remediation context in one health surface, which supports combining source recovery, freshness, and daily-ops triage inside the navigator."},{"date":"2026-05-02","source":"Elastic Attack Discovery","url":"https://www.elastic.co/docs/solutions/security/ai/attack-discovery","signal":"AI security workflows now routinely combine scheduled discoveries, saved review state, status changes, and connector-aware notifications in one operating surface, which supports promoting SecurityRecipes from isolated panels into a browser-local mission board."},{"date":"2026-05-04","source":"GitLab Issues API","url":"https://docs.gitlab.com/api/issues/","signal":"GitLab still exposes direct project issue creation with URL-encoded project paths and token-authenticated API access, which makes a browser-first BYO-token issue route feasible without inventing a separate relay product."},{"date":"2026-05-05","source":"GitLab Projects, Merge Requests, and Vulnerability Findings APIs","url":"https://docs.gitlab.com/api/projects/","signal":"GitLab still exposes project metadata through ID or URL-encoded path, project merge requests through the REST API, and project vulnerability findings through an authenticated but unstable REST surface that GitLab recommends treating as bounded and GraphQL-adjacent. That keeps browser-side GitLab intake viable, but it should stay explicitly sampled and reviewer-visible."},{"date":"2026-05-04","source":"Azure DevOps REST auth and work item create docs","url":"https://learn.microsoft.com/en-us/azure/devops/integrate/get-started/rest/samples?view=azure-devops","signal":"Azure DevOps continues to recommend Microsoft Entra tokens for production while still documenting PATs as simple auth and the Work Item Tracking create endpoint as JSON Patch, which supports a browser-local BYO-token route that remains `live_or_copy` rather than pretending every tenant should allow direct writes."},{"date":"2026-05-01","source":"Azure DevOps public projects retirement","url":"https://learn.microsoft.com/en-us/azure/devops/organizations/projects/public-projects-retirement?view=azure-devops","signal":"Microsoft now treats Azure DevOps public projects as retired and says remaining public projects convert to private in 2027, which reinforces an authenticated browser-side enterprise intake model instead of designing around anonymous repository access."},{"date":"2026-05-01","source":"Microsoft Security Copilot prompting","url":"https://learn.microsoft.com/en-us/copilot/security/prompting-security-copilot","signal":"Microsoft now treats process-log visibility during response generation as a first-class operator surface, which supports exposing browser-local AI run chronology instead of leaving provider actions opaque."},{"date":"2025-12-05","source":"Microsoft Security Copilot navigation","url":"https://learn.microsoft.com/en-us/copilot/security/navigating-security-copilot","signal":"Security Copilot now exposes a dedicated History view plus process logs in the main workflow, which supports making Navigator carry both local session history and current operational context."},{"date":"2026-03-04","source":"Cortex XSOAR incident management","url":"https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.11/Cortex-XSOAR-Administrator-Guide/Incident-Management","signal":"Cortex XSOAR continues to frame incident investigation as one place to review status, timeline, and escalations together, which supports exporting grouped browser-local investigation sessions instead of leaving only isolated event records."},{"date":"2026-01-16","source":"Microsoft Security Copilot audit log","url":"https://learn.microsoft.com/en-us/copilot/security/audit-log","signal":"Microsoft explicitly frames prompt, response, and activity metadata as audit artifacts, which supports giving the browser workbench a portable operations-history contract instead of treating AI work as disposable UI state."},{"date":"2026-04-26","source":"Cortex XSOAR War Room","url":"https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-SaaS-Documentation/Use-the-War-Room-in-an-investigation","signal":"Cortex XSOAR continues to position the investigation timeline as the place to document automatic and manual actions in one source, which reinforces adding a browser-local SecOps chronology on top of chat, cases, and routes."},{"date":"2026-05-05","source":"Elastic Attack Discovery saved discoveries","url":"https://www.elastic.co/docs/solutions/security/ai/attack-discovery","signal":"Elastic now treats AI discoveries as saved artifacts for later review, reporting, tracking, and search/filter workflows, which supports adding a filterable replay-friendly operations ledger instead of limiting browser history to a short recent list."},{"date":"2025-10-20","source":"Use plugins in Microsoft Security Copilot","url":"https://learn.microsoft.com/en-us/copilot/security/use-plugins","signal":"Microsoft now exposes plugin state filters and per-plugin personalization settings such as default Sentinel workspaces, which supports treating launch-readiness and connector defaults as a first-class operator surface instead of burying them behind scattered setup forms."},{"date":"2026-03-18","source":"Microsoft Security Copilot in your workflows","url":"https://learn.microsoft.com/en-us/copilot/security/workflows-overview","signal":"Microsoft now frames discovering agents, configuring plugins, and reviewing agent success as one workflow, which supports adding a planner-side readiness gate before analysts generate a run or attempt downstream delivery."}],"strategic_tracks":[{"id":"appsec-code-intake","label":"AppSec and code intake","priority":"now","summary":"Close the major AppSec intake gaps so the browser planner can start from first-party scanner state instead of only manual uploads and generic artifacts.","pack_ids":["github-code-scanning-alerts","gitlab-vulnerability-findings","semgrep-appsec-findings","sonarqube-issues","checkmarx-one-findings","veracode-findings","sarif-manual-import"],"market_signal_sources":["Harness STO SARIF ingestion","GitLab Projects, Merge Requests, and Vulnerability Findings APIs","Microsoft Security Copilot plugins overview"],"next_focus":["Promote GitHub code scanning and at least one dedicated AppSec platform feed from reviewed starter contract to browser-live intake.","Keep SARIF as the universal fallback when vendor APIs, scopes, or CORS policies block direct browser pulls."]},{"id":"cloud-exposure-intake","label":"Cloud and exposure intake","priority":"now","summary":"Make cloud posture, CNAPP, and exposure feeds feel native by covering the attack-surface and runtime platforms that security teams already triage every day.","pack_ids":["wiz-findings-api","security-hub-api","aws-inspector-findings","prisma-cloud-alerts","orca-security-alerts","lacework-alerts","google-cloud-scc-findings"],"market_signal_sources":["Wiz State of AI in the Cloud 2026","Salt Security 1H 2026 report","Microsoft Security Exposure Management prerequisites"],"next_focus":["Group posture, runtime, and API-exposure evidence into one normalized queue so portfolios and cases stop depending on one vendor at a time.","Keep cloud-provider starter packs honest about request signing and delegated auth until the browser flow is proven end to end."]},{"id":"secops-detection-intake","label":"SecOps detection intake","priority":"next","summary":"Broaden detection and vulnerability intake beyond Microsoft so the queue proves it is usable for MSSP, IR, and enterprise operations teams with mixed stacks.","pack_ids":["microsoft-defender-xdr-incidents","microsoft-sentinel-incidents","crowdstrike-detections","tenable-vulnerability-management","rapid7-insightvm-vulnerabilities"],"market_signal_sources":["Google SecOps Health Hub","Elastic Attack Discovery","2026 State of Browser Security"],"next_focus":["Promote one non-Microsoft detection feed to live browser pull so the queue is clearly multi-platform rather than Microsoft-centric.","Use freshness and queue-state labels to show when a detection feed is sampled, stale, or only available through a starter contract."]},{"id":"orchestration-and-delivery","label":"Orchestration and delivery","priority":"now","summary":"Meet the baseline expectation that a security workbench can hand reviewed output into the ticketing, SOAR, and workflow systems already running the team.","pack_ids":["jira-ticket","servicenow-incident","gitlab-issue","azure-devops-work-item","cortex-xsoar-incident","ibm-soar-incident","microsoft-sentinel-playbook","tines-webhook","torq-webhook","splunk-soar-incident","swimlane-case","pagerduty-events-v2"],"market_signal_sources":["Cortex XSOAR content pack contributions","Cortex XSOAR create or update incident API","Using the Splunk SOAR REST API","Torq integration builder docs","Tines templates docs","Tines intelligent workflow platform"],"next_focus":["Build on the live Tines, Torq, Cortex XSOAR, and Splunk SOAR routes by promoting Swimlane or IBM SOAR next so the browser workbench covers both container and case-record handoff patterns.","Keep route-specific payload shaping and copy-safe handoff packets first-class so blocked writes do not collapse the operator workflow."]}]},"input_channels":{"channels":[{"id":"page-context","label":"Current page context","category":"Local browser context","status":"native","runtime_support":"live","description":"Sends the current page title, headings, and bounded body text to the model.","auth_modes":["none"],"config":{"type":"page_context","source":"active_document","max_chars":4200,"include_headings":true,"include_matches":true}},{"id":"recipe-index","label":"SecurityRecipes search index","category":"Local browser context","status":"native","runtime_support":"live","description":"Searches the generated recipe index and attaches the most relevant docs, prompts, and remediation pages.","auth_modes":["none"],"config":{"type":"recipes_index","source":"/recipes-index.json","top_k":5,"sections":["recipes","security-remediation","automation","docs"]}},{"id":"github-repository","label":"GitHub repository context","category":"Code and findings sources","status":"native","runtime_support":"live","description":"Pulls bounded public or authenticated GitHub repo metadata, manifest files, open issues, and pull requests.","auth_modes":["public","pat","oauth"],"config":{"type":"github_repository","repository":"owner/repo","include":["readme","security","contributing","manifests","issues","pull_requests"],"max_files":18,"max_chars_per_file":1600}},{"id":"deps-dev-advisories","label":"deps.dev advisory context","category":"Code and findings sources","status":"native","runtime_support":"live","description":"Checks public GitHub Dependency Graph SBOM packages against deps.dev advisory metadata.","auth_modes":["public","pat","oauth"],"config":{"type":"deps_dev_lookup","repository":"owner/repo","include":["sbom_packages","advisories","cvss","aliases"],"max_packages":40,"max_advisories":12}},{"id":"osv-vulnerability-api","label":"OSV.dev vulnerability context","category":"Code and findings sources","status":"native","runtime_support":"live","description":"Checks public GitHub Dependency Graph SBOM package URLs against OSV.dev vulnerability records without a token.","auth_modes":["public","pat","oauth"],"config":{"type":"osv_vulnerability_lookup","repository":"owner/repo","include":["sbom_packages","vulnerabilities","aliases","severity"],"max_packages":40,"max_vulnerabilities":12}},{"id":"mcp-http-gateway","label":"MCP HTTP gateway","category":"MCP and context gateways","status":"native","runtime_support":"live","description":"Calls one configured read-only MCP tool through a CORS-enabled Streamable HTTP gateway endpoint and attaches bounded text context to chat or agent runs.","auth_modes":["none","bearer_token","oauth"],"config":{"type":"mcp_http_gateway","transport":"streamable_http","read_only_tool_pattern":"search|query|list|get|read|find|lookup|fetch|describe|inspect|analyze|scan","max_chars":9000}},{"id":"gitlab-project-context","label":"GitLab project context","category":"Code and findings sources","status":"native","runtime_support":"live","description":"Pulls bounded GitLab project metadata, useful repository files, open issues, and open merge requests directly in the browser for GitLab-centered remediation work.","auth_modes":["public","pat","oauth"],"config":{"type":"gitlab_project_context","base_url":"https://gitlab.com/api/v4","project":"group/project","include":["project","readme","default_branch","issues","merge_requests","vulnerability_findings"],"max_items":20}},{"id":"azure-devops-repository","label":"Azure DevOps repository context","category":"Code and findings sources","status":"native","runtime_support":"live","description":"Pulls bounded Azure DevOps repository metadata, useful repo files, active pull requests, and recent open work items directly in the browser for remediation planning.","auth_modes":["oauth","pat"],"config":{"type":"azure_devops_repository","base_url":"https://dev.azure.com","organization":"YOUR-AZURE-DEVOPS-ORGANIZATION","project":"security-platform","repository":"payments-api","include":["repository","default_branch","readme","security","contributing","manifests","pull_requests","work_items"],"api_version":"7.1","max_files":18,"max_chars_per_file":1600}},{"id":"sarif-manual-import","label":"SARIF upload","category":"Scanner findings","status":"native","runtime_support":"live","description":"Uploads a local SARIF 2.1.0 file in the browser, normalizes the findings, and attaches a bounded summary to prompts and agent runs.","auth_modes":["none"],"config":{"type":"sarif_bundle","source":"local_file","accepted_formats":["sarif-2.1.0-json"],"expected_files":["findings.sarif.json"],"required_fields":["runs[].tool.driver.name","runs[].results[].ruleId","runs[].results[].level"],"normalization":{"severity_map":"sarif_default","max_results":250}}},{"id":"sbom-manual-import","label":"SBOM upload","category":"Scanner findings","status":"native","runtime_support":"live","description":"Uploads a local CycloneDX or SPDX JSON SBOM in the browser and attaches a bounded package, dependency, and vulnerability summary to prompts.","auth_modes":["none"],"config":{"type":"sbom_bundle","source":"local_file","accepted_formats":["cyclonedx-json","spdx-json"],"format_markers":["bomFormat=CycloneDX","spdxVersion"],"normalization":{"max_components":5000,"infer_ecosystem":true}}},{"id":"scanner-export-bundle","label":"Major scanner JSON exports","category":"Scanner findings","status":"native","runtime_support":"live","description":"Uploads major scanner and findings-platform JSON exports in the browser, normalizes them into a bounded summary, and feeds the exposure queue plus downstream reports without any server-side secret handling.","auth_modes":["none"],"config":{"type":"scanner_export_bundle","source":"local_file","accepted_formats":["aws-security-hub-asff","tenable-vulnerability-export","defectdojo-findings-json","generic-findings-array-json"],"normalization":{"max_files":12,"max_findings":1500,"max_sample_findings":12}}},{"id":"wiz-findings-api","label":"Wiz findings API","category":"Scanner findings","status":"template","runtime_support":"planned","description":"Pre-populated browser-side config for pulling cloud and workload findings from Wiz when a customer enables direct API access.","auth_modes":["api_key","oauth"],"config":{"type":"wiz_findings","base_url":"https://api.us1.app.wiz.io/graphql","scopes":["issues:read"],"filters":{"status":["OPEN"],"severity":["CRITICAL","HIGH"]},"pagination":{"page_size":100}}},{"id":"snyk-issues-api","label":"Snyk issues API","category":"Scanner findings","status":"native","runtime_support":"live","description":"Pulls a bounded first page of high-priority Snyk organization issues directly in the browser for scanner-aware triage and remediation planning.","auth_modes":["api_token"],"config":{"type":"snyk_issues","base_url":"https://api.snyk.io/rest","version":"2024-10-15","filters":{"status":["open"],"effective_severity_level":["high","critical"]}}},{"id":"security-hub-api","label":"AWS Security Hub","category":"Scanner findings","status":"template","runtime_support":"planned","description":"Config profile for pulling ASFF findings into remediation reports and downstream workflow packs.","auth_modes":["aws_sigv4"],"config":{"type":"aws_security_hub","region":"us-east-1","filters":{"RecordState":["ACTIVE"],"SeverityLabel":["HIGH","CRITICAL"]}}},{"id":"microsoft-defender-xdr-incidents","label":"Microsoft Defender XDR incidents","category":"Scanner findings","status":"native","runtime_support":"live","description":"Pulls a bounded Microsoft Defender XDR incident sample directly in the browser with local severity and status filters for queueing, reporting, and remediation planning.","auth_modes":["oauth"],"config":{"type":"microsoft_defender_xdr_incidents","base_url":"https://api.security.microsoft.com/api/incidents","scopes":["Incident.Read.All"],"filters":{"status":["Active"],"severity":["High","Medium"]},"pagination":{"top":50}}},{"id":"microsoft-sentinel-incidents","label":"Microsoft Sentinel incidents","category":"Scanner findings","status":"native","runtime_support":"live","description":"Pulls a bounded Microsoft Sentinel workspace incident sample directly in the browser with local severity and status filters for queueing, reporting, and remediation planning.","auth_modes":["oauth"],"config":{"type":"microsoft_sentinel_incidents","base_url":"https://management.azure.com","resource_path":"/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.OperationalInsights/workspaces/{workspaceName}/providers/Microsoft.SecurityInsights/incidents","api_version":"2025-09-01","include":["incidents"],"filters":{"status":["New","Active"],"severity":["High","Medium"]},"pagination":{"top":50}}},{"id":"gitlab-vulnerability-findings","label":"GitLab vulnerability findings","category":"Scanner findings","status":"native","runtime_support":"live","description":"Pulls a bounded first page of GitLab project vulnerability findings directly in the browser when AppSec findings and fix ownership live in the same GitLab namespace.","auth_modes":["pat","oauth"],"config":{"type":"gitlab_vulnerability_findings","base_url":"https://gitlab.com/api/v4","project":"group/project","endpoint":"/projects/:id/vulnerability_findings","filters":{"report_type":["dependency_scanning","sast"],"severity":["high","critical"],"state":["detected","confirmed"]}}},{"id":"crowdstrike-detections","label":"CrowdStrike detections","category":"Scanner findings","status":"template","runtime_support":"planned","description":"Starter config for bounded CrowdStrike Falcon detection intake into browser-side triage and response workflows.","auth_modes":["oauth","api_key"],"config":{"type":"crowdstrike_detections","base_url":"https://api.crowdstrike.com","endpoint":"/detects/queries/detects/v1","filters":{"status":["new","in_progress"],"severity":["high","critical"]}}},{"id":"tenable-vulnerability-management","label":"Tenable vulnerability management","category":"Scanner findings","status":"template","runtime_support":"planned","description":"Starter config for exporting high-severity Tenable vulnerabilities into remediation and report workflows.","auth_modes":["api_key"],"config":{"type":"tenable_vuln_export","base_url":"https://cloud.tenable.com","export_path":"/vulns/export","filters":{"severity":["high","critical"],"state":["OPEN","REOPENED"]}}},{"id":"defectdojo-findings","label":"DefectDojo findings","category":"Scanner findings","status":"template","runtime_support":"planned","description":"Starter config for pulling active high-severity DefectDojo findings with enough context for analyst routing and ticket creation.","auth_modes":["api_token","oauth"],"config":{"type":"defectdojo_findings","base_url":"https://YOUR-DEFECTDOJO-HOST/api/v2","endpoint":"/findings","include":["product","engagement","test","finding"],"filters":{"active":true,"severity":["Critical","High"]}}},{"id":"prisma-cloud-alerts","label":"Prisma Cloud alerts","category":"Scanner findings","status":"template","runtime_support":"planned","description":"Starter config for Prisma Cloud alert intake across posture and runtime findings.","auth_modes":["access_key"],"config":{"type":"prisma_cloud_alerts","base_url":"https://api.prismacloud.io","resource":"/alert","filters":{"policy_severity":["high","critical"],"alert_status":["open"]}}},{"id":"google-cloud-scc-findings","label":"Google Cloud SCC findings","category":"Scanner findings","status":"template","runtime_support":"planned","description":"Starter config for Security Command Center findings when cloud exposures need browser-side triage and routing.","auth_modes":["oauth"],"config":{"type":"google_cloud_scc_findings","base_url":"https://securitycenter.googleapis.com","resource":"organizations/{organizationId}/sources/-/findings","filters":{"state":["ACTIVE"],"severity":["HIGH","CRITICAL"]}}},{"id":"github-code-scanning-alerts","label":"GitHub code scanning alerts","category":"Scanner findings","status":"template","runtime_support":"planned","description":"Starter config for pulling open high-severity GitHub code scanning alerts into browser-side triage and remediation planning.","auth_modes":["pat","oauth"],"config":{"type":"github_code_scanning_alerts","base_url":"https://api.github.com","repository":"owner/repo","endpoint":"/repos/{owner}/{repo}/code-scanning/alerts","filters":{"state":["open"],"severity":["high","critical"]}}},{"id":"semgrep-appsec-findings","label":"Semgrep AppSec findings","category":"Scanner findings","status":"template","runtime_support":"planned","description":"Starter config for bringing bounded Semgrep AppSec findings into browser-side reviewer queues and remediation handoffs.","auth_modes":["api_token"],"config":{"type":"semgrep_appsec_findings","base_url":"https://semgrep.dev/api/v1","resource":"/deployments/{deploymentId}/findings","filters":{"state":["open","triaged"],"severity":["high","critical"]}}},{"id":"sonarqube-issues","label":"SonarQube security issues","category":"Scanner findings","status":"template","runtime_support":"planned","description":"Starter config for pulling open SonarQube vulnerabilities and security hotspots into a browser-local remediation queue.","auth_modes":["api_token"],"config":{"type":"sonarqube_issues","base_url":"https://YOUR-SONARQUBE-HOST/api","endpoint":"/issues/search","filters":{"statuses":["OPEN","CONFIRMED","REOPENED"],"severities":["CRITICAL","BLOCKER"],"types":["VULNERABILITY","SECURITY_HOTSPOT"]}}},{"id":"checkmarx-one-findings","label":"Checkmarx One findings","category":"Scanner findings","status":"template","runtime_support":"planned","description":"Starter config for pulling high-severity Checkmarx One findings into browser-side triage and routed handoff workflows.","auth_modes":["oauth","api_key"],"config":{"type":"checkmarx_one_findings","base_url":"https://ast.checkmarx.net/api","resource":"/findings","filters":{"state":["NEW","TO_VERIFY"],"severity":["HIGH","CRITICAL"]}}},{"id":"veracode-findings","label":"Veracode findings","category":"Scanner findings","status":"template","runtime_support":"planned","description":"Starter config for pulling actionable Veracode findings into a browser-local remediation and reporting workflow.","auth_modes":["api_key"],"config":{"type":"veracode_findings","base_url":"https://api.veracode.com/appsec/v1","resource":"/findings","filters":{"scan_status":["OPEN"],"severity":["HIGH","VERY_HIGH"]}}},{"id":"aws-inspector-findings","label":"AWS Inspector findings","category":"Scanner findings","status":"template","runtime_support":"planned","description":"Starter config for pulling Amazon Inspector findings into browser-side prioritization, reporting, and downstream routing.","auth_modes":["aws_sigv4"],"config":{"type":"aws_inspector_findings","base_url":"https://inspector2.us-east-1.amazonaws.com","resource":"/findings/list","filters":{"finding_status":["ACTIVE"],"severity":["HIGH","CRITICAL"]}}},{"id":"rapid7-insightvm-vulnerabilities","label":"Rapid7 InsightVM vulnerabilities","category":"Scanner findings","status":"template","runtime_support":"planned","description":"Starter config for pulling high-risk Rapid7 InsightVM vulnerabilities into browser-side triage and routing workflows.","auth_modes":["api_key"],"config":{"type":"rapid7_insightvm_vulnerabilities","base_url":"https://console.insight.rapid7.com/api/3","resource":"/vulnerabilities","filters":{"severity":["Severe","Critical"],"status":["active"]}}},{"id":"orca-security-alerts","label":"Orca Security alerts","category":"Scanner findings","status":"template","runtime_support":"planned","description":"Starter config for Orca alert intake when cloud exposure and workload findings need browser-side case and report handling.","auth_modes":["api_token"],"config":{"type":"orca_security_alerts","base_url":"https://api.orcasecurity.io","resource":"/api/alerts","filters":{"state":["open"],"severity":["high","critical"]}}},{"id":"lacework-alerts","label":"Lacework alerts","category":"Scanner findings","status":"template","runtime_support":"planned","description":"Starter config for pulling open high-severity Lacework alerts into browser-side remediation and escalation planning.","auth_modes":["api_key"],"config":{"type":"lacework_alerts","base_url":"https://api.lacework.net","resource":"/api/v2/Alerts/Search","filters":{"status":["Open"],"severity":["High","Critical"]}}},{"id":"confluence-knowledge","label":"Confluence runbook context","category":"Knowledge sources","status":"native","runtime_support":"live","description":"Searches Confluence Cloud pages in the browser to bring internal runbooks, exception notes, and operational context into a scoped agent session.","auth_modes":["api_token","oauth"],"config":{"type":"confluence_search","base_url":"https://YOUR-ATLASSIAN-SITE.atlassian.net/wiki","spaces":["SEC","ENG"],"max_pages":10}}]},"output_channels":{"channels":[{"id":"draft-pr-packet","label":"Draft PR packet","driver":"draft-pr","category":"Code handoff","status":"native","runtime_support":"copy_only","browser_delivery":true,"requirement":"No GitHub write required. Produces branch name, PR body, tests, rollback, and reviewer checklist.","description":"Reviewer-ready markdown and metadata for a pull request without writing to the source host.","config":{"type":"draft_pr_packet","labels":["security-remediation","ai-agent-draft"],"required_sections":["branch_name","pr_title","pr_body","test_plan","rollback","reviewer_checklist"]}},{"id":"github-issue","label":"GitHub issue","driver":"github-issue","category":"Ticketing","status":"native","runtime_support":"live","browser_delivery":true,"requirement":"Requires GitHub PAT or OAuth token with issues write access.","description":"Creates a GitHub issue with a normalized remediation or scan handoff body.","config":{"type":"github_issue","repository":"owner/repo","labels":["security-remediation","ai-agent-draft"],"issue_type":"Task"}},{"id":"slack-webhook","label":"Slack webhook","driver":"slack","category":"Collaboration","status":"native","runtime_support":"live","browser_delivery":true,"requirement":"Requires an incoming Slack webhook URL.","description":"Posts the report or remediation handoff into a Slack channel using an incoming webhook.","config":{"type":"slack_webhook","webhook_url":"https://hooks.slack.com/services/...","message_format":"mrkdwn","include_fields":["title","severity","scope","next_steps"]}},{"id":"email-handoff","label":"Email handoff","driver":"email","category":"Collaboration","status":"native","runtime_support":"live_or_copy","browser_delivery":true,"requirement":"Uses a local mailto draft, or a configured CORS-enabled email relay URL.","description":"Generates a browser mail draft or sends through a configured relay endpoint.","config":{"type":"email_handoff","to":["security-team@YOUR-DOMAIN"],"subject_prefix":"[SecurityRecipes]","relay_url":""}},{"id":"jira-ticket","label":"Jira ticket","driver":"jira","category":"Ticketing","status":"native","runtime_support":"live","browser_delivery":true,"requirement":"Requires Jira base URL, account email, API token, and project key.","description":"Creates a Jira task with a structured remediation or scan summary.","config":{"type":"jira_issue","base_url":"https://YOUR-ATLASSIAN-SITE.atlassian.net","project_key":"SEC","issue_type":"Task"}},{"id":"runbook-receipt","label":"Runbook receipt","driver":"runbook","category":"Reports and evidence","status":"native","runtime_support":"copy_only","browser_delivery":true,"requirement":"No external auth required. Produces copyable steps and evidence.","description":"Clipboard-friendly markdown for human execution with stop conditions and rollback.","config":{"type":"runbook_receipt","required_sections":["scope","steps","evidence","stop_conditions","rollback"]}},{"id":"server-runbook","label":"Server runbook","driver":"server-runbook","category":"Reports and evidence","status":"native","runtime_support":"copy_only","browser_delivery":true,"requirement":"No automatic server changes. Produces commands for a human-run maintenance window.","description":"Operations-focused handoff for patching or validation during a maintenance window.","config":{"type":"server_runbook","required_sections":["change_window","commands","verification","rollback"]}},{"id":"teams-workflow-webhook","label":"Microsoft Teams workflow webhook","driver":"teams","category":"Collaboration","status":"native","runtime_support":"live_or_copy","browser_delivery":true,"requirement":"Requires a Teams Workflows webhook URL. Microsoft 365 connectors are nearing deprecation, so prefer a Workflows-owned webhook.","description":"Posts a browser-generated handoff to a Microsoft Teams channel or chat through a Workflows webhook.","config":{"type":"teams_workflows_webhook","webhook_url":"https://prod-00.westus.logic.azure.com/workflows/...","payload_shape":"text_or_adaptive_card","include_fields":["title","severity","scope","recommendation","links"]}},{"id":"servicenow-incident","label":"ServiceNow incident","driver":"servicenow","category":"Ticketing","status":"native","runtime_support":"live_or_copy","browser_delivery":true,"requirement":"Requires a ServiceNow instance URL, table name, and OAuth bearer token with create access to the target table.","description":"Creates a ServiceNow incident or task record with a normalized remediation or scan summary.","config":{"type":"servicenow_incident","instance_url":"https://YOUR-SERVICENOW-INSTANCE.service-now.com","table":"incident","priority_map":{"critical":"1","high":"2","medium":"3"}}},{"id":"linear-issue","label":"Linear issue","driver":"linear","category":"Ticketing","status":"native","runtime_support":"live_or_copy","browser_delivery":true,"requirement":"Requires a Linear personal API key and a target team ID.","description":"Creates a Linear issue through the GraphQL API for security engineering or platform backlog handoff.","config":{"type":"linear_issue","team_id":"9cfb482a-81e3-4154-b5b9-2c805e70a02d","labels":["security-remediation","ai-agent"],"state":"Backlog"}},{"id":"splunk-hec","label":"Splunk HEC event","driver":"splunk-hec","category":"SIEM and analytics","status":"native","runtime_support":"live_or_copy","browser_delivery":true,"requirement":"Requires a Splunk HEC URL and HEC token.","description":"Posts the normalized report bundle directly to Splunk HTTP Event Collector for SIEM or analytics use.","config":{"type":"splunk_hec","hec_url":"https://YOUR-SPLUNK-HOST:8088/services/collector","sourcetype":"securityrecipes:report","index":"secops"}},{"id":"elastic-security-case","label":"Elastic Security case","driver":"elastic-case","category":"SIEM and analytics","status":"native","runtime_support":"live_or_copy","browser_delivery":true,"requirement":"Requires a Kibana base URL and Elastic API key with Cases write access.","description":"Creates an Elastic case with the generated remediation or scan summary.","config":{"type":"elastic_security_case","space_id":"default","tags":["security-remediation","browser-agent"],"owner":"securitySolution"}},{"id":"pagerduty-events-v2","label":"PagerDuty Events API v2","driver":"pagerduty","category":"Incident response","status":"native","runtime_support":"live_or_copy","browser_delivery":true,"requirement":"Requires a PagerDuty Events API v2 routing key or service integration configured for the target escalation path.","description":"Starter browser-side route for escalating a high-confidence incident or remediation brief into PagerDuty event orchestration.","config":{"type":"pagerduty_events_v2","events_api_url":"https://events.pagerduty.com/v2/enqueue","event_action":"trigger","payload_class":"security_remediation","dedup_key_template":"securityrecipes-{{asset_id}}-{{finding_key}}"}},{"id":"google-chat-webhook","label":"Google Chat webhook","driver":"google-chat","category":"Collaboration","status":"native","runtime_support":"live_or_copy","browser_delivery":true,"requirement":"Requires a Google Chat incoming webhook URL for the destination space.","description":"Starter browser-side route for posting a normalized remediation or incident brief into a Google Chat space.","config":{"type":"google_chat_webhook","webhook_url":"https://chat.googleapis.com/v1/spaces/SPACE_ID/messages?key=KEY&token=TOKEN","include_fields":["title","severity","scope","next_steps","links"]}},{"id":"azure-devops-work-item","label":"Azure DevOps work item","driver":"azure-devops","category":"Ticketing","status":"native","runtime_support":"live_or_copy","browser_delivery":true,"requirement":"Requires an Azure DevOps organization, project, work item type, and a PAT or bearer token with Work Items write scope.","description":"Browser-side route for creating an Azure DevOps work item from a normalized remediation or scan handoff, with local preview fallback when direct delivery is blocked.","config":{"type":"azure_devops_work_item","base_url":"https://dev.azure.com","project":"security-platform","work_item_type":"Issue","api_version":"7.1"}},{"id":"gitlab-issue","label":"GitLab issue","driver":"gitlab-issue","category":"Ticketing","status":"native","runtime_support":"live_or_copy","browser_delivery":true,"requirement":"Requires a GitLab project path or ID plus a personal access token or bearer token. GitLab.com works out of the box; self-managed hosts need a browser-allowed API base URL.","description":"Browser-side route for creating a GitLab issue with a normalized remediation or triage brief, with local preview fallback when direct delivery is blocked.","config":{"type":"gitlab_issue","base_url":"https://gitlab.com/api/v4","project":"group/project","labels":["security-remediation","ai-agent"],"issue_type":"issue"}},{"id":"cortex-xsoar-incident","label":"Cortex XSOAR incident","driver":"xsoar","category":"SOAR and case management","status":"native","runtime_support":"live_or_copy","browser_delivery":true,"requirement":"Requires a Cortex XSOAR tenant URL or incident endpoint plus API key ID and API key with incident create access. Direct browser delivery still depends on tenant CORS and any mandatory incident fields.","description":"Browser-side route for creating a Cortex XSOAR incident from a reviewed SecurityRecipes packet, with incident-shaped payloads and local preview fallback when direct delivery is blocked.","config":{"type":"cortex_xsoar_incident","base_url":"https://YOUR-XSOAR-HOST/xsoar/public/v1/incident","api_key_header":"Authorization","api_key_id_header":"x-xdr-auth-id","create_investigation":true,"incident_type":"Security","include_fields":["name","type","severity","details","rawJSON"]}},{"id":"ibm-soar-incident","label":"IBM SOAR incident","driver":"ibm-soar","category":"SOAR and case management","status":"template","runtime_support":"planned","browser_delivery":true,"requirement":"Requires an IBM SOAR organization URL and API credentials with incident create access.","description":"Starter browser-side route for creating an IBM SOAR incident from a structured SecurityRecipes packet.","config":{"type":"ibm_soar_incident","base_url":"https://YOUR-IBM-SOAR-HOST/rest/orgs/{orgId}/incidents","incident_type_ids":[123],"handle_format":"names"}},{"id":"microsoft-sentinel-playbook","label":"Microsoft Sentinel playbook trigger","driver":"sentinel-playbook","category":"SOAR and case management","status":"template","runtime_support":"planned","browser_delivery":true,"requirement":"Requires Azure subscription and workspace identifiers plus an OAuth token permitted to run Sentinel playbooks.","description":"Starter browser-side route for forwarding a reviewed packet into a Microsoft Sentinel incident playbook.","config":{"type":"microsoft_sentinel_playbook","base_url":"https://management.azure.com","resource_path":"/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.OperationalInsights/workspaces/{workspaceName}/providers/Microsoft.SecurityInsights/incidents/{incidentIdentifier}/runPlaybook","api_version":"2025-09-01"}},{"id":"tines-webhook","label":"Tines webhook","driver":"tines","category":"SOAR and case management","status":"native","runtime_support":"live_or_copy","browser_delivery":true,"requirement":"Requires a Tines webhook or HTTP Request action endpoint approved for browser-triggered incident or remediation intake, with any optional auth header or custom headers configured in the browser.","description":"Browser-side route for forwarding a reviewed SecurityRecipes packet into a Tines story or event-driven workflow, with local preview fallback when direct delivery is blocked.","config":{"type":"tines_webhook","webhook_url":"https://tenant.tines.com/webhook/...","story":"SecurityRecipes downstream orchestration","include_fields":["title","severity","scope","report","links"]}},{"id":"torq-webhook","label":"Torq workflow webhook","driver":"torq","category":"SOAR and case management","status":"native","runtime_support":"live_or_copy","browser_delivery":true,"requirement":"Requires a Torq webhook or API-triggered workflow endpoint plus any auth header or secret material approved for browser-side use.","description":"Browser-side route for sending a reviewed remediation or incident packet into a Torq automation workflow, with local preview fallback when direct delivery is blocked.","config":{"type":"torq_webhook","webhook_url":"https://api.torq.io/webhooks/...","workflow":"SecurityRecipes handoff","include_fields":["title","severity","scope","recommendation","artifacts"]}},{"id":"splunk-soar-incident","label":"Splunk SOAR incident","driver":"splunk-soar","category":"SOAR and case management","status":"native","runtime_support":"live_or_copy","browser_delivery":true,"requirement":"Requires a Splunk SOAR or Phantom tenant URL or /rest/container endpoint plus a ph-auth-token for an automation user with container create access. Direct browser delivery still depends on tenant CORS and label permissions.","description":"Browser-side route for creating a Splunk SOAR container from a reviewed SecurityRecipes packet, with container-shaped payloads and local preview fallback when direct delivery is blocked.","config":{"type":"splunk_soar_container","base_url":"https://YOUR-SPLUNK-SOAR-HOST/rest/container","auth_header":"ph-auth-token","label":"events","container_type":"case","include_fields":["name","label","description","severity","sensitivity","source_data_identifier","data"]}},{"id":"swimlane-case","label":"Swimlane case","driver":"swimlane","category":"SOAR and case management","status":"template","runtime_support":"planned","browser_delivery":true,"requirement":"Requires a Swimlane environment URL, app identifier, and API token with record create access for the target case app.","description":"Starter browser-side route for creating a Swimlane case or work item from a reviewed SecurityRecipes packet.","config":{"type":"swimlane_record","base_url":"https://YOUR-SWIMLANE-HOST/api","app":"Security Cases","record_type":"case"}},{"id":"generic-webhook","label":"Generic webhook","driver":"generic-webhook","category":"Custom integrations","status":"native","runtime_support":"live_or_copy","browser_delivery":true,"requirement":"Requires a browser-reachable webhook URL and any required headers or bearer token.","description":"Posts the full SecurityRecipes delivery envelope to a custom SOAR, queue, or workflow endpoint.","config":{"type":"generic_webhook","url":"https://YOUR-INTERNAL-WORKFLOW-HOST/hooks/security-recipes","method":"POST","headers":{"Content-Type":"application/json"}}}]},"report_profiles":{"profiles":[{"id":"remediation-pr-packet","label":"Remediation PR packet","status":"native","category":"Remediation","format":"markdown+json","description":"Reviewer-ready packet for a code or configuration fix that stops at draft stage.","sections":["executive_summary","scope","root_cause","proposed_change","validation","rollback","approvals"],"example_output":{"report_type":"remediation_pr_packet","risk_level":"high","status":"draft","evidence":["scanner_before","scanner_after","tests","reviewers"]}},{"id":"scan-findings-bundle","label":"Scan findings bundle","status":"native","category":"Scanning","format":"json","description":"Normalized browser-side report for imported SARIF, SBOM, and scanner context that can be copied or exported downstream as JSON.","sections":["metadata","source","summary","findings","severity_counts","recommended_workflows","artifacts"],"example_output":{"report_type":"scan_findings_bundle","finding_count":12,"critical":2,"high":5,"recommended_workflows":["dependency","sast","sensitive-data"],"scanner_artifacts":["findings.sarif.json","bom.cdx.json"]}},{"id":"ticket-ready-brief","label":"Ticket-ready brief","status":"native","category":"Operational handoff","format":"markdown","description":"Compact summary optimized for Jira, GitHub Issues, ServiceNow, Linear, or GitLab.","sections":["title","impact","scope","actions","owner_notes","links"],"example_output":{"report_type":"ticket_ready_brief","destination":"jira","priority":"high"}},{"id":"exec-risk-brief","label":"Executive risk brief","status":"native","category":"Reporting","format":"markdown+json","description":"Short-form leadership update for weekly risk review or board prep.","sections":["risk_statement","trend","top_findings","business_impact","next_actions"],"example_output":{"report_type":"exec_risk_brief","top_risk_theme":"agentic_api_exposure","decision_needed":"approve_connector_review"}},{"id":"run-receipt","label":"Run receipt","status":"native","category":"Evidence","format":"json","description":"Evidence-oriented receipt for a browser-run investigation or remediation planning session.","sections":["run_metadata","inputs","decisions","outputs","operator_notes"],"example_output":{"report_type":"run_receipt","runtime":"browser","byo_tokens":true,"human_review_required":true}},{"id":"investigation-session-packet","label":"Investigation session packet","status":"native","category":"Evidence","format":"json","description":"Grouped browser-local investigation session export with timeline, linked case reference, and handoff guidance.","sections":["investigation_session","session","timeline","linked_case","next_actions"],"example_output":{"report_type":"investigation_session_packet","session_kind":"agent_run","record_count":9,"linked_case_id":"case-dependency-fix-payments-api"}},{"id":"connector-intake-decision","label":"Connector intake decision","status":"native","category":"Governance","format":"json","description":"Structured approval, hold, or deny pack for new MCP or API integration candidates.","sections":["candidate","auth","egress","tool_surface","decision","required_controls"],"example_output":{"report_type":"connector_intake_decision","decision":"hold_for_review","required_controls":["token_audience_validation","audit_every_tool_call"]}},{"id":"incident-response-brief","label":"Incident response brief","status":"native","category":"Incident response","format":"markdown+json","description":"Short-form incident commander brief for XDR, SIEM, and responder escalation workflows.","sections":["incident_summary","triage","impacted_assets","containment","owner_handoff","evidence_links"],"example_output":{"report_type":"incident_response_brief","incident_severity":"high","recommended_escalation":"pagerduty"}},{"id":"case-management-packet","label":"Case management packet","status":"native","category":"Case management","format":"json","description":"Structured case payload optimized for SOAR and case-management systems that want fields instead of freeform prose.","sections":["title","severity","scope","tasks","entities","references","custom_fields"],"example_output":{"report_type":"case_management_packet","destination":"xsoar","case_template":"cloud_exposure"}},{"id":"siem-forwarding-envelope","label":"SIEM forwarding envelope","status":"native","category":"Telemetry","format":"json","description":"Normalized telemetry envelope for SIEM, webhook, and downstream analytics ingestion paths.","sections":["metadata","routing","summary","findings","entities","observables","artifacts"],"example_output":{"report_type":"siem_forwarding_envelope","destination":"splunk","event_count":1}}]},"workflow_templates":{"templates":[{"id":"github-dependency-pr-handoff","label":"GitHub dependency PR handoff","status":"curated","workflow_value":"dependency","description":"Use GitHub repo, deps.dev, and OSV.dev context to draft a narrow dependency remediation packet for human review.","default_recipe_query":"vulnerable dependency remediation","default_context_pack":"Secure context trust pack","default_report_profile_id":"remediation-pr-packet","default_output_channel_id":"draft-pr-packet","default_input_channel_ids":["page-context","recipe-index","github-repository","deps-dev-advisories","osv-vulnerability-api"],"default_approval_gate":"Security reviewer required","default_cadence":"Manual approval","target_hint":"owner/repo package/CVE"},{"id":"sast-triage-to-jira","label":"SAST triage to Jira","status":"curated","workflow_value":"sast","description":"Bundle bounded SAST findings into a Jira-ready brief and route the follow-up through a governed ticket.","default_recipe_query":"SAST finding triage","default_context_pack":"Runtime controls","default_report_profile_id":"ticket-ready-brief","default_output_channel_id":"jira-ticket","default_input_channel_ids":["page-context","recipe-index","sarif-manual-import"],"default_approval_gate":"Code owner required","default_cadence":"Manual approval","target_hint":"service/module SARIF upload"},{"id":"mcp-connector-intake-review","label":"MCP connector intake review","status":"curated","workflow_value":"mcp-guardrail","description":"Score a proposed connector, produce a hold/allow decision pack, and route it to governance stakeholders.","default_recipe_query":"MCP connector intake scanner","default_context_pack":"MCP gateway policy","default_report_profile_id":"connector-intake-decision","default_output_channel_id":"runbook-receipt","default_input_channel_ids":["page-context","recipe-index","confluence-knowledge"],"default_approval_gate":"Two-person review","default_cadence":"Manual approval","target_hint":"connector name / namespace"},{"id":"security-hub-risk-brief","label":"Security Hub risk brief","status":"curated","workflow_value":"recipe-runbook","description":"Aggregate cloud findings into an executive summary and downstream analyst brief.","default_recipe_query":"agentic risk review","default_context_pack":"Agentic assurance pack","default_report_profile_id":"exec-risk-brief","default_output_channel_id":"slack-webhook","default_input_channel_ids":["page-context","security-hub-api"],"default_approval_gate":"Security reviewer required","default_cadence":"Weekly sweep","target_hint":"account / business unit / region"},{"id":"snyk-triage-with-runbooks","label":"Snyk triage with runbooks","status":"curated","workflow_value":"recipe-runbook","description":"Pull bounded Snyk issues plus Confluence runbooks into a reviewer-ready remediation or triage brief.","default_recipe_query":"agentic risk review","default_context_pack":"Agentic assurance pack","default_report_profile_id":"ticket-ready-brief","default_output_channel_id":"jira-ticket","default_input_channel_ids":["recipe-index","snyk-issues-api","confluence-knowledge"],"default_approval_gate":"Security reviewer required","default_cadence":"Daily review queue","target_hint":"org / product / initiative"},{"id":"browser-run-receipt","label":"Browser run receipt","status":"curated","workflow_value":"recipe-runbook","description":"Document a BYO-token browser investigation or planning session with an evidence-first receipt.","default_recipe_query":"Run receipt","default_context_pack":"Secure context trust pack","default_report_profile_id":"run-receipt","default_output_channel_id":"runbook-receipt","default_input_channel_ids":["page-context","recipe-index"],"default_approval_gate":"Security reviewer required","default_cadence":"Manual approval","target_hint":"workflow / incident / repo"},{"id":"defender-xdr-incident-to-servicenow","label":"Defender XDR incident to ServiceNow","status":"curated","workflow_value":"recipe-runbook","description":"Pull a bounded Defender XDR incident, align containment with internal runbooks, and draft a ServiceNow follow-up.","default_recipe_query":"incident triage and containment","default_context_pack":"Runtime controls","default_report_profile_id":"incident-response-brief","default_output_channel_id":"servicenow-incident","default_input_channel_ids":["page-context","recipe-index","microsoft-defender-xdr-incidents","confluence-knowledge"],"default_approval_gate":"Security reviewer required","default_cadence":"On new finding","target_hint":"incident / device / user"},{"id":"sentinel-incident-to-pagerduty","label":"Sentinel incident to PagerDuty","status":"community","workflow_value":"recipe-runbook","description":"Summarize a live Sentinel incident and escalate a high-confidence response brief into PagerDuty.","default_recipe_query":"incident triage and containment","default_context_pack":"Runtime controls","default_report_profile_id":"incident-response-brief","default_output_channel_id":"pagerduty-events-v2","default_input_channel_ids":["page-context","recipe-index","microsoft-sentinel-incidents","confluence-knowledge"],"default_approval_gate":"Security reviewer required","default_cadence":"On new finding","target_hint":"subscription / workspace / incident"},{"id":"gitlab-vulnerability-to-gitlab-issue","label":"GitLab vulnerability to GitLab issue","status":"community","workflow_value":"dependency","description":"Turn GitLab vulnerability findings into a reviewer-ready fix plan and open a GitLab issue in the same project.","default_recipe_query":"vulnerable dependency remediation","default_context_pack":"Secure context trust pack","default_report_profile_id":"ticket-ready-brief","default_output_channel_id":"gitlab-issue","default_input_channel_ids":["recipe-index","gitlab-project-context","gitlab-vulnerability-findings","sbom-manual-import"],"default_approval_gate":"Code owner required","default_cadence":"Manual approval","target_hint":"group/project vulnerability"},{"id":"azure-devops-remediation-to-work-item","label":"Azure DevOps remediation to work item","status":"community","workflow_value":"dependency","description":"Use Azure DevOps repo context plus imported scanner artifacts to generate a governed remediation work item.","default_recipe_query":"vulnerable dependency remediation","default_context_pack":"Secure context trust pack","default_report_profile_id":"ticket-ready-brief","default_output_channel_id":"azure-devops-work-item","default_input_channel_ids":["page-context","recipe-index","azure-devops-repository","sarif-manual-import","sbom-manual-import"],"default_approval_gate":"Code owner required","default_cadence":"Manual approval","target_hint":"organization / project / repo"},{"id":"defectdojo-findings-to-jira","label":"DefectDojo findings to Jira","status":"community","workflow_value":"sast","description":"Bundle active DefectDojo findings into a Jira-ready analyst brief with recipe-backed remediation steps.","default_recipe_query":"SAST finding triage","default_context_pack":"Runtime controls","default_report_profile_id":"ticket-ready-brief","default_output_channel_id":"jira-ticket","default_input_channel_ids":["recipe-index","defectdojo-findings","confluence-knowledge"],"default_approval_gate":"Security reviewer required","default_cadence":"Daily review queue","target_hint":"product / engagement / finding set"},{"id":"cloud-alerts-to-xsoar-case","label":"Cloud alerts to XSOAR case","status":"community","workflow_value":"recipe-runbook","description":"Aggregate Wiz, Prisma Cloud, or Security Hub findings into a structured case payload for Cortex XSOAR.","default_recipe_query":"agentic risk review","default_context_pack":"Agentic assurance pack","default_report_profile_id":"case-management-packet","default_output_channel_id":"cortex-xsoar-incident","default_input_channel_ids":["recipe-index","wiz-findings-api","prisma-cloud-alerts","security-hub-api"],"default_approval_gate":"Two-person review","default_cadence":"On new finding","target_hint":"account / subscription / tenant"},{"id":"high-severity-detection-to-google-chat","label":"High-severity detection to Google Chat","status":"community","workflow_value":"recipe-runbook","description":"Post a compact high-severity detection brief to Google Chat for cross-functional review without leaving the browser runtime.","default_recipe_query":"incident triage and containment","default_context_pack":"Runtime controls","default_report_profile_id":"incident-response-brief","default_output_channel_id":"google-chat-webhook","default_input_channel_ids":["page-context","recipe-index","microsoft-defender-xdr-incidents","crowdstrike-detections"],"default_approval_gate":"Security reviewer required","default_cadence":"On new finding","target_hint":"chat space / responder group"},{"id":"community-scan-to-siem","label":"Community scan to SIEM","status":"community","workflow_value":"recipe-runbook","description":"Example community-submitted profile for normalizing scan outputs before forwarding them to a SIEM pipeline.","default_recipe_query":"scan findings bundle","default_context_pack":"Runtime controls","default_report_profile_id":"scan-findings-bundle","default_output_channel_id":"splunk-hec","default_input_channel_ids":["sarif-manual-import","sbom-manual-import"],"default_approval_gate":"Ticket required","default_cadence":"On new finding","target_hint":"scanner / tenant / environment"},{"id":"scanner-export-to-servicenow","label":"Scanner export to ServiceNow","status":"curated","workflow_value":"recipe-runbook","description":"Normalize a browser-local scanner export bundle into a reviewer-ready incident or remediation handoff for ServiceNow.","default_recipe_query":"scan findings bundle","default_context_pack":"Runtime controls","default_report_profile_id":"incident-response-brief","default_output_channel_id":"servicenow-incident","default_input_channel_ids":["page-context","recipe-index","scanner-export-bundle","confluence-knowledge"],"default_approval_gate":"Security reviewer required","default_cadence":"On new finding","target_hint":"scanner export / environment / service owner"},{"id":"scanner-export-to-splunk","label":"Scanner export to Splunk","status":"community","workflow_value":"recipe-runbook","description":"Forward normalized browser-local scanner export findings into a SIEM-ready envelope for Splunk or another downstream analytics pipeline.","default_recipe_query":"scan findings bundle","default_context_pack":"Agentic assurance pack","default_report_profile_id":"siem-forwarding-envelope","default_output_channel_id":"splunk-hec","default_input_channel_ids":["scanner-export-bundle","sarif-manual-import","sbom-manual-import"],"default_approval_gate":"Ticket required","default_cadence":"On new finding","target_hint":"scanner export / index / environment"},{"id":"sarif-to-servicenow-incident","label":"SARIF to ServiceNow incident","status":"curated","workflow_value":"sast","description":"Turn imported SARIF findings into a governed ServiceNow incident for SecOps or platform follow-up.","default_recipe_query":"SAST finding triage","default_context_pack":"Runtime controls","default_report_profile_id":"ticket-ready-brief","default_output_channel_id":"servicenow-incident","default_input_channel_ids":["page-context","recipe-index","sarif-manual-import"],"default_approval_gate":"Ticket required","default_cadence":"On new finding","target_hint":"service / module / SARIF upload"},{"id":"scan-bundle-to-elastic-case","label":"Scan bundle to Elastic case","status":"community","workflow_value":"recipe-runbook","description":"Normalize imported scanner evidence into a browser-side report bundle, then open an Elastic Security case.","default_recipe_query":"scan findings bundle","default_context_pack":"Agentic assurance pack","default_report_profile_id":"scan-findings-bundle","default_output_channel_id":"elastic-security-case","default_input_channel_ids":["sarif-manual-import","sbom-manual-import"],"default_approval_gate":"Security reviewer required","default_cadence":"On new finding","target_hint":"scanner / cluster / environment"},{"id":"weekly-risk-brief-to-teams","label":"Weekly risk brief to Teams","status":"community","workflow_value":"recipe-runbook","description":"Assemble a review-ready risk brief from imported findings and route it to a Teams channel through a workflow webhook.","default_recipe_query":"agentic risk review","default_context_pack":"Agentic assurance pack","default_report_profile_id":"exec-risk-brief","default_output_channel_id":"teams-workflow-webhook","default_input_channel_ids":["page-context","recipe-index","sarif-manual-import","sbom-manual-import"],"default_approval_gate":"Security reviewer required","default_cadence":"Weekly sweep","target_hint":"business unit / leadership channel / finding set"},{"id":"dependency-fix-to-linear","label":"Dependency fix to Linear","status":"community","workflow_value":"dependency","description":"Draft a reviewer-ready dependency remediation handoff and create a Linear issue for platform backlog tracking.","default_recipe_query":"vulnerable dependency remediation","default_context_pack":"Secure context trust pack","default_report_profile_id":"ticket-ready-brief","default_output_channel_id":"linear-issue","default_input_channel_ids":["page-context","recipe-index","github-repository","deps-dev-advisories","osv-vulnerability-api","sbom-manual-import"],"default_approval_gate":"Code owner required","default_cadence":"Manual approval","target_hint":"owner/repo package / team ID"},{"id":"github-code-scanning-to-jira","label":"GitHub code scanning to Jira","status":"community","workflow_value":"sast","description":"Turn GitHub code scanning alerts into a reviewer-ready Jira handoff that keeps repository context and remediation prompts together.","default_recipe_query":"SAST finding triage","default_context_pack":"Runtime controls","default_report_profile_id":"ticket-ready-brief","default_output_channel_id":"jira-ticket","default_input_channel_ids":["page-context","recipe-index","github-repository","github-code-scanning-alerts"],"default_approval_gate":"Code owner required","default_cadence":"On new finding","target_hint":"owner/repo alert number / branch"},{"id":"semgrep-findings-to-linear","label":"Semgrep findings to Linear","status":"community","workflow_value":"sast","description":"Use Semgrep AppSec findings plus recipe context to create a platform-ready Linear issue without leaving the browser workbench.","default_recipe_query":"SAST finding triage","default_context_pack":"Runtime controls","default_report_profile_id":"ticket-ready-brief","default_output_channel_id":"linear-issue","default_input_channel_ids":["recipe-index","semgrep-appsec-findings","confluence-knowledge"],"default_approval_gate":"Security reviewer required","default_cadence":"Daily review queue","target_hint":"deployment / project / rule set"},{"id":"aws-inspector-to-servicenow","label":"AWS Inspector to ServiceNow","status":"community","workflow_value":"recipe-runbook","description":"Pull AWS Inspector findings into a reviewed ServiceNow-ready incident or remediation handoff for cloud and platform teams.","default_recipe_query":"scan findings bundle","default_context_pack":"Agentic assurance pack","default_report_profile_id":"incident-response-brief","default_output_channel_id":"servicenow-incident","default_input_channel_ids":["recipe-index","aws-inspector-findings","confluence-knowledge"],"default_approval_gate":"Security reviewer required","default_cadence":"On new finding","target_hint":"account / region / workload"},{"id":"rapid7-vulnerability-to-swimlane","label":"Rapid7 vulnerability to Swimlane","status":"community","workflow_value":"recipe-runbook","description":"Turn Rapid7 InsightVM vulnerabilities into a structured Swimlane case packet for downstream coordination and response.","default_recipe_query":"scan findings bundle","default_context_pack":"Runtime controls","default_report_profile_id":"case-management-packet","default_output_channel_id":"swimlane-case","default_input_channel_ids":["recipe-index","rapid7-insightvm-vulnerabilities","confluence-knowledge"],"default_approval_gate":"Ticket required","default_cadence":"On new finding","target_hint":"site / asset group / vulnerability set"},{"id":"orca-alerts-to-tines","label":"Orca alerts to Tines","status":"community","workflow_value":"recipe-runbook","description":"Normalize Orca alerts into a Tines-ready payload so cloud exposure review can move straight into deterministic workflow automation.","default_recipe_query":"agentic risk review","default_context_pack":"Agentic assurance pack","default_report_profile_id":"case-management-packet","default_output_channel_id":"tines-webhook","default_input_channel_ids":["recipe-index","orca-security-alerts","prisma-cloud-alerts"],"default_approval_gate":"Two-person review","default_cadence":"On new finding","target_hint":"cloud account / exposure cluster / Tines story"},{"id":"veracode-review-to-torq","label":"Veracode review to Torq","status":"community","workflow_value":"sast","description":"Route reviewed Veracode findings into a Torq workflow for coordinated remediation, approvals, or exception handling.","default_recipe_query":"SAST finding triage","default_context_pack":"Runtime controls","default_report_profile_id":"case-management-packet","default_output_channel_id":"torq-webhook","default_input_channel_ids":["recipe-index","veracode-findings","confluence-knowledge"],"default_approval_gate":"Security reviewer required","default_cadence":"Daily review queue","target_hint":"application profile / finding set / Torq workflow"},{"id":"defender-xdr-to-splunk-soar","label":"Defender XDR to Splunk SOAR","status":"community","workflow_value":"recipe-runbook","description":"Take a bounded Defender XDR incident, attach recipe and runbook context, and package it for a Splunk SOAR container.","default_recipe_query":"incident triage and containment","default_context_pack":"Runtime controls","default_report_profile_id":"case-management-packet","default_output_channel_id":"splunk-soar-incident","default_input_channel_ids":["page-context","recipe-index","microsoft-defender-xdr-incidents","confluence-knowledge"],"default_approval_gate":"Security reviewer required","default_cadence":"On new finding","target_hint":"incident / device / Splunk SOAR container"}]},"readiness_profiles":{"runtime_labels":{"live":"Browser live","live_or_copy":"Live with copy fallback","copy_only":"Local copy only","config_only":"Config contract only","planned":"Reviewed starter contract","contract":"Contract only"},"auth_mode_labels":{"none":"No external auth","public":"Public access","pat":"Personal access token","bearer_token":"Bearer token","oauth":"OAuth delegated token","api_key":"API key","api_token":"API token","access_key":"Access key pair","aws_sigv4":"AWS SigV4 signing","webhook":"Webhook secret or URL"},"auth_mode_details":{"none":"No provider credential is required; the operator still chooses the exact page, file, or route input in the browser.","public":"The pack can rely on public or anonymously readable data, but the browser still needs a bounded repository, tenant, or document target.","pat":"A user-scoped personal access token must stay in browser storage and carry only the minimum read or write scope required for the selected task.","bearer_token":"A scoped bearer token must stay in browser storage and be sent only to the operator-configured gateway origin.","oauth":"The browser runtime needs an OAuth-capable flow and a delegated token with the provider scopes required for the selected source or route.","api_key":"The operator must paste a provider-issued API key into browser storage before the pack can call the provider API directly.","api_token":"The operator must supply a provider token or service token in browser storage before this pack can run.","access_key":"The pack needs provider access-key style credentials and should only be promoted when the browser flow can keep those values bounded and explicit.","aws_sigv4":"The browser runtime needs real AWS SigV4 request signing and short-lived credentials before the provider API can be called honestly from the browser.","webhook":"The destination system must expose a pre-approved webhook endpoint or secret-backed URL that the browser can post to directly."},"output_driver_auth_modes":{"draft-pr":["none"],"github-issue":["pat","oauth"],"slack":["webhook"],"email":["none"],"jira":["api_token"],"runbook":["none"],"server-runbook":["none"],"teams":["webhook"],"servicenow":["oauth"],"linear":["api_key"],"splunk-hec":["api_token"],"elastic-case":["api_key"],"pagerduty":["api_key"],"google-chat":["webhook"],"azure-devops":["pat","oauth"],"gitlab-issue":["pat","oauth"],"xsoar":["api_key"],"ibm-soar":["api_key"],"sentinel-playbook":["oauth"],"tines":["webhook"],"torq":["webhook"],"splunk-soar":["api_token"],"swimlane":["api_token"],"generic-webhook":["webhook"]},"runtime_requirements":{"live":"The browser workbench already has a direct BYO-token runtime path for this pack today.","live_or_copy":"The browser can try a direct write when the operator supplies the required config, and it still keeps a safe local copy or export fallback.","copy_only":"This pack intentionally stops at a local contract and never performs the external write for the operator.","config_only":"The contract shape is published for authoring and validation, but the browser runtime is not shipped.","planned":"This is a reviewed starter contract that still needs a verified browser-safe auth, API, and CORS story before promotion.","contract":"This entry is a reusable contract rather than a direct connector runtime."},"runtime_blockers":{"live":[],"live_or_copy":["Operator-owned credentials, webhook targets, or tenant metadata still need to be configured in the browser before a live call can run.","Provider cross-origin behavior and tenant policy still decide whether the direct browser path succeeds, so the local handoff fallback remains part of the design."],"copy_only":["No external write path exists by design, so a reviewer or downstream tool must copy, download, or relay the generated payload."],"config_only":["Only the configuration contract is published today; the browser runtime has not been implemented yet."],"planned":["The runtime path has not been promoted from starter contract to live browser flow yet.","Auth scope, request signing, pagination, throttling, and cross-origin behavior still need explicit verification for this provider."],"contract":["This pack shapes the workflow, but it is not itself a connector."]}}}