> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cotool.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# List critical issues

> Retrieve normalized critical issues from agent evaluations and code-detection circuit breakers.



## OpenAPI

````yaml https://app.cotool.ai/api/docs/openapi.json get /api/critical-issues
openapi: 3.1.0
info:
  title: Cotool API
  version: 1.0.0
  description: >-
    The Cotool REST API. Authenticate with an API key from `/settings/api-keys`
    sent as `Authorization: Bearer <key>`.


    Authentication, error formats, pagination, and common integration recipes
    are documented in the [API
    overview](https://docs.cotool.ai/api-reference/introduction). Endpoints
    marked **Deprecated** keep working; each one's description names its
    replacement.
servers:
  - url: https://app.cotool.ai
    description: Production server
security:
  - ApiKeyAuth: []
tags:
  - name: Agents
    description: Create, update, run, and version agents.
  - name: Agent Runs
    description: Inspect agent runs, submit feedback, and read evaluation metrics.
  - name: Agent Triggers
    description: Webhook, schedule, and integration triggers that start agent runs.
  - name: Agents as Code
    description: Validate agents and skills defined as YAML in a Git repository.
  - name: Skills
    description: Reusable instructions and tool grants attached to agents.
  - name: Chat
    description: Chat sessions and their transcripts.
  - name: Alerts
    description: Alert triage, routing, and escalation notifications.
  - name: Output Destinations
    description: Webhook, Slack, Jira, and Linear destinations for agent output.
  - name: Detections
    description: Detection agents, detection hits, and the Cotool detection library.
  - name: Hunt
    description: Autonomous hunt threats, gaps, and settings.
  - name: Intel
    description: Threat-intelligence feed items, indicators, and sources.
  - name: Threat Model
    description: The organization threat model and its version history.
  - name: MITRE Coverage
    description: MITRE ATT&CK coverage across detections.
  - name: Tools
    description: Connected tool integrations and captured tool output.
  - name: CLIs
    description: Connected CLI integrations.
  - name: Artifacts
    description: Files and reports produced by agent runs.
  - name: Audit Logs
    description: Organization audit log export and event catalog.
  - name: Users
    description: Users, memberships, and the current session.
  - name: Roles
    description: Role-based permissions.
  - name: Organizations
    description: Organization-level metrics.
paths:
  /api/critical-issues:
    get:
      tags:
        - Agent Runs
      summary: List critical issues
      description: >-
        Retrieve normalized critical issues from agent evaluations and
        code-detection circuit breakers.
      parameters:
        - in: query
          name: limit
          description: Number of critical issues to return
          schema:
            type: number
            minimum: 1
            maximum: 100
            default: 50
            description: Number of critical issues to return
        - in: query
          name: offset
          description: Number of critical issues to skip
          schema:
            type: number
            minimum: 0
            default: 0
            description: Number of critical issues to skip
        - in: query
          name: status
          description: Critical issue status filter
          schema:
            type: string
            enum:
              - open
              - dismissed
              - resolved
            default: open
            description: Critical issue status filter
        - in: query
          name: issueId
          description: Specific critical issue ID to return
          schema:
            type: string
            format: uuid
            description: Specific critical issue ID to return
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
                properties:
                  alerts:
                    type: array
                    items:
                      oneOf:
                        - type: object
                          properties:
                            id:
                              type: string
                              format: uuid
                            organizationId:
                              type: string
                              format: uuid
                            category:
                              type: string
                              enum:
                                - authentication
                                - connectivity
                                - missing_data
                                - permission
                                - configuration
                                - service_unavailable
                                - content_filter
                              description: >-
                                Critical Issue Categories that prevented task
                                completion (external blockers, not agent
                                faults):

                                authentication: OAuth tokens, API keys,
                                credentials failures

                                connectivity: Service/network connectivity
                                issues

                                missing_data: Required data/logs not available

                                permission: User lacks required permissions

                                configuration: Misconfiguration (wrong settings,
                                missing config)

                                service_unavailable: External service down or
                                unresponsive

                                content_filter: The LLM provider's content
                                safety filter declined a request
                            explanation:
                              type: string
                            status:
                              type: string
                              enum:
                                - open
                                - dismissed
                                - resolved
                            dismissedAt:
                              type:
                                - string
                                - 'null'
                            dismissedByUserId:
                              type:
                                - string
                                - 'null'
                              format: uuid
                            createdAt:
                              type: string
                            updatedAt:
                              type: string
                            sourceType:
                              type: string
                              const: agent_run
                            agentId:
                              type: string
                              format: uuid
                            agentName:
                              type: string
                            agentType:
                              type: string
                              enum:
                                - response
                                - detection
                              description: >-
                                Type of agent: response (standard agent) or
                                detection (security detection agent)
                            runId:
                              type: string
                              format: uuid
                            runTitle:
                              type: string
                            runCreatedAt:
                              type: string
                            agentRunEvalId:
                              type:
                                - string
                                - 'null'
                              format: uuid
                            evaluatorType:
                              type: string
                            evaluatorVersion:
                              type: string
                          required:
                            - id
                            - organizationId
                            - category
                            - explanation
                            - status
                            - dismissedAt
                            - dismissedByUserId
                            - createdAt
                            - updatedAt
                            - sourceType
                            - agentId
                            - agentName
                            - agentType
                            - runId
                            - runTitle
                            - runCreatedAt
                            - agentRunEvalId
                            - evaluatorType
                            - evaluatorVersion
                        - type: object
                          properties:
                            id:
                              type: string
                              format: uuid
                            organizationId:
                              type: string
                              format: uuid
                            category:
                              type: string
                              enum:
                                - authentication
                                - connectivity
                                - missing_data
                                - permission
                                - configuration
                                - service_unavailable
                                - content_filter
                              description: >-
                                Critical Issue Categories that prevented task
                                completion (external blockers, not agent
                                faults):

                                authentication: OAuth tokens, API keys,
                                credentials failures

                                connectivity: Service/network connectivity
                                issues

                                missing_data: Required data/logs not available

                                permission: User lacks required permissions

                                configuration: Misconfiguration (wrong settings,
                                missing config)

                                service_unavailable: External service down or
                                unresponsive

                                content_filter: The LLM provider's content
                                safety filter declined a request
                            explanation:
                              type: string
                            status:
                              type: string
                              enum:
                                - open
                                - dismissed
                                - resolved
                            dismissedAt:
                              type:
                                - string
                                - 'null'
                            dismissedByUserId:
                              type:
                                - string
                                - 'null'
                              format: uuid
                            createdAt:
                              type: string
                            updatedAt:
                              type: string
                            sourceType:
                              type: string
                              const: code_detection
                            codeDetectionId:
                              type: string
                              format: uuid
                            codeDetectionName:
                              type: string
                            codeDetectionExecutionId:
                              type: string
                              format: uuid
                            executionKind:
                              type: string
                              enum:
                                - editor
                                - manual
                                - scheduled
                            executionStartedAt:
                              type: string
                          required:
                            - id
                            - organizationId
                            - category
                            - explanation
                            - status
                            - dismissedAt
                            - dismissedByUserId
                            - createdAt
                            - updatedAt
                            - sourceType
                            - codeDetectionId
                            - codeDetectionName
                            - codeDetectionExecutionId
                            - executionKind
                            - executionStartedAt
                  totalCount:
                    type: integer
                required:
                  - alerts
                  - totalCount
                description: Paginated list of normalized critical issues
        '400':
          description: Bad request — input validation failed or the request was malformed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationError'
        '401':
          description: Unauthorized — missing or invalid API key / session
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Forbidden — the authenticated user lacks the required permissions
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PermissionError'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      x-codeSamples:
        - lang: shell
          label: cURL
          source: |-
            curl -X GET "https://app.cotool.ai/api/critical-issues" \
              -H "Authorization: Bearer YOUR_API_KEY" \
              -H "Content-Type: application/json"
components:
  schemas:
    ValidationError:
      type: object
      properties:
        error:
          type: string
          description: Error message describing what went wrong
        issues:
          type: array
          description: >-
            Detailed validation issues, present when request or response schema
            validation fails
          items:
            type: object
            additionalProperties: true
      required:
        - error
    Error:
      type: object
      properties:
        error:
          type: string
          description: Error message describing what went wrong
      required:
        - error
    PermissionError:
      type: object
      properties:
        error:
          type: string
          description: Error message describing what went wrong
        missingPerms:
          type: array
          description: Permissions the authenticated user is missing for this operation
          items:
            type: string
      required:
        - error
  securitySchemes:
    ApiKeyAuth:
      type: http
      scheme: bearer
      bearerFormat: API Key
      description: >-
        API Key authentication for programmatic access. Include your API key in
        the Authorization header as: `Bearer your_api_key_here`

````