Start a run
Starts an agent on a task and returns the run while it initializes. Each successful request creates a separate run. The agent continues independently of your HTTP connection.
Supply an agent configuration and instructions with targets, vulnerabilityIds, or both. A base such as tcell uses that pre-built agent’s defaults; supplied configuration fields replace the corresponding exposed defaults. Vulnerability IDs are resolved within your organization. Target scope is checked before execution.
The SDK serializes the Agent object into agent and converts task vulnerabilities into vulnerabilityIds. The run retains the resolved configuration even if the registered agent changes later.
{
"id": "run_123",
"status": "creating",
"agent": {
"base": "tcell",
"model": "claude-opus-5-cyber",
"skills": [
"Check authorization when one account requests another account’s resources."
],
"guardrails": "Do not attempt denial of service.",
"tools": [
"asset_map",
"human_tasks"
]
},
"task": {
"instructions": "Test the production API for authorization vulnerabilities.",
"targets": [
"api.example.com"
]
},
"createdAt": "2026-09-13T10:00:00.000Z",
"updatedAt": "2026-09-13T10:00:00.000Z",
"error": null
}{
"error": {
"code": "invalid_request",
"message": "Check the request fields and values."
}
}{
"error": {
"code": "unauthorized",
"message": "Supply a valid API key."
}
}{
"error": {
"code": "forbidden",
"message": "The API key does not permit this operation or requested scope."
}
}{
"error": {
"code": "rate_limited",
"message": "Retry after the interval in Retry-After."
}
}Authorizations
API key from your organization. Supply the value directly, without a Bearer prefix.
Body
An agent configuration. Supply a pre-built base, a model, or both. Omitted fields use the base configuration, or empty skills and guardrails with asset_map and human_tasks tools when no base is supplied. Supplied fields replace the corresponding values. A retrieved Agent can be passed directly; name and builtIn are response metadata and do not change execution.
- Option 1
- Option 2
Show child attributes
Show child attributes
{ "base": "tcell" }
- Option 1
- Option 2
Show child attributes
Show child attributes
{ "instructions": "Test the production API for authorization vulnerabilities.", "targets": ["api.example.com"] }
Response
Created.
1creating, running, stopped, completed, failed Show child attributes
Show child attributes
{ "base": "tcell", "model": "claude-opus-5-cyber", "skills": [ "Check authorization when one account requests another account’s resources." ], "guardrails": "Do not attempt denial of service.", "tools": ["asset_map", "human_tasks"] }
- Option 1
- Option 2
Show child attributes
Show child attributes
{ "instructions": "Test the production API for authorization vulnerabilities.", "targets": ["api.example.com"] }
Failure description when status is failed; otherwise null.
{
"id": "run_123",
"status": "creating",
"agent": {
"base": "tcell",
"model": "claude-opus-5-cyber",
"skills": [
"Check authorization when one account requests another account’s resources."
],
"guardrails": "Do not attempt denial of service.",
"tools": [
"asset_map",
"human_tasks"
]
},
"task": {
"instructions": "Test the production API for authorization vulnerabilities.",
"targets": [
"api.example.com"
]
},
"createdAt": "2026-09-13T10:00:00.000Z",
"updatedAt": "2026-09-13T10:00:00.000Z",
"error": null
}{
"error": {
"code": "invalid_request",
"message": "Check the request fields and values."
}
}{
"error": {
"code": "unauthorized",
"message": "Supply a valid API key."
}
}{
"error": {
"code": "forbidden",
"message": "The API key does not permit this operation or requested scope."
}
}{
"error": {
"code": "rate_limited",
"message": "Retry after the interval in Retry-After."
}
}