# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Harness Frontend API version: 1.0.0 extends: openapi/harness-frontend-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 33 - target: $.paths['/sto/api/v2/frontend/all-issues/filters'].get update: x-apievangelist-phrasing: intent: List filter options for a project's security issues effect: read questions: - Which scanners, targets and severities can I filter a project's security issues by? - What filter values are available for the issues from my latest baseline scans? instructions: - text: Show the available issue filters for project {project}. slots: project: query.projectId - text: Get the filter options for the all-issues view of project {project} in org {org}. slots: project: query.projectId org: query.orgId method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/all-issues/issues'].get update: x-apievangelist-phrasing: intent: List security issues from latest baseline scans effect: read questions: - What security issues were found in my project's latest baseline scans? - Can I narrow the issue list to critical findings that are in the KEV catalog? - Is there a way to page through baseline scan issues filtered by scanner and status? instructions: - text: List baseline scan issues in project {project} with severity {severity}. slots: project: query.projectId severity: query.severityCodes - text: Page through issues from scanner {scanner} in project {project}, page {page}. slots: scanner: query.scanTools project: query.projectId page: query.page - text: Find baseline issues in project {project} matching {text}. slots: project: query.projectId text: query.search method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/all-issues/issues/{issueId}'].get update: x-apievangelist-phrasing: intent: Get a security issue's baseline scan details effect: read questions: - What are the full details of one security issue from the latest baseline scans? - Can I see which targets a single baseline issue shows up in? instructions: - text: Show baseline scan details for issue {issue} in project {project}. slots: issue: path.issueId project: query.projectId - text: Get issue {issue} details including exempted occurrences with status {exemption}. slots: issue: path.issueId exemption: query.exemptionStatuses method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/all-issues/issues/{issueId}/targets/{targetId}'].get update: x-apievangelist-phrasing: intent: List an issue's occurrences on one target effect: read questions: - Where exactly does a security issue occur on a specific scan target? - Can I page through the occurrences of one issue for a single target? instructions: - text: List occurrences of issue {issue} on target {target}. slots: issue: path.issueId target: path.targetId - text: Show page {page} of occurrences for issue {issue} on target {target} in project {project}. slots: page: query.page issue: path.issueId target: path.targetId project: query.projectId method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/all-issues/v2/counts'].get update: x-apievangelist-phrasing: intent: Count issues by severity and issue type effect: read questions: - How many security issues does my project have per severity level? - Can I get issue counts broken down by issue type for the all-issues page? instructions: - text: Count issues by severity and type for project {project}. slots: project: query.projectId - text: Get severity and type counts for project {project} limited to scanner {scanner}. slots: project: query.projectId scanner: query.scanTools method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/all-issues/v2/counts/total'].get update: x-apievangelist-phrasing: intent: Get total issue and occurrence counts effect: read questions: - What is the overall number of issues and occurrences in a project, ignoring filters? - How many total occurrences of security issues does my project have? instructions: - text: Give me the unfiltered total issue and occurrence count for project {project}. slots: project: query.projectId - text: Show grand totals of issues and occurrences in project {project}, org {org}. slots: project: query.projectId org: query.orgId method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/all-issues/v2/issues'].get update: x-apievangelist-phrasing: intent: List project issues from the summary table effect: read questions: - Is there a faster, pre-aggregated way to list all of a project's security issues? - Can the v2 issues list filter by EPSS score and reachability? instructions: - text: List project {project} issues from the pre-aggregated summary, page {page}. slots: project: query.projectId page: query.page - text: Use the v2 issues list to show issues with reachability {reach} in project {project}. slots: project: query.projectId reach: query.reachability - text: Pull v2 summary issues for project {project} with status {status}. slots: project: query.projectId status: query.statuses method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/all-issues/v2/issues/{issueId}'].get update: x-apievangelist-phrasing: intent: Get issue details from the summary tables effect: read questions: - Can I fetch one issue's details from the pre-aggregated summary and detection data? - What does the v2 issue detail view return for a single finding? instructions: - text: Get v2 summary-table details for issue {issue} in project {project}. slots: issue: path.issueId project: query.projectId - text: Open the detection-table view of issue {issue}. slots: issue: path.issueId method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/all-issues/v2/trend'].get update: x-apievangelist-phrasing: intent: Show daily issue trend by status effect: read questions: - How have my project's open and resolved issue counts changed day by day? - Can I see the issue trend over the last 30 days for one scanner? instructions: - text: Show the daily issue status trend for project {project} over {days} days. slots: project: query.projectId days: query.intervalDays - text: Chart daily issue counts by status for project {project} with severity {severity}. slots: project: query.projectId severity: query.severityCodes method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/executions/trend'].get update: x-apievangelist-phrasing: intent: Show finding trend across scans for a target effect: read questions: - How have severity counts changed across scans of one target variant? - Can I see the finding trend per execution for a specific branch or image? instructions: - text: Show the per-scan finding trend for target variant {variant} in project {project}. slots: variant: query.targetVariantId project: query.projectId - text: Get severity counts per execution for variant {variant} over the last {days} days. slots: variant: query.targetVariantId days: query.intervalDays method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/exemption/{exemptionId}/issue-severity-change'].get update: x-apievangelist-phrasing: intent: Preview severity change from an exemption effect: read questions: - What happens to an issue's severity if I approve an occurrence-level exemption? - Will approving this exemption lower the issue's overall severity? instructions: - text: Preview the severity change for issue {issue} if exemption {exemption} is approved. slots: issue: query.issueId exemption: path.exemptionId - text: Check how exemption {exemption} would shift the severity of issue {issue} in scan {scan}. slots: exemption: path.exemptionId issue: query.issueId scan: query.scanId method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/exemption/{exemptionId}/targets'].get update: x-apievangelist-phrasing: intent: List targets impacted by an exemption effect: read questions: - Which scan targets does a given exemption apply to? - Can I search the targets affected by one exemption? instructions: - text: List the targets impacted by exemption {exemption}. slots: exemption: path.exemptionId - text: Search targets affected by exemption {exemption} for {text}. slots: exemption: path.exemptionId text: query.search method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/exemptions'].post update: x-apievangelist-phrasing: intent: Review exemptions across the account effect: read questions: - Which exemption requests are pending review across all my projects? - Can I filter account-wide exemptions by who approved or requested them? - What does the global exemptions security review show for approved exemptions? instructions: - text: List global exemptions with status {status} for account {account}. slots: status: query.status account: query.accountId - text: Show account-wide exemptions with status {status} requested by {user}. slots: status: query.status user: requestBody.requestedBy - text: Review global exemptions with status {status} sorted by {field}. slots: status: query.status field: query.sortBy method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/exemptions/filters'].post update: x-apievangelist-phrasing: intent: List filter options for exemptions effect: read questions: - What filter values can I use when reviewing exemptions? - Which requesters, scanners and pipelines appear in the exemption filters? instructions: - text: Get the exemption filter options for account {account}. slots: account: query.accountId - text: Show exemption filter values scoped to org {org}. slots: org: query.orgId method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/expiring-exemptions/{executionId}'].get update: x-apievangelist-phrasing: intent: List exemptions about to expire for an execution effect: read questions: - Which exempted issues in a pipeline run are going to expire soon? - Can I see exemptions expiring within the next few days for an execution? instructions: - text: List issues whose exemptions expire soon for execution {execution}. slots: execution: path.executionId - text: Show exemptions in execution {execution} expiring within {days} days. slots: execution: path.executionId days: query.days method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/issue-counts'].get update: x-apievangelist-phrasing: intent: Count active issues for pipeline executions effect: read questions: - How many active security issues did my pipeline runs produce? - Can I get issue counts for several pipeline executions at once? instructions: - text: Count active security issues for executions {executions} in project {project}. slots: executions: query.executionIds project: query.projectId - text: Get active issue totals for pipeline execution {executions}. slots: executions: query.executionIds method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/issue-exemption/{exemptionId}'].get update: x-apievangelist-phrasing: intent: Get the issue behind an exemption effect: read questions: - What issue does a specific exemption cover? - Can I view the details of one issue exemption and its targets? instructions: - text: Show the issue exemption {exemption}. slots: exemption: path.exemptionId - text: Get exemption {exemption} limited to target {target}. slots: exemption: path.exemptionId target: query.targetId method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/issues/{issueId}/occurrence/{occurrenceInternalId}/dataflow'].get update: x-apievangelist-phrasing: intent: Get dataflow for an issue occurrence effect: read questions: - How does tainted data flow through the code for one vulnerability occurrence? - Can I load the source-to-sink dataflow for a single occurrence separately? instructions: - text: Get the dataflow for occurrence {occurrence} of issue {issue}. slots: occurrence: path.occurrenceInternalId issue: path.issueId - text: Show source-to-sink trace for issue {issue} occurrence {occurrence} in project {project}. slots: issue: path.issueId occurrence: path.occurrenceInternalId project: query.projectId method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/licenses/qwiet/trial'].post update: x-apievangelist-phrasing: intent: Start a Qwiet trial license effect: write questions: - Can I start a Qwiet trial for my account? - What happens to my STO license when a Qwiet trial is provisioned? instructions: - text: Provision a Qwiet trial license for account {account}. slots: account: query.accountId - text: Turn on the Qwiet trial for account {account}. slots: account: query.accountId method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/metrics/licenseUsage'].get update: x-apievangelist-phrasing: intent: Get Qwiet license usage effect: read questions: - How much of our Qwiet license are we using? - Where can I see Qwiet license usage metrics for the account? instructions: - text: Show Qwiet license usage for account {account}. slots: account: query.accountId - text: Report current Qwiet license consumption for account {account}. slots: account: query.accountId method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/overview/baselines'].get update: x-apievangelist-phrasing: intent: Get baseline executions for the overview effect: read questions: - Which baseline scan executions feed my project's security overview? - What baseline data does the STO overview page use? instructions: - text: Get overview baseline execution data for project {project}. slots: project: query.projectId - text: Show the latest baseline runs behind the overview of project {project}. slots: project: query.projectId method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/overview/historical-counts'].get update: x-apievangelist-phrasing: intent: Get historical issue counts for the overview effect: read questions: - How many issues did my project have over the past few weeks? - Can I get historical issue numbers for the security overview dashboard? instructions: - text: Get historical issue counts for project {project} over {days} days. slots: project: query.projectId days: query.days - text: Show issue history for the overview of project {project}. slots: project: query.projectId method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/pipeline-security/issues'].get update: x-apievangelist-phrasing: intent: List new and existing issues for a pipeline run effect: read questions: - What security issues did a specific pipeline execution find, split into new and existing? - Can I page new issues and existing issues separately for one pipeline run? instructions: - text: List new and existing security issues for execution {execution}. slots: execution: query.executionId - text: Show pipeline run {execution} issues from step {step}, excluding exemptions. slots: execution: query.executionId step: query.steps - text: Get page {page} of new issues for pipeline execution {execution}. slots: page: query.pageNew execution: query.executionId method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/pipeline-security/issues/csv'].get update: x-apievangelist-phrasing: intent: Export a pipeline run's issues for CSV effect: read questions: - Can I export the security issues from a pipeline run as a CSV? - What data do I get when downloading pipeline security issues for a spreadsheet? instructions: - text: Export security issues from execution {execution} for CSV. slots: execution: query.executionId - text: Download a CSV of severity {severity} issues from pipeline run {execution}. slots: severity: query.severityCodes execution: query.executionId method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/pipeline-security/steps'].get update: x-apievangelist-phrasing: intent: List security steps in a pipeline run effect: read questions: - Which scan steps ran in a given pipeline execution? - What step data does the pipeline security view show? instructions: - text: List the security scan steps for execution {execution}. slots: execution: query.executionId - text: Show step data for pipeline execution {execution} in project {project}. slots: execution: query.executionId project: query.projectId method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/pipeline-security/v2/issues'].get update: x-apievangelist-phrasing: intent: List a pipeline run's issues in one combined list effect: read questions: - Can I get one combined list of new-then-existing issues for a pipeline run? - Is there a single paginated pipeline issue list that also covers the remediation agent tab? instructions: - text: Give me the combined new-first issue list for execution {execution}. slots: execution: query.executionId - text: Show combined pipeline issues for execution {execution} with detection type {type}. slots: execution: query.executionId type: query.detectionType - text: List remediation agent tab issues for execution {execution} and summary {summary}. slots: execution: query.executionId summary: query.remAgentSummaryId method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/remediation-agent/activities'].get update: x-apievangelist-phrasing: intent: List remediation agent PR activity for a run effect: read questions: - What pull requests has the remediation agent opened for a pipeline execution? - Can I see the remediation agent's activity for the scans in one run? instructions: - text: List remediation agent PR activities for execution {execution}. slots: execution: query.executionId - text: Show the next {count} remediation agent activities for execution {execution}. slots: count: query.pageSize execution: query.executionId method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/remediation/trend'].get update: x-apievangelist-phrasing: intent: Show active remediation trend effect: read questions: - How is active remediation trending across my project's scans? - Can I see the remediation trend for just one target variant? instructions: - text: Show the project-wide active remediation trend for project {project}. slots: project: query.projectId - text: Get the remediation trend for target variant {variant} over {days} days. slots: variant: query.targetVariantId days: query.intervalDays method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/security-review'].get update: x-apievangelist-phrasing: intent: Get exemptions for a project's security review effect: read questions: - Which exemptions in my project are waiting for security review? - Can I search the project-level security review queue by status? instructions: - text: Show the security review list with status {status} for project {project}. slots: status: query.status project: query.projectId - text: Search project {project} security review items with status {status} for {text}. slots: project: query.projectId status: query.status text: query.search method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/test-targets'].get update: x-apievangelist-phrasing: intent: List test targets in a project effect: read questions: - Which test targets are being scanned in my project? - Can I search test targets and see their variants? instructions: - text: List test targets for project {project}. slots: project: query.projectId - text: Find test targets in project {project} named {text}. slots: project: query.projectId text: query.search method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/test-targets/{targetId}/variants/status'].put update: x-apievangelist-phrasing: intent: Update statuses of test target variants effect: write questions: - Can I change the status of several variants of a test target at once? - How can I mark a branch variant of a target as no longer tracked? instructions: - text: Update variant statuses for test target {target} to {variants}. slots: target: path.targetId variants: requestBody.targetVariants - text: Set the variant statuses on target {target} in project {project}. slots: target: path.targetId project: query.projectId method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/tickets'].post update: x-apievangelist-phrasing: intent: Create or link a Jira ticket for an issue effect: write questions: - Can I open a Jira ticket for a security issue straight from STO? - Is it possible to link an existing Jira ticket to an issue instead of creating one? instructions: - text: Create a Jira ticket in project {jira} for issue {issue} of type {type}. slots: jira: requestBody.projectKey issue: requestBody.issueId type: requestBody.issueType - text: File a Jira ticket titled {title} in {jira} for issue {issue}. slots: title: requestBody.title jira: requestBody.projectKey issue: requestBody.issueId method: generated generated: '2026-09-26' - target: $.paths['/sto/api/v2/frontend/tickets/occurrence'].post update: x-apievangelist-phrasing: intent: Create a Jira ticket for one occurrence effect: write questions: - Can I raise a Jira ticket for just one occurrence of an issue rather than the whole issue? - What does a ticket for a single vulnerability occurrence include? instructions: - text: Create a Jira ticket in {jira} for occurrence {occurrence} of issue {issue} on target {target}. slots: jira: requestBody.projectKey occurrence: requestBody.occurrenceInternalId issue: requestBody.issueId target: requestBody.targetId - text: Open a single-occurrence ticket for occurrence {occurrence} with notes {notes}. slots: occurrence: requestBody.occurrenceInternalId notes: requestBody.notes method: generated generated: '2026-09-26'