# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Palo Alto Networks Vulnerabilities Dashboard API version: 1.0.0 extends: openapi/palo-alto-networks-vulnerabilities-dashboard-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 31 - target: $.paths['/trace/api/v1/asset'].post update: x-apievangelist-phrasing: intent: Trace an asset from code to cloud effect: read questions: - Can I see how a vulnerable asset connects across code, build, deploy and run stages? - Where does a container image I run in the cloud originate in my code repositories? instructions: - text: Trace the code-to-cloud asset graph for source {source}. slots: source: requestBody.source - text: Get the next page of the code-to-cloud trace for {source} using page token {token}. slots: source: requestBody.source token: requestBody.nextPageToken method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v1/dashboard/vulnerabilities/cve-overview'].get update: x-apievangelist-phrasing: intent: Get a basic CVE overview (legacy v1) effect: read questions: - What CVSS score, severity and affected packages does a CVE have in my environment, using the original overview endpoint? - Which lifecycle stages and distributions are hit by a given CVE on the first-generation dashboard? instructions: - text: Show the original v1 overview for {cve_id} with its CVSS score and impacted stages. slots: cve_id: query.cve_id - text: Get the legacy CVE overview for {cve_id} limited to {severities} severities. slots: cve_id: query.cve_id severities: query.severities method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v1/cve-overview'].get update: x-apievangelist-phrasing: intent: Get a CVE overview with EPSS and exploit details effect: read questions: - Does a CVE have a known exploit and what is its EPSS score in my environment? - Which environment factors raise the risk of a specific CVE, via the V2 GET overview? instructions: - text: Get the V2 CVE overview for {cve_id} including EPSS and exploit details. slots: cve_id: query.cve_id - text: Show V2 CVE details for {cve_id} in the {life_cycle} lifecycle stage. slots: cve_id: query.cve_id life_cycle: query.life_cycle method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v2/cve-overview'].post update: x-apievangelist-phrasing: intent: Get a CVE overview filtered by cloud account effect: read questions: - Can I scope a CVE's EPSS and CVSS details to specific account groups or cloud accounts? - What does a CVE look like inside one Kubernetes cluster namespace? instructions: - text: Get the CVE overview for {cveId} scoped to account group {accountGroups}. slots: cveId: requestBody.cveId accountGroups: requestBody.accountGroups - text: Show details for {cveId} in cluster {clusters} and namespace {clusterNamespaces}. slots: cveId: requestBody.cveId clusters: requestBody.clusters clusterNamespaces: requestBody.clusterNamespaces method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v2/dashboard/vulnerabilities/burndown'].get update: x-apievangelist-phrasing: intent: Get the 30-day vulnerability burndown effect: read questions: - How many vulnerabilities have we remediated over the past 30 days compared to the total? - Is our vulnerability burndown trending down for critical findings this month? instructions: - text: Show the 30-day vulnerability burndown. - text: Get the burndown of {severities} vulnerabilities for {asset_type} assets. slots: severities: query.severities asset_type: query.asset_type method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v1/dashboard/vulnerabilities/vuln-assets'].post update: x-apievangelist-phrasing: intent: List assets affected by a CVE (legacy) effect: read questions: - Which assets are affected by a particular CVE, using the original assets-by-CVE endpoint? - Can I exclude suppressed findings when listing the assets hit by one CVE on the older endpoint? instructions: - text: List the assets affected by {cve_id} with the legacy assets-by-CVE call. slots: cve_id: requestBody.cve_id - text: Page through assets hit by {cve_id} with page size {page_size} on the original endpoint. slots: cve_id: requestBody.cve_id page_size: requestBody.page_size method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v1/vuln-assets'].post update: x-apievangelist-phrasing: intent: List assets affected by a CVE per account effect: read questions: - Which of my cloud accounts have assets exposed to a specific CVE? - What assets in one account group are affected by a CVE, sorted by risk factors? instructions: - text: List V2 assets affected by {cve_id} in account {account_ids}. slots: cve_id: requestBody.cve_id account_ids: requestBody.account_ids - text: Find assets affected by {cve_id} within account group {account_groups} using the V2 call. slots: cve_id: requestBody.cve_id account_groups: requestBody.account_groups method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v1/dashboard/vulnerabilities/prioritised'].get update: x-apievangelist-phrasing: intent: Count top-priority vulnerabilities (v1) effect: read questions: - How many urgent, exploitable and patchable vulnerabilities do we have in total? - What is the count of priority vulnerabilities for a given risk factor in the v1 widget? instructions: - text: Count the top-priority vulnerabilities with the v1 prioritized endpoint. - text: Count v1 prioritized vulnerabilities that carry risk factor {risk_factors}. slots: risk_factors: query.risk_factors method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v2/dashboard/vulnerabilities/prioritised'].get update: x-apievangelist-phrasing: intent: List unique priority vulnerabilities with asset counts effect: read questions: - Which unique priority vulnerabilities occur on the most assets? - How many assets does each urgent or exploitable vulnerability appear in, filtered by risk factor? instructions: - text: List unique prioritized vulnerabilities with their asset counts (V2). - text: Show V2 prioritized vulnerabilities filtered to risk factor {risk_factors}. slots: risk_factors: query.risk_factors method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v3/dashboard/vulnerabilities/prioritised'].get update: x-apievangelist-phrasing: intent: List priority vulnerabilities including internet exposure effect: read questions: - Are any of our priority vulnerabilities on internet-exposed assets, per the V3 prioritized view? - What unique urgent vulnerabilities exist in the run stage once internet exposure is counted? instructions: - text: Get V3 prioritized vulnerabilities that add internet exposure to the ranking. - text: Show V3 prioritized vulnerabilities for {asset_type} assets in the {life_cycle} stage. slots: asset_type: query.asset_type life_cycle: query.life_cycle method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v4/dashboard/vulnerabilities/prioritised'].get update: x-apievangelist-phrasing: intent: Get priority vulnerabilities (V4 aggregation) effect: read questions: - What does the V4 prioritized vulnerability widget report for exploitable, internet exposed packages? - Which V4 top-priority vulnerabilities affect my deployed images? instructions: - text: Fetch the V4 prioritized vulnerabilities aggregation. - text: Get V4 top-priority vulnerabilities for {asset_type} in lifecycle {life_cycle}. slots: asset_type: query.asset_type life_cycle: query.life_cycle method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v5/dashboard/vulnerabilities/prioritised'].post update: x-apievangelist-phrasing: intent: Get priority vulnerabilities by account group effect: read questions: - Can I break down top-priority vulnerabilities by cloud account group or cluster? - Which urgent vulnerabilities affect a specific cloud account name? instructions: - text: Get prioritized vulnerabilities for account group {accountGroups}. slots: accountGroups: requestBody.accountGroups - text: Show prioritized vulnerabilities of severity {severities} in cloud account {accountIds}. slots: severities: requestBody.severities accountIds: requestBody.accountIds method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v1/dashboard/vulnerabilities/prioritised-vuln'].get update: x-apievangelist-phrasing: intent: Get top impacting CVEs by risk score (v1) effect: read questions: - What are the most critical CVEs in my environment ranked by risk score, on the original widget? - Which top CVEs impact the build stage, per the first top-impacting endpoint? instructions: - text: List the top {topN} impacting CVEs in the {life_cycle} stage with the v1 call. slots: topN: query.topN life_cycle: query.life_cycle - text: Show v1 top impacting vulnerabilities for lifecycle {life_cycle}. slots: life_cycle: query.life_cycle method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v2/dashboard/vulnerabilities/prioritised-vuln'].get update: x-apievangelist-phrasing: intent: Get top impacting CVEs with EPSS scores effect: read questions: - Which of my top CVEs have the highest EPSS exploit probability? - What are the ten most impactful CVEs for container images, including EPSS? instructions: - text: Get the top {topN} impacting CVEs with EPSS for the {life_cycle} stage. slots: topN: query.topN life_cycle: query.life_cycle - text: List top {topN} CVEs with EPSS for {asset_type} assets in {life_cycle}. slots: topN: query.topN asset_type: query.asset_type life_cycle: query.life_cycle method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v3/dashboard/vulnerabilities/prioritised-vuln'].post update: x-apievangelist-phrasing: intent: Get top impacting CVEs for an account group effect: read questions: - What are the top impacting CVEs within one cloud account group? - Can I limit the top-N critical CVE list to a cluster namespace? instructions: - text: Get the top {topNValue} impacting CVEs for account group {accountGroups}. slots: topNValue: requestBody.topNValue accountGroups: requestBody.accountGroups - text: List top impacting CVEs in cluster {clusters}. slots: clusters: requestBody.clusters method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v1/dashboard/vulnerabilities/overview'].get update: x-apievangelist-phrasing: intent: Get the vulnerability overview (v1) effect: read questions: - How many vulnerabilities do we have overall, split into by-asset and already remediated, on the v1 summary? - What does the original vulnerability overview show for a given risk factor? instructions: - text: Show the v1 vulnerability overview summary. - text: Get the v1 vulnerability summary for risk factor {risk_factors}. slots: risk_factors: query.risk_factors method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v2/dashboard/vulnerabilities/overview'].get update: x-apievangelist-phrasing: intent: Get the runtime vulnerability overview effect: read questions: - How many runtime vulnerabilities are in my environment right now? - What share of runtime vulnerabilities has already been remediated? instructions: - text: Show the runtime vulnerability overview. - text: Summarize runtime vulnerabilities by asset and remediated count. method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v3/dashboard/vulnerabilities/overview'].get update: x-apievangelist-phrasing: intent: Get vulnerability totals with weekly change effect: read questions: - How have our unique vulnerability counts changed versus seven days ago? - What is the severity breakdown of total and remediated vulnerabilities this week? instructions: - text: Get the V3 vulnerability overview with the week-over-week change. - text: Show V3 unique vulnerability totals for {severities} severities in {life_cycle}. slots: severities: query.severities life_cycle: query.life_cycle method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v4/dashboard/vulnerabilities/overview'].post update: x-apievangelist-phrasing: intent: Get vulnerability totals per cloud account effect: read questions: - What are the unique and remediated vulnerability counts for one cloud account? - Can I see the weekly vulnerability change for a specific account group only? instructions: - text: Get the vulnerability overview totals for account {accountIds}. slots: accountIds: requestBody.accountIds - text: Summarize vulnerability counts with weekly change for account group {accountGroups}. slots: accountGroups: requestBody.accountGroups method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v1/dashboard/vulnerabilities/impact-stage'].get update: x-apievangelist-phrasing: intent: Get vulnerability impact by lifecycle stage effect: read questions: - How are vulnerabilities spread across code, build, deploy and run stages? - Which application lifecycle stage carries the most critical vulnerabilities, using the GET version? instructions: - text: Show vulnerability impact by stage. - text: Get impact by stage for {severities} vulnerabilities on {asset_type} assets. slots: severities: query.severities asset_type: query.asset_type method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v2/dashboard/vulnerabilities/impact-stage'].post update: x-apievangelist-phrasing: intent: Get vulnerability impact by stage per account effect: read questions: - What is the stage-by-stage vulnerability impact for one cloud account group? - Can I see lifecycle stage impact limited to a Kubernetes cluster? instructions: - text: Get vulnerability impact by stage for account group {accountGroups}. slots: accountGroups: requestBody.accountGroups - text: Show stage impact of vulnerabilities for cluster {clusters}. slots: clusters: requestBody.clusters method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v1/dashboard/vulnerabilities/vulnerableAsset'].get update: x-apievangelist-phrasing: intent: Get vulnerable asset statistics effect: read questions: - How many registries, packages and repositories are vulnerable across our lifecycle? - What is the vulnerability count by severity for our vulnerable assets? instructions: - text: Show vulnerable asset statistics across lifecycle stages. - text: Get vulnerable asset stats for {asset_type} with {severities} severities. slots: asset_type: query.asset_type severities: query.severities method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v2/dashboard/vulnerabilities/vulnerableAsset'].post update: x-apievangelist-phrasing: intent: Get vulnerable asset stats per cloud provider effect: read questions: - How many vulnerable assets does each cloud provider have for a given CVE? - What are the total assets and vulnerabilities per stage for one account group? instructions: - text: Get vulnerable asset stats per cloud provider for {cveId}. slots: cveId: requestBody.cveId - text: Show asset stats for {cveId} in account group {accountGroups}. slots: cveId: requestBody.cveId accountGroups: requestBody.accountGroups method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v1/remediation/vuln-remediation-status'].post update: x-apievangelist-phrasing: intent: Check remediation status for a CVE effect: read questions: - Has the remediation action on a vulnerable asset been completed yet? - What is the remediation progress for all assets of one type affected by a CVE? instructions: - text: Check the remediation status of {cveId} for asset {assetId} under Prisma ID {prismaId} and type {assetType}. slots: cveId: requestBody.cveId assetId: requestBody.assetId prismaId: requestBody.prismaId assetType: requestBody.assetType - text: Get group-level remediation status for {cveId} on {assetType} assets for Prisma ID {prismaId}. slots: cveId: requestBody.cveId assetType: requestBody.assetType prismaId: requestBody.prismaId method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v1/remediation/vuln-create-remediation'].post update: x-apievangelist-phrasing: intent: Request remediation for a vulnerability effect: write questions: - Can I open a Jira ticket or merge request to fix a CVE on my assets? - Is it possible to suppress a vulnerability across every asset it affects? instructions: - text: Create a {remediationAction} remediation for {cveId} under Prisma ID {prismaId}. slots: remediationAction: requestBody.remediationAction cveId: requestBody.cveId prismaId: requestBody.prismaId - text: Raise a {remediationAction} request for {cveId} on asset {assetId} for Prisma ID {prismaId}. slots: remediationAction: requestBody.remediationAction cveId: requestBody.cveId assetId: requestBody.assetId prismaId: requestBody.prismaId method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v1/vulnerabilities/search/download'].post update: x-apievangelist-phrasing: intent: Download vulnerabilities matching an RQL query effect: read questions: - Can I export the results of a vulnerability RQL query to a CSV file? - What is the maximum number of vulnerability records I can download at once? instructions: - text: Download the vulnerabilities matching RQL {query} as a gzipped CSV. slots: query: requestBody.query - text: Export saved search {id} results for query {query} to CSV. slots: id: requestBody.id query: requestBody.query method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v1/vulnerabilities/download'].post update: x-apievangelist-phrasing: intent: Download CVE details as CSV (v1) effect: read questions: - Can I download a CSV of the assets impacted by one CVE with the original export endpoint? - Which older export call gives CVE details for a single unified asset? instructions: - text: Download v1 CVE details for {cveId} as a CSV file. slots: cveId: requestBody.cveId - text: Export the original CVE detail file for {cveId} limited to asset {unifiedAssetId}. slots: cveId: requestBody.cveId unifiedAssetId: requestBody.unifiedAssetId method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v2/vulnerabilities/download'].post update: x-apievangelist-phrasing: intent: Download CVE details as CSV (V2) effect: read questions: - Is there a V2 export of a CVE's impacted assets filtered by cloud account? - Can I use the second-version CVE download for one Kubernetes namespace? instructions: - text: Download V2 CVE details for {cveId} for account {accountIds}. slots: cveId: requestBody.cveId accountIds: requestBody.accountIds - text: Export V2 impacted assets of {cveId} in namespace {clusterNamespace}. slots: cveId: requestBody.cveId clusterNamespace: requestBody.clusterNamespace method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v3/vulnerabilities/download'].post update: x-apievangelist-phrasing: intent: Download details for several CVEs at once effect: read questions: - Can I download details for multiple CVEs in a single gzipped CSV request? - What is the current endpoint for exporting CVE details and impacted assets in bulk? instructions: - text: Download CVE details in bulk for requests {downloadRequests}. slots: downloadRequests: requestBody.downloadRequests - text: Export a batch CSV of impacted assets for the CVEs in {downloadRequests}. slots: downloadRequests: requestBody.downloadRequests method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v1/vulnerabilities/search/asset'].post update: x-apievangelist-phrasing: intent: Find vulnerable assets for a CVE by RQL effect: read questions: - Which asset IDs match a vulnerability RQL query for a particular CVE? - Can I search vulnerable assets by lifecycle and asset type with RQL? instructions: - text: Find {assetType} assets in {assetLifecycle} vulnerable to {cveId} matching RQL {query}. slots: assetType: requestBody.assetType assetLifecycle: requestBody.assetLifecycle cveId: requestBody.cveId query: requestBody.query - text: Search RQL {query} for assets affected by {cveId} in the {assetLifecycle} lifecycle as {assetType}. slots: query: requestBody.query cveId: requestBody.cveId assetLifecycle: requestBody.assetLifecycle assetType: requestBody.assetType method: generated generated: '2026-09-26' - target: $.paths['/uve/api/v1/vulnerabilities/search'].post update: x-apievangelist-phrasing: intent: Search vulnerabilities with RQL effect: read questions: - How can I query vulnerabilities with RQL and see the results in a CVE view? - Can I page through vulnerability search results from a saved search? instructions: - text: Search vulnerabilities with RQL {query}. slots: query: requestBody.query - text: Run RQL {query} and return results in the {view} view. slots: query: requestBody.query view: query.view - text: Get the next page of vulnerability search results for {query} with token {page_token}. slots: query: requestBody.query page_token: query.page_token method: generated generated: '2026-09-26'