Prerequisites
- Docker, installed and running.
- A running copy of your application that your machine can reach.
Run live validation
Add--live-validate and the URL of your application to a scan:
localhost URL works.
To test the findings of a finished scan, run agentgg live-validate on its output directory:
agentgg score ./out and agentgg fix ./out to update the scores and the suggested fixes for the new results.
Add testing instructions
Use--target-context to tell the test how to use your application, for example the account to sign in with, the pages to test, and the actions to avoid. Pass the text directly, or @ followed by the path to a file.
testing-instructions.txt
Results
Live validation tests each primary finding, except findings that the validator markedout-of-scope. A finding is reproduced only when the attack succeeds and the same steps with harmless input do not.
Evidence
Each tested finding gets a### Live validation section in its finding file, with the result and the reasoning.
reproduced and refuted findings also keep their evidence in a folder next to the finding file: the test script, the Playwright trace, screenshots, and the requests. A reproduced finding also keeps a video of the attack.
Run agentgg view ./out to see the evidence in your browser.
Options
For all flags, see Scan flags.

