> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# RoboShadow API

> Read RoboShadow CVE and missing-update reports, the fix for each CVE and remediation attempts, so an agent can patch vulnerable devices through your RMM

The RoboShadow API tool gives Neo agents read access to RoboShadow, the vulnerability management and endpoint security platform. The common use is a request like "analyse the missing CVEs for Contoso and remediate them": the agent reads the client's CVE report, the fix for each CVE, the affected devices and RoboShadow's own remediation attempts, then updates the devices with your RMM tools.

<Info>
  Automatically enabled when you configure RoboShadow permissions in your agent workflow.
</Info>

## What It Does

* Read the organisations your RoboShadow login reaches
* Read devices with their health scores, CVE counts and missing-update counts, and each device's installed applications, services, disks and hardware
* Read the CVE, CPE and vulnerable-application reports, with CVSS, EPSS and the known-exploited flag, and the fixes RoboShadow lists for each CVE
* Read missing Windows updates per device, and RoboShadow's remediation attempts with the CVEs each one addressed
* Read antivirus, ransomware protection, detected threats, Windows Defender and firewall status
* Read the users on each device and the Microsoft 365 MFA report
* Read external vulnerability scans and what each scanned IP address exposes

Neo reads RoboShadow and changes nothing there. To fix what it finds, the agent uses the RMM tools you give it, under their own approval rules, and reports what it changed.

## Permission Groups

| Group | Access levels | Covers |
| - | - | - |
| Organisations, Devices and Inventory | Disabled, Read Only | Organisations, devices, installed applications, services, disks, shares and hardware |
| Vulnerabilities and Updates | Disabled, Read Only | CVE, CPE and vulnerable-application reports, fixes per CVE, missing Windows updates and remediation attempts |
| Antivirus and Firewall | Disabled, Read Only | Antivirus and ransomware protection, threats, Windows Defender settings and firewall profiles |
| Users and MFA | Disabled, Read Only | RoboShadow users of an organisation, users and profiles on each device, and the Microsoft MFA report |
| External Scans | Disabled, Read Only | External vulnerability scans, their status and the vulnerabilities found per IP address and web target |

Every group is read only. Device rows in the other groups still name the logged-on user and carry IP and MAC addresses and serial numbers.

## Setup

See [Connecting RoboShadow to Neo](/integrations/roboshadow/connecting-to-neo).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.