> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/scripts/create-a-script.md).

# Create a script

Creating custom scripts helps meet your organization’s specific needs to automate repetitive tasks, streamline security operations, and make case response more efficient.

1. Navigate to Investigation & Response → Automation → Scripts and click New Script.
2. Add an identifying name for the script.
3. Click Save.
4. In the Agentic Assistant pane, start a conversation with the Automation Engineer agent to create the script, or manually create the script code and define the script settings.

   For more information, see [Use the Automation Engineer agent to accelerate script development and deployment](https://app.gitbook.com/s/cyIgISZgANJYkmLlnwdK/investigate-and-respond-to-cases/automation/scripts/accelerate-script-development-using-the-automation-engineer-agent). For details about script settings, see [Create a script](https://app.gitbook.com/s/cyIgISZgANJYkmLlnwdK/investigate-and-respond-to-cases/automation/scripts/create-a-script).
5. Save the script version.
6. (Recommended) Click Test to validate your script.
   1. In the Arguments section, provide values for any inputs your prompt requires. These inputs are used to simulate how the script will behave in a live playbook, or how the script registered as an Action and assigned to an Agent will run as part of an executed plan.

      You can add input values manually.
   2. Click Run.

      The tests are executed in a Playground environment. Review the output generated by the AI to validate the script's behavior and ensure it produces the expected results. The output is typically a text summary or another structured format that you have defined.

      If there is an error, you can copy the error message from the test result into the Agentic Assistant prompt and ask the Automation Engineer agent to correct the error.

      In each run result, you can take the following actions:

      | Action                   | Description                                                                                                                                                                                                                                    |
      | ------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
      | Mark as note             | <p>Marks the entry as a note, which can help you understand why certain action was taken and assist future decisions.</p><p>When marked as a note, it is highlighted, so you can easily find it in the War Room or the Issue Overview tab.</p> |
      | View artifact in new tab | Opens a new tab for the artifact.                                                                                                                                                                                                              |
      | Download artifact        | Downloads the run details to a text file, including the AI task name,, the script name, user name and password, and the result.                                                                                                                |
      | Add tags                 | Add any relevant tags to use that help you find relevant information.                                                                                                                                                                          |
7. (Optional) Click [![three-dots-dark.png](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAjCAYAAAD17ghaAAAACXBIWXMAABJ0AAASdAHeZh94AAAAB3RJTUUH6QsCDQAEL/NOOgAAApxJREFUWIXtVzFrpEAYfXPIoOIMBq1clmUk2N2vuCK/5ur7CYH8lTTpUh6Brba9zkIJi1spBkdUjOAVYWVvV129y7Ep8irRb973+ObNN59ktVq1uCC+XDL5p4APIUCZGmgYBq6ursAYg6ZpUJS3pU3ToCxLSCmRpinyPH9fAaZpwnEcUEqRJAmiKEJRFGia5o1AUaDrOjjnuL6+Rl3X2O12eHl5mSSAjB1DIQQ454iiCHEcTyK0bRuLxQJZliEMw78ToCgKPM9DVVUIwxBtO69VEEIghICqqvB9v6tWH3pN6HkepJQIgmB2cgBo2xZBEEBKCc/zRmNPBAghUFUVttvt7MTH2G63qKoKQohpAkzTBOf87N7d3D1is9lgs9ng8e5mNDYMQ3DOYZrmeQGO4yCKorNltxntnimzR2PbtkUURXAcZ1yAYRiglE5ye33oqaY+Gx/HMSilMAzj5Ft3CpbLJQC8y973YYi/qwBjDFmW/ZfkAJBlGRhjJ+87AZqmoSiKSWRzTLhHURTQNG1YgKIoow3jEHNMuEfTNN390StgDuaacAydpL3C19fXs4vuv3/D/dxEAxXuKlCWJXRdn0k7HbquoyzLYQFSSnDOJ5Hd3D5g/bTG+mmNh9tpJuScQ0o5LCBNU1iWNYnMNhmoRkE1CmZOM6FlWUjTdFhAnueo6xq2fZ5wrglt20Zd173T0h/nYrfbYbVaIUmS0fvg/u4H4q8WKGokv36OJieEYLFY4Pn5uf/78UAihAAhBEEQjBJPheu6aNt28IY96QNhGEJV1a53/wuWyyVUVR293nsbke/7YIzBdV0QQmYnJoTAdV0wxuD7/njshxxKD3E8lmdZNjiWW5b1vmP5IS72Y7JHnuezyafg4v+GnwJ+AxX2QhQiVAHvAAAAAElFTkSuQmCC)](https://docs-cortex.paloaltonetworks.com/viewer/attachment/GD6sG6FlxDWxAn13_eZuUQ/397odY1bQBdxlJldZh0LQg-GD6sG6FlxDWxAn13_eZuUQ) and select Register new Action to register the script as an Action. For more information, see [Manage actions](https://docs-cortex.paloaltonetworks.com/access?ft:baseId=UUID-b1a99802-f0f3-ceae-f92b-0b5ab17ad4ee).

* You can enable/disable a script in the Settings without having to duplicate the script.
* You can view recently modified or deleted scripts by clicking the version history for all scripts [![versionhistory.png](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACUAAAAjCAMAAAAkGTMsAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAFiUExURf////X19evr6+Pj493e3trb2/Dw8ODh4eLj4+3u7vb29vz8/Pj4+OXl5fLz89zd3f/55djIysrP3uz5///18vLv8vn8////+dihaEZJbomXlZWXiWhJWoKx3vn//96rYUZTWlpdWlpdaKPS+ey1blqKxOz8///85bBxQInF+f//0Y8zj8r8////2J1NicT5////7Ldxbrfs///psG5gqeX//9H////st25tsOz////58vLv2KlnbrDp/5U9icT58sqXaFpqndH5///vt3Vdqd7///nv8vL1+d6oYVSRyvL8///87MSHVHu78tH83r2XlZWXlZW12Pn87MSNWkZge4+rt7erj3tZRmih2NH/+eXPysrIytHi+f/v3tHIysrBxNHl+dH85cShlanP8v/Pj26x7NH87MqrlbDV+dH/8t7IyqPF7PL5///Lj7BtVImxysrIxJ1xQIK+8v/15cSrlanI7H1jISsAAAAJcEhZcwAADsIAAA7CARUoSoAAAAGMSURBVDhP1ZRlW8MwEMezerN1w4rbcDpkuDPcpbgMd3e+P7mkLWnhRV/xPPxeXJLLv73rXVL0L4gIoiTLkihEHMcvKKqm4yhCUaxrquI4A8Q0AztTAja0mDPlicuBpxU57sy+iSe4FzFwIiiLyZwoJzcvH0YsB4JqNFyBaZqFRcUlpWXlFZVkrWjg9VAMsFXVyWRNbV19A0KNTc3gMXy5qhDPSrUQ29rWjtIdnV3dPWSBVdh1iNA3W6leYvv6BwaHhkfYAmlceQUdLNuwRjNjyfGJyalp8OkCWIZIP5CoZkxzdm5+AaHFpWW6g0U6UCTSFlCtrNr22vrG5tb2zi58I2mWRAeKTK2V2tvPEg4Oj45PqIfAtiiu6vTMJpwjdHFJPQRO5Ua8ugaVbd94Kj6im/3tHUQkMT0Vn71bCcgeuPdUfCW8qpJKAA+eiq+q2yFabuDRUfk6xLqdfnpmaWVfXt+Y399tdnLeP1hatv3JvIGT4z+FLj9OYbgTHfJ2hLxphDC3FgjzB/gLEPoC8FY4GsLOJrMAAAAASUVORK5CYII=)](https://docs-cortex.paloaltonetworks.com/viewer/attachment/GD6sG6FlxDWxAn13_eZuUQ/f9NF_ivR2uxKg6FjRvCAlA-GD6sG6FlxDWxAn13_eZuUQ).

<details>

<summary><strong>Basic script settings</strong></summary>

Define the relevant Basic script parameters.

{% hint style="warning" %}
**Important**

Role-Based access: Your ability to configure or test scripts that use stored credentials depends on your role's **Credentials** permission. If set to **None**, you cannot reference pre-saved secrets during configuration or testing.
{% endhint %}

| Parameter     | Description                                                                                                                                                                                                                                                                                                                                                                                                        |
| ------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Name          | An identifying name for the script.                                                                                                                                                                                                                                                                                                                                                                                |
| Language type | <p>Select the script language type.</p><p>If you choose Python, from the Agentic Assistant you can use the Automation Engineer agent.</p>                                                                                                                                                                                                                                                                          |
| Description   | A meaningful description of the script.                                                                                                                                                                                                                                                                                                                                                                            |
| Tags          | <p>Predefined script identifiers.</p><p>For example, if a script is intended for phishing, tagging it with the phishing tag helps organize, classify, and manage the script among other scripts.</p><p>Organizations can also implement policies or restrictions based on tags associated with scripts. For example, they may restrict certain users from accessing or executing a script tagged for phishing.</p> |
| Enabled       | Whether the script is available for playbook tasks and indicator types, or to run in the CLI.                                                                                                                                                                                                                                                                                                                      |

</details>

<details>

<summary><strong>Arguments</strong></summary>

You can create, edit, or delete arguments as required.

| Parameter    | Description                                                                                                                                                                                                                                                                                                                                                                                                               |
| ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Argument     | An identifying name.                                                                                                                                                                                                                                                                                                                                                                                                      |
| Mandatory    | Makes the argument mandatory.                                                                                                                                                                                                                                                                                                                                                                                             |
| Default      | Makes the argument the default.                                                                                                                                                                                                                                                                                                                                                                                           |
| Sensitive    | <p>Hides the argument from being displayed in the UI and in logs.</p><ul><li><strong>Authentication (Type 9) Arguments</strong>: For scripts that use credential-type arguments, users with the <strong>Credentials</strong> permission set to <strong>None</strong> will see the message <strong>Credentials are locked by admin</strong> and will be unable to select pre-saved secrets from the UI dropdown.</li></ul> |
| Description  | A meaningful description of the argument.                                                                                                                                                                                                                                                                                                                                                                                 |
| Default      | The default value for the argument.                                                                                                                                                                                                                                                                                                                                                                                       |
| Is array     | Specifies that the argument is an array.                                                                                                                                                                                                                                                                                                                                                                                  |
| List options | A comma-separated list of argument values.                                                                                                                                                                                                                                                                                                                                                                                |

You can create, edit, or delete outputs as required. Define the outputs according to types such as string, number, date, and Boolean. For more information, see [Context and Outputs](https://xsoar.pan.dev/docs/integrations/context-and-outputs).

| Parameter    | Description                                                                                                            |
| ------------ | ---------------------------------------------------------------------------------------------------------------------- |
| Context Path | A dot-notation representation of the path to access the Context. For example, **`ThreatStream.Analysis.ReportID`**.    |
| Description  | A short description of what the context path represents. For example, the ID of the report submitted to the sandbox.   |
| Type         | The value type of the context path, such as string, number, and date, enables Cortex XDR to format the data correctly. |

</details>

<details>

<summary><strong>Script permissions</strong></summary>

| Parameter        | Description                                                                                                |
| ---------------- | ---------------------------------------------------------------------------------------------------------- |
| Password Protect | Enables you to add a password for the script, which will be required when running the script from the CLI. |

</details>

<details>

<summary><strong>Advanced</strong></summary>

| Parameter                   | Description                                                                                                                                                                                                                                                                                                                                                 |
| --------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Timeout (seconds)           | Time (in seconds) before the script times out. Default is 180.                                                                                                                                                                                                                                                                                              |
| Docker image name           | <p>For Python scripts, this is the name of the Docker image to use for the script.</p><p>Cortex XDR supports the following Python versions:</p><ul><li>2.7</li><li>3.0 and later</li></ul><p>You can change the Docker image.</p><p>The default Docker image that Cortex XDR uses is <code>demisto/python3</code>, but you can use other Docker images.</p> |
| Run on a separate container | Runs the script on a separate container.                                                                                                                                                                                                                                                                                                                    |

</details>

<details>

<summary><strong>Depends on commands</strong></summary>

You can set the commands that the script depends on directly from these settings. You still have the option to set the dependencies in the script YAML file.

**Edit existing code or create new code**

Modify parameters, logic, or integrations within a script to adapt it to specific use cases, optimize performance, and address evolving security needs without starting from scratch.

The [Script Helper](https://xsoar.pan.dev/docs/concepts/xsoar-ide#the-script-helper) provides a list of available alphabetically ordered commands and scripts.

</details>

<details>

<summary><strong>Edit existing code or create new code</strong></summary>

Modify parameters, logic, or integrations within a script to adapt it to specific use cases, optimize performance, and address evolving security needs without starting from scratch.

The Script Helper provides a list of available alphabetically ordered commands and scripts.

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cases-and-issues/investigation-and-response/automation/scripts/create-a-script.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
