Skip to content

Product1 publisher3 min readPublished

StackHawk's Wingman asks the coding agent to patch the vulnerability it just wrote

The tool boots the running app once an agent finishes a feature, sends findings to Claude Code or Copilot, and rescans to confirm the fix. It costs $10 a seat a month and meters that loop at 50 scans.

The Product Desk · Product desk

What happened

  • StackHawk launched Wingman, a tool that installs into Claude Code, Cursor, GitHub Copilot, Codex and Antigravity to find and fix vulnerabilities during AI-assisted coding sessions.
  • Every test is tied to a specific commit, which StackHawk offers security teams as an attestation record of what code was securely shipped.
  • StackHawk says the tool has already fixed more than 7,000 vulnerabilities for early access customers, with 98 percent of those fixes remaining resolved and no regressions.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • exposure The agent that introduced the flaw also writes the patch, so a team that wants an opinion from outside that loop has to supply it separately.
  • decision At $250 a month for 25 seats, the purchase clears an engineering manager's discretion, while the security team inherits the resulting record without having chosen the tool.
  • precedent If Ashley's description of the control point moving into the coding session holds, the pipeline gate becomes the place results are reported instead of the place they are enforced.

When an agent reports a feature is done, Wingman auto-configures and boots the running application, then runs its security tests with no manual step from the developer [4]. The findings go back to the coding agent that wrote the code, and that agent applies the fix [5].

So the party writing the patch is the agent that produced the flaw, and the check on the patch is a rescan by the tool that raised it [6]. StackHawk says more than 7,000 vulnerabilities have been fixed this way for early access customers, with 98 percent of those fixes staying resolved and no regressions [9]. Two percent of 7,000 is about 140 fixes that did not hold [10]. The devops.com report does not say how many customers produced that total or how long the early access period ran [17].

The price is $10 per user per month, with unlimited applications and 50 scans per user per month [8]. At the cap a scan costs 20 cents [11]. The loop as described spends two of those scans on each feature, one to test and one to confirm, so 50 covers about 25 test-and-confirm cycles per developer per month [12]. A fix that fails its rescan costs a third scan. For a developer merging a couple of agent-written features a day, the cap binds before the price does.

This is for a team whose developers already work inside Claude Code, Cursor, GitHub Copilot, Codex or Antigravity [2], and whose testing sits on StackHawk's platform, which Wingman reaches through a set of AI skills, hooks and rules [3]. Twenty-five seats is $250 a month [13]. In my view an engineering manager signs that off without a procurement cycle.

StackHawk CEO Joni Klippert said Wingman is designed to prevent vulnerabilities from ever finding their way into a build in the first place, and said that removes tickets DevSecOps teams would otherwise have to work through at a time when code generation has accelerated [14]. Mitch Ashley, vice president and practice lead at the Futurum Group, said embedding the fix and verification inside the coding session moves the security control point out of the pipeline gate and into the loop that writes the code [15]. He said that is the right response to AI-generated code because verification work is accumulating faster than teams can hire reviewers [16].

Two axes decide whether this fits a given team. The first is who writes the fix, the agent that wrote the code or something outside it; Wingman routes the finding back to the agent [5]. The second is what confirms the fix, the scanner that found it or an independent check; here the confirming rescan comes from the same tool [6]. A team that lets the agent both write and confirm the fix gets volume, and it gets a per-commit attestation record of what shipped securely [7]. That record will read resolved on the strength of the rescan, and StackHawk's own figure for how often that holds is 98 percent [9].

What to watch

  • Whether StackHawk publishes the customer count and time period behind the 7,000 fixes, and how many findings the coding agent failed to fix at all.
  • Whether the 50-scan allowance moves once customers run several agent-written features through the loop each day.
  • Whether auditors accept the per-commit attestation record as evidence of what shipped securely.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories