Skip to content

Product1 publisher3 min readPublished

StackHawk hands the vulnerability back to the agent that wrote it

Wingman probes the running app the moment a coding agent says a feature is done, then sends the findings back to that same agent to patch. StackHawk reports more than 7,000 fixes in early access, 98% of them holding.

The Product Desk · Product desk

Illustration accompanying StackHawk hands the vulnerability back to the agent that wrote it

What happened

  • StackHawk launched Wingman, which installs into agentic coding workflows including Claude Code, Cursor, GitHub Copilot, Codex and Antigravity.
  • Findings go back to the agent that wrote the code, which patches the flaw, and a second scan checks the repair before a pull request opens.
  • A seat costs $10 a month with unlimited applications and 50 scans per user, and there is a 14-day free trial.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision At $200 a month for twenty developers, the buying decision sits with an engineering lead, and the security group meets the tool once it is already gating commits in CI.
  • constraint The 50-scan allowance sets the ceiling on how often the fix loop can run, so heavy agent users hit the cap before the month ends and some merges go unscanned.
  • exposure The agent that introduced the flaw is the one writing the patch. That leaves the runtime rescan as the only independent check standing between a bad fix and a merged pull request.
  • precedent If fixing moves inside the coding session, what a downstream scanner is for narrows to the things the agent cannot see, and StackHawk already sells that remainder as an enterprise tier.

A developer tells Cursor to add an upload endpoint, the agent reports the feature done, and the pull request is one keystroke away. StackHawk has put its trigger on that report [3]. Wingman configures itself, boots the running application and probes it the way an attacker would, then sends what it finds back to the same agent to patch [3][4].

The thing being sold is context. StackHawk's argument is that the agent that built the application already holds its architecture, its dependencies and the conventions the rest of the team codes to, and that this is what separates Wingman from a scanner bolted on downstream [5]. Patches come back in the shape of the surrounding code, the company said [6].

The agent that wrote the flaw also writes the fix, and the independent step is the second scan against the running app before the pull request opens [4]. Because the scanner boots the application and probes it from outside, what it can hand the agent is what a request against a live app provokes [3].

StackHawk said Wingman fixed more than 7,000 vulnerabilities for early-access customers before launch, and that 98% of those repairs have held [8]. At that rate, roughly 140 of those repairs did not hold [1]. The company did not say how many customers produced the total, or what a repair is measured against when it is called held.

A seat costs $10 a month and includes unlimited applications with 50 scans [10]. At full use that is 20 cents a scan [3]. The loop as described spends two scans on one finding, the first when the agent says done and the second to verify the repair, so a seat funds about 25 complete cycles a month [2]. Twenty developers come to $200 a month [4]. In my view an engineering lead signs that without involving security, and security meets the tool later, in the pipeline: Wingman tells CI whether a commit is clean, and because every test carries the commit it ran against, teams end up with a record of what shipped [7].

Chief Executive Joni Klippert put the gap in staffing terms. "Finding was never the hard part," she said. What security teams have never had the staff or the hours for, she said, is fixing and verifying a vulnerability fast enough to match how engineering teams ship today, at machine speed, inside the workflow, as the code is written [9].

Who this is for is the team that has already lost the race between agent output and security review. Klippert said AI coding agents have pushed engineering teams out ahead of what security can absorb [14], and in March she told theCUBE that developers "want to write quality code, but they don't want to become security engineers" [13].

Teams that want broader API discovery and attack-surface mapping are pointed at StackHawk Scale, the enterprise tier [11]. StackHawk sells to more than 200 enterprises and raised $20.7 million in May 2022 in a round led by Sapphire Ventures and Costanoa Ventures [12].

It comes back to the scan cap. Below 25 agent-completed features merged per developer in a month, a seat covers all of them at two scans each; above 25, the choice is more seats or merges that ship without a scan behind them [2].

What to watch

  • Whether StackHawk defines what a repair that 'held' means, and over what window, since the 98% figure rests on it.
  • Whether the 50-scan seat allowance moves once teams running agents all day start hitting it mid-month.
  • Whether the agent vendors Wingman plugs into (Claude Code, Cursor, GitHub Copilot) build the same fix-and-verify loop in-house.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories