Retour aux Actualités
SécuritéBriefing AI Understanding

StackHawk lance Wingman pour sécuriser les sessions de codage assistées par IA

StackHawk a dévoilé Wingman, une plate-forme de sécurité qui détecte, corrige et vérifie automatiquement les vulnérabilités du code tandis que les développeurs utilisent des assistants de codage IA tels que GitHub Copilot et Claude Code.

4 min readRead the linked source
Source-provided image accompanying StackHawk launches Wingman to secure AI‑assisted coding sessions
Référence sourceSource enregistrée
Éditeur
securitybrief.asia
Lien source
securitybrief.asiahttps://securitybrief.asia/story/stackhawk-launches-wingman-to-fix-ai-coding-flaws
Type de source
Source liée : le statut de source principale n'a pas été établi.
ContexteComprenez cela en 60 secondes

Commencez ici

Termes clés

API (interface de programmation d'applications)
Une manière structurée permettant à un système logiciel d'envoyer des requêtes et de recevoir des réponses d'un autre système.
Intégration
Représentation vectorielle numérique qui capture la signification sémantique du texte, des images ou d'autres données.
Agent IA
Un système logiciel capable d'observer, de raisonner et de prendre des mesures pour atteindre un objectif, souvent en utilisant des outils et de la mémoire.
Testez-vousQuiz sur les agents IA

Que s'est-il passé

StackHawk announced the launch of Wingman, an application‑security platform built to operate inside AI‑assisted coding sessions. The tool integrates with popular AI coding assistants—including Claude Code, Cursor, GitHub Copilot, Codex, and Antigravity—and automatically scans code for known vulnerability classes (remote code execution, SQL injection, cross‑site scripting) as it is written. When a flaw is found, Wingman applies a fix through the same , rescans the code to confirm remediation, and records the result against the specific commit. Early‑access customers reportedly saw more than 7,500 vulnerabilities fixed, with the company claiming a 98 % fix‑without‑regression rate. Wingman is priced at US $10 per user per month, covering unlimited applications and up to 50 scans per user each month.

StackHawk, a Denver‑based provider of application and API security testing tools, introduced Wingman as a new product aimed at developers who use AI coding assistants. The platform plugs into development environments that host AI agents—Claude Code, Cursor, GitHub Copilot, Codex, and Antigravity—allowing it to monitor code generation in real time.

When Wingman detects a vulnerability, it leverages the same that produced the code to generate a fix, then automatically rescans the updated code to confirm the issue is resolved. Each scan is tied to a specific Git commit, creating an auditable trail that security teams can reference without manually reviewing every change.

According to StackHawk, early‑access customers have already benefited from more than 7,500 automated fixes across five AI coding agents, with a reported 98 % success rate for fixes that did not regress. The company priced the service at US $10 per user per month, offering unlimited applications and a cap of 50 scans per user each month.

Détails de la source: securitybrief.asia ↗

Pourquoi c'est important

The rapid adoption of AI coding assistants has accelerated software delivery, but security teams often lag behind, leaving newly generated code exposed to known exploit classes. By remediation directly into the coding workflow, Wingman aims to shrink the window between vulnerability creation and patching—from hours or days to seconds—potentially reducing the risk of zero‑day attacks that exploit code before it is publicly disclosed. If the claimed 98 % remediation success holds in broader deployments, the tool could alleviate the chronic backlog of security tickets that slows many enterprises, enabling faster, safer releases without adding manual review steps. However, the efficacy figures are self‑reported and have not been independently verified, so the true impact on real‑world breach reduction remains uncertain.

AI‑assisted coding tools have dramatically shortened development cycles, but they also introduce a risk that vulnerable code can be generated and merged before security teams have a chance to review it. Traditional static analysis tools often flag issues after code is committed, creating a backlog of tickets that can delay releases.

Wingman's approach of fixing vulnerabilities in‑line, before a pull request is opened, directly addresses this timing mismatch. By reducing the exposure window—potentially from days to minutes—the platform could mitigate the likelihood of attackers exploiting newly introduced flaws before they are publicly disclosed.

If the platform's self‑reported metrics hold true across a broader user base, organizations could see a measurable decline in the number of high‑severity vulnerabilities that reach production, translating into lower breach risk and reduced remediation costs. However, the lack of third‑party validation means the actual effectiveness remains to be proven in independent studies.

Interactive Mechanism

Mécanisme interactif : comment cela fonctionne réellement

Explorez de manière interactive la technologie sous-jacente à ce développement.

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
Vérification de concept interactive+10 Points
AI Agents Quiz

What most distinguishes an AI agent from a basic chatbot?

Que regarder ensuite

Key indicators to monitor include adoption rates among enterprises that rely heavily on AI‑driven development pipelines, independent security audits of Wingman's detection and remediation accuracy, and any reported incidents where the tool either prevented or missed a critical vulnerability. Competitors may also respond with similar “in‑the‑loop” security solutions, shaping a nascent market for AI‑integrated application security. Finally, pricing and usage limits (50 scans per user per month) could affect scalability for large development teams, prompting potential revisions to the licensing model.

Adoption trends: Tracking how quickly enterprises with heavy AI‑driven development pipelines adopt Wingman will indicate market demand for integrated security solutions.

Independent validation: Security researchers and third‑party auditors may test Wingman's detection and remediation rates, providing data that could confirm or challenge the company's claims.

Competitive response: Other security vendors may launch comparable tools that embed remediation within AI coding assistants, potentially leading to a new segment of AI‑integrated security products.

Pricing and scalability: The current limit of 50 scans per user per month may become a constraint for large teams, prompting StackHawk to adjust pricing or scan caps. Monitoring any changes to the licensing model will be important for organizations evaluating cost‑effectiveness.

Guides et quiz associés

Agents IAÉthique de l'IAModèles d'IA expliquésTestez ce que vous savez : essayez un quiz gratuit sur l'IARecherchez un terme d'IA dans notre glossaireSuivez le tracker de la réglementation de l'IA
Vous avez trouvé cela utile ?