Kembali ke Berita
KeselamatanAI Understanding taklimat

StackHawk melancarkan Wingman untuk menjamin sesi pengekodan berbantukan AI

StackHawk melancarkan Wingman, platform keselamatan yang secara automatik mengesan, membetulkan dan mengesahkan kelemahan kod sementara pembangun menggunakan pembantu pengekodan AI seperti GitHub Copilot dan Claude Code.

4 min readRead the linked source
Source-provided image accompanying StackHawk launches Wingman to secure AI‑assisted coding sessions
Rujukan sumberSumber direkodkan
Penerbit
securitybrief.asia
Pautan sumber
securitybrief.asiahttps://securitybrief.asia/story/stackhawk-launches-wingman-to-fix-ai-coding-flaws
Jenis sumber
Sumber terpaut — status sumber primer belum ditetapkan.
KonteksFahami perkara ini dalam masa 60 saat

Mulakan di sini

Istilah utama

API (Antara Muka Pengaturcaraan Aplikasi)
Cara berstruktur untuk satu sistem perisian menghantar permintaan dan menerima respons daripada sistem lain.
Membenamkan
Perwakilan vektor berangka yang menangkap makna semantik teks, imej atau data lain.
Ejen AI
Sistem perisian yang boleh memerhati, menaakul dan mengambil tindakan untuk mencapai matlamat, selalunya menggunakan alatan dan ingatan.
Uji diri andaKuiz Agen AI

Apa yang berlaku

StackHawk announced the launch of Wingman, an application‑security platform built to operate inside AI‑assisted coding sessions. The tool integrates with popular AI coding assistants—including Claude Code, Cursor, GitHub Copilot, Codex, and Antigravity—and automatically scans code for known vulnerability classes (remote code execution, SQL injection, cross‑site scripting) as it is written. When a flaw is found, Wingman applies a fix through the same , rescans the code to confirm remediation, and records the result against the specific commit. Early‑access customers reportedly saw more than 7,500 vulnerabilities fixed, with the company claiming a 98 % fix‑without‑regression rate. Wingman is priced at US $10 per user per month, covering unlimited applications and up to 50 scans per user each month.

StackHawk, a Denver‑based provider of application and API security testing tools, introduced Wingman as a new product aimed at developers who use AI coding assistants. The platform plugs into development environments that host AI agents—Claude Code, Cursor, GitHub Copilot, Codex, and Antigravity—allowing it to monitor code generation in real time.

When Wingman detects a vulnerability, it leverages the same that produced the code to generate a fix, then automatically rescans the updated code to confirm the issue is resolved. Each scan is tied to a specific Git commit, creating an auditable trail that security teams can reference without manually reviewing every change.

According to StackHawk, early‑access customers have already benefited from more than 7,500 automated fixes across five AI coding agents, with a reported 98 % success rate for fixes that did not regress. The company priced the service at US $10 per user per month, offering unlimited applications and a cap of 50 scans per user each month.

Butiran sumber: securitybrief.asia ↗

Mengapa ia penting

The rapid adoption of AI coding assistants has accelerated software delivery, but security teams often lag behind, leaving newly generated code exposed to known exploit classes. By remediation directly into the coding workflow, Wingman aims to shrink the window between vulnerability creation and patching—from hours or days to seconds—potentially reducing the risk of zero‑day attacks that exploit code before it is publicly disclosed. If the claimed 98 % remediation success holds in broader deployments, the tool could alleviate the chronic backlog of security tickets that slows many enterprises, enabling faster, safer releases without adding manual review steps. However, the efficacy figures are self‑reported and have not been independently verified, so the true impact on real‑world breach reduction remains uncertain.

AI‑assisted coding tools have dramatically shortened development cycles, but they also introduce a risk that vulnerable code can be generated and merged before security teams have a chance to review it. Traditional static analysis tools often flag issues after code is committed, creating a backlog of tickets that can delay releases.

Wingman's approach of fixing vulnerabilities in‑line, before a pull request is opened, directly addresses this timing mismatch. By reducing the exposure window—potentially from days to minutes—the platform could mitigate the likelihood of attackers exploiting newly introduced flaws before they are publicly disclosed.

If the platform's self‑reported metrics hold true across a broader user base, organizations could see a measurable decline in the number of high‑severity vulnerabilities that reach production, translating into lower breach risk and reduced remediation costs. However, the lack of third‑party validation means the actual effectiveness remains to be proven in independent studies.

Interactive Mechanism

Mekanisme Interaktif: Bagaimana Ia Berfungsi Sebenarnya

Terokai teknologi asas di sebalik pembangunan ini secara interaktif.

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
Semakan Konsep Interaktif+10 Points
AI Agents Quiz

What most distinguishes an AI agent from a basic chatbot?

Apa yang perlu ditonton seterusnya

Key indicators to monitor include adoption rates among enterprises that rely heavily on AI‑driven development pipelines, independent security audits of Wingman's detection and remediation accuracy, and any reported incidents where the tool either prevented or missed a critical vulnerability. Competitors may also respond with similar “in‑the‑loop” security solutions, shaping a nascent market for AI‑integrated application security. Finally, pricing and usage limits (50 scans per user per month) could affect scalability for large development teams, prompting potential revisions to the licensing model.

Adoption trends: Tracking how quickly enterprises with heavy AI‑driven development pipelines adopt Wingman will indicate market demand for integrated security solutions.

Independent validation: Security researchers and third‑party auditors may test Wingman's detection and remediation rates, providing data that could confirm or challenge the company's claims.

Competitive response: Other security vendors may launch comparable tools that embed remediation within AI coding assistants, potentially leading to a new segment of AI‑integrated security products.

Pricing and scalability: The current limit of 50 scans per user per month may become a constraint for large teams, prompting StackHawk to adjust pricing or scan caps. Monitoring any changes to the licensing model will be important for organizations evaluating cost‑effectiveness.

Panduan & kuiz berkaitan

Ejen AIEtika AIModel AI DiterangkanUji apa yang anda tahu — cuba kuiz AI percumaCari istilah AI dalam glosari kamiIkuti penjejak peraturan AI
Adakah ini berguna?