返回新聞
安全性AI Understanding 簡報

StackHawk 推出 Wingman 以確保人工智慧輔助編碼會話的安全

StackHawk 推出了 Wingman,這是一個安全平台,可以在開發人員使用 GitHub Copilot 和 Claude Code 等 AI 編碼助理時自動偵測、修復和驗證程式碼漏洞。

4 min readRead the linked source
Source-provided image accompanying StackHawk launches Wingman to secure AI‑assisted coding sessions
來源參考來源記錄
出版商
securitybrief.asia
來源連結
securitybrief.asiahttps://securitybrief.asia/story/stackhawk-launches-wingman-to-fix-ai-coding-flaws
來源類型
連結來源-主要來源狀態尚未確定。
背景60 秒內了解這一點

從這裡開始

關鍵術語

API(應用程式介面)
一種軟體系統向另一個系統發送請求並接收回應的結構化方式。
嵌入
擷取文字、影像或其他資料語意的數位向量表示。
人工智慧代理
一種可以觀察、推理並採取行動來實現目標的軟體系統,通常使用工具和記憶體。
測試一下自己AI 代理測驗

發生了什麼事

StackHawk announced the launch of Wingman, an application‑security platform built to operate inside AI‑assisted coding sessions. The tool integrates with popular AI coding assistants—including Claude Code, Cursor, GitHub Copilot, Codex, and Antigravity—and automatically scans code for known vulnerability classes (remote code execution, SQL injection, cross‑site scripting) as it is written. When a flaw is found, Wingman applies a fix through the same , rescans the code to confirm remediation, and records the result against the specific commit. Early‑access customers reportedly saw more than 7,500 vulnerabilities fixed, with the company claiming a 98 % fix‑without‑regression rate. Wingman is priced at US $10 per user per month, covering unlimited applications and up to 50 scans per user each month.

StackHawk, a Denver‑based provider of application and API security testing tools, introduced Wingman as a new product aimed at developers who use AI coding assistants. The platform plugs into development environments that host AI agents—Claude Code, Cursor, GitHub Copilot, Codex, and Antigravity—allowing it to monitor code generation in real time.

When Wingman detects a vulnerability, it leverages the same that produced the code to generate a fix, then automatically rescans the updated code to confirm the issue is resolved. Each scan is tied to a specific Git commit, creating an auditable trail that security teams can reference without manually reviewing every change.

According to StackHawk, early‑access customers have already benefited from more than 7,500 automated fixes across five AI coding agents, with a reported 98 % success rate for fixes that did not regress. The company priced the service at US $10 per user per month, offering unlimited applications and a cap of 50 scans per user each month.

來源詳情: securitybrief.asia ↗

為什麼這很重要

The rapid adoption of AI coding assistants has accelerated software delivery, but security teams often lag behind, leaving newly generated code exposed to known exploit classes. By remediation directly into the coding workflow, Wingman aims to shrink the window between vulnerability creation and patching—from hours or days to seconds—potentially reducing the risk of zero‑day attacks that exploit code before it is publicly disclosed. If the claimed 98 % remediation success holds in broader deployments, the tool could alleviate the chronic backlog of security tickets that slows many enterprises, enabling faster, safer releases without adding manual review steps. However, the efficacy figures are self‑reported and have not been independently verified, so the true impact on real‑world breach reduction remains uncertain.

AI‑assisted coding tools have dramatically shortened development cycles, but they also introduce a risk that vulnerable code can be generated and merged before security teams have a chance to review it. Traditional static analysis tools often flag issues after code is committed, creating a backlog of tickets that can delay releases.

Wingman's approach of fixing vulnerabilities in‑line, before a pull request is opened, directly addresses this timing mismatch. By reducing the exposure window—potentially from days to minutes—the platform could mitigate the likelihood of attackers exploiting newly introduced flaws before they are publicly disclosed.

If the platform's self‑reported metrics hold true across a broader user base, organizations could see a measurable decline in the number of high‑severity vulnerabilities that reach production, translating into lower breach risk and reduced remediation costs. However, the lack of third‑party validation means the actual effectiveness remains to be proven in independent studies.

Interactive Mechanism

互動機制:它實際上是如何運作的

以互動方式探索這項發展背後的基礎技術。

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
互動式概念檢查+10 Points
AI Agents Quiz

What most distinguishes an AI agent from a basic chatbot?

接下來看什麼

Key indicators to monitor include adoption rates among enterprises that rely heavily on AI‑driven development pipelines, independent security audits of Wingman's detection and remediation accuracy, and any reported incidents where the tool either prevented or missed a critical vulnerability. Competitors may also respond with similar “in‑the‑loop” security solutions, shaping a nascent market for AI‑integrated application security. Finally, pricing and usage limits (50 scans per user per month) could affect scalability for large development teams, prompting potential revisions to the licensing model.

Adoption trends: Tracking how quickly enterprises with heavy AI‑driven development pipelines adopt Wingman will indicate market demand for integrated security solutions.

Independent validation: Security researchers and third‑party auditors may test Wingman's detection and remediation rates, providing data that could confirm or challenge the company's claims.

Competitive response: Other security vendors may launch comparable tools that embed remediation within AI coding assistants, potentially leading to a new segment of AI‑integrated security products.

Pricing and scalability: The current limit of 50 scans per user per month may become a constraint for large teams, prompting StackHawk to adjust pricing or scan caps. Monitoring any changes to the licensing model will be important for organizations evaluating cost‑effectiveness.

相關指引和測驗

人工智慧代理AI 倫理人工智慧模型解釋測試你所知道的—嘗試免費的人工智慧測驗在我們的詞彙表中尋找人工智慧術語關注AI監管追蹤器
覺得有用嗎?