Skip to content
StackHawk Launches Wingman to Fix Vulnerabilities Inside AI Coding Workflows

StackHawk Launches Wingman to Fix Vulnerabilities Inside AI Coding Workflows

Citybiz.Co • September 15, 2026

AI coding agents are helping engineering teams produce software faster, but that acceleration can create a security bottleneck when vulnerabilities still move through traditional scanning, ticketing and remediation processes. StackHawk is targeting that gap with Wingman, a new application security product designed to find, fix and verify vulnerabilities within the same AI coding session that produced the code.

The Denver -based application security company has publicly launched Wingman with support for agentic development environments including Claude Code, Cursor, GitHub Copilot, Codex and Antigravity. Rather than generating a vulnerability report for engineers to address later, Wingman sends findings back to the coding agent for remediation and then retests the application to verify that the fix worked.

The product is designed to move application security earlier in the development process, before a pull request is opened and potentially before vulnerable code reaches a security team’s backlog.

That timing has become more important as AI-assisted development increases software delivery speed. StackHawk CEO Joni Klippert said the time between the discovery of a vulnerability and exploitation has compressed sharply, with attackers in some cases exploiting flaws before they are publicly disclosed.

“Engineering teams are shipping faster than ever because of AI coding agents, but security hasn’t kept pace,” Klippert said. “That mismatch is exactly what’s putting most organizations at risk today.”

Wingman builds on StackHawk ’s dynamic application security testing capabilities but places testing directly inside the AI agent workflow. When an agent marks a feature as complete, Wingman can automatically configure and start the application, test the running software for exploitable vulnerabilities and return findings to the same agent.

Because that coding agent already has context the application’s architecture, dependencies, coding patterns and development standards, it can use that information to generate a remediation consistent with the existing codebase. Wingman then rescans the application to determine whether the vulnerability has been resolved.

The process creates a find-fix-verify loop intended to reduce the amount of security work that becomes a separate engineering task after development. Testing occurs before the pull request opens, and Wingman can report the security status of the commit back to the continuous integration pipeline.

StackHawk also creates an attestation record tying each test to a specific commit, providing security teams with evidence of what was tested and verified during development.

Early-access customers have used Wingman to automatically fix more than 7,500 vulnerabilities across more than five AI coding agents, according to StackHawk. The company said 98% of those vulnerabilities have remained resolved without regressions.

The remediation work has included exploit-confirmed, high-severity vulnerabilities such as remote code execution, SQL injection and cross-site scripting.

CertiPath is among the organizations using the technology as part of a broader effort to introduce AI throughout its software development lifecycle.

“With StackHawk’s Wingman, our engineers can find and fix vulnerabilities in the same agentic session where the code is written, with human review ‘over the loop’ and a verified record of what shipped clean,” CertiPath CISO George Baker said.

For security organizations, the operational proposition is less finding additional vulnerabilities than reducing the time between detection and remediation. Conventional application security workflows can leave findings waiting for engineering attention while developers move to other projects, creating backlogs that become increasingly difficult to manage as development velocity increases.

Wingman is designed to automate more of that remediation while retaining human oversight. Klippert said vulnerability discovery itself is no longer the central constraint; resolving and verifying findings quickly enough to match modern software delivery has become the more difficult problem.

The product includes unlimited applications and 50 scans per user each month. Wingman is priced at $10 per user per month, with a 14-day free trial. Organizations requiring broader API discovery and attack-surface visibility can use it alongside StackHawk Scale, the company’s enterprise offering.

Founded by Klippert and Chief Security Officer Scott Gerlach , StackHawk develops dynamic application security testing and API security technology used by more than 200 enterprise organizations worldwide. Wingman extends that testing infrastructure into AI-assisted development workflows as engineering and security teams adjust their processes for increasingly agent-driven software development.

COMPANIES THAT TRUST city biz