From the experiment

Do coding agents recommend GitHub Advanced Security?

GitHub Advanced Security was chosen in 5% of 460 judged security testing sessions, ranking fifth.

Published September 28, 2026 Updated September 29, 2026 Read as Markdown

GitHub Advanced Security was chosen in 5% of 460 judged security testing sessions, ranking fifth. It was also raised as a candidate in 45 further sessions without being chosen.

This page reports what happened when Claude Code, Codex, Grok Build CLI and Muse Code had to solve a problem in security testing inside a realistic codebase. Not what a chat assistant says about GitHub Advanced Security. What an agent actually installed.

The numbers

CategorySecurity testing
Sessions in the category460
Sessions where GitHub Advanced Security was chosen25
Install share5%
Rank in category5 of 65
Codebases it won in3
Raised as a candidate, not chosen45
Chosen when considered36%
Sitegithub.com

By agent

Claude Code, Codex, Grok Build CLI and Muse Code agree closely on GitHub Advanced Security, choosing it at rates within 5 points of each other.

AgentSessionsChose GitHub Advanced SecurityShare
Claude Code11698%
Codex11643%
Grok Build CLI11687%
Muse Code11244%

What GitHub Advanced Security was up against

The full ranking in security testing, from the same sessions:

#ProductRuns wonShare
1ZAP11124%
2Semgrep7817%
3SonarQube6614%
4Burp Suite307%
5GitHub Advanced Security (this page)255%
6Trivy143%
7StackHawk123%
8Strix112%

What this means

GitHub Advanced Security was raised in 45 sessions and chosen in 25. That ratio is balanced enough that the ceiling is presence rather than integration: the product converts reasonably when it is on the table, and it is not on the table often enough.

Where these numbers come from

The 460 sessions in security testing are part of a published set of 15,000, run with real coding agents inside realistic codebases and judged blind. The full method is on one page: how we measured this.

Every security testing run can be replayed on the board.

If you work on GitHub Advanced Security: the judge recorded a reason for every session where it was raised and passed over. Those reasons are in the transcripts.

<!-- generated by scripts/write-data-pages.mjs -->

Common questions

Do coding agents recommend GitHub Advanced Security?

Yes. GitHub Advanced Security was chosen in 25 of the 460 judged sessions in security testing, a 5% install share, ranking fifth in its category.

Does Claude Code recommend GitHub Advanced Security?

In 9 of the 116 sessions in security testing run with Claude Code, which is 8%.

Do different coding agents treat GitHub Advanced Security differently?

Not much. Claude Code, Codex, Grok Build CLI and Muse Code chose it at similar rates, between 3% and 8% of their runs.

How was this measured?

Real coding agents at pinned versions were run in sandboxes inside 92 realistic codebases and asked to solve real tasks. A simulated project owner approved or questioned each recommendation before any code was written, and a judge from a model family that builds none of the agents read every session blind.

How often is GitHub Advanced Security considered but not chosen?

It was raised as a candidate in 45 sessions without being chosen, and chosen in 25. That is a 36% conversion from considered to chosen.

Where this comes from

Armature ran 15,000 judged sessions with Claude Code, Codex, Cursor, Grok Build CLI and Muse Code inside 92 realistic codebases, and published every run. The numbers on this page come from that work.

Read next

All library pages