# Do coding agents recommend GitHub Advanced Security?

> GitHub Advanced Security was chosen in 5% of 460 judged security testing sessions, ranking fifth.

Source: https://armature.tech/library/do-coding-agents-recommend-github-advanced-security
Published: 2026-09-28 · Updated: 2026-09-29
Publisher: Armature, Inc. (https://armature.tech)

---

> GitHub Advanced Security was chosen in 5% of 460 judged security testing sessions, ranking fifth. It was also raised as a candidate in 45 further sessions without being chosen.

This page reports what happened when Claude Code, Codex, Grok Build CLI and Muse Code had to solve a problem in security testing inside a realistic codebase. Not what a chat assistant says about GitHub Advanced Security. What an agent actually installed.

## The numbers

| | |
| --- | --- |
| Category | Security testing |
| Sessions in the category | 460 |
| Sessions where GitHub Advanced Security was chosen | 25 |
| Install share | 5% |
| Rank in category | 5 of 65 |
| Codebases it won in | 3 |
| Raised as a candidate, not chosen | 45 |
| Chosen when considered | 36% |
| Site | github.com |

## By agent

Claude Code, Codex, Grok Build CLI and Muse Code agree closely on GitHub Advanced Security, choosing it at rates within 5 points of each other.

| Agent | Sessions | Chose GitHub Advanced Security | Share |
| --- | --- | --- | --- |
| Claude Code | 116 | 9 | 8% |
| Codex | 116 | 4 | 3% |
| Grok Build CLI | 116 | 8 | 7% |
| Muse Code | 112 | 4 | 4% |

## What GitHub Advanced Security was up against

The full ranking in security testing, from the same sessions:

| # | Product | Runs won | Share |
| --- | --- | --- | --- |
| 1 | ZAP | 111 | 24% |
| 2 | Semgrep | 78 | 17% |
| 3 | SonarQube | 66 | 14% |
| 4 | Burp Suite | 30 | 7% |
| 5 | GitHub Advanced Security **(this page)** | 25 | 5% |
| 6 | Trivy | 14 | 3% |
| 7 | StackHawk | 12 | 3% |
| 8 | Strix | 11 | 2% |

## What this means

GitHub Advanced Security was raised in 45 sessions and chosen in 25. That ratio is balanced enough that the ceiling is presence rather than integration: the product converts reasonably when it is on the table, and it is not on the table often enough.

## Where these numbers come from

The 460 sessions in security testing are part of a published set of 15,000, run with real coding agents inside realistic codebases and judged blind. The full method is on one page: [how we measured this](/library/how-we-measured-this).

Every security testing run can be replayed on [the board](/leaderboards/security-testing).

If you work on GitHub Advanced Security: the judge recorded a reason for every session where it was raised and passed over. Those reasons are in the transcripts.

<!-- generated by scripts/write-data-pages.mjs -->

## Common questions

### Do coding agents recommend GitHub Advanced Security?

Yes. GitHub Advanced Security was chosen in 25 of the 460 judged sessions in security testing, a 5% install share, ranking fifth in its category.

### Does Claude Code recommend GitHub Advanced Security?

In 9 of the 116 sessions in security testing run with Claude Code, which is 8%.

### Do different coding agents treat GitHub Advanced Security differently?

Not much. Claude Code, Codex, Grok Build CLI and Muse Code chose it at similar rates, between 3% and 8% of their runs.

### How was this measured?

Real coding agents at pinned versions were run in sandboxes inside 92 realistic codebases and asked to solve real tasks. A simulated project owner approved or questioned each recommendation before any code was written, and a judge from a model family that builds none of the agents read every session blind.

### How often is GitHub Advanced Security considered but not chosen?

It was raised as a candidate in 45 sessions without being chosen, and chosen in 25. That is a 36% conversion from considered to chosen.

## Read next

- [How to get picked for security testing by coding agents](https://armature.tech/library/security-testing-coding-agents-playbook) (Markdown: https://armature.tech/library/security-testing-coding-agents-playbook.md)
- [Do coding agents recommend ZAP?](https://armature.tech/library/do-coding-agents-recommend-zap) (Markdown: https://armature.tech/library/do-coding-agents-recommend-zap.md)
- [Do coding agents recommend Semgrep?](https://armature.tech/library/do-coding-agents-recommend-semgrep) (Markdown: https://armature.tech/library/do-coding-agents-recommend-semgrep.md)
- [Do Claude Code, Codex and Cursor pick the same tools?](https://armature.tech/library/do-claude-code-and-codex-agree) (Markdown: https://armature.tech/library/do-claude-code-and-codex-agree.md)

---

Armature helps software products get discovered and used by coding agents.
Service: https://armature.tech/discoverability · Results: https://armature.tech/leaderboards/sectors · Contact: contact@armature.tech
