From the experiment

Do coding agents recommend GitLab Security?

GitLab Security was chosen in 19% of 118 judged security platforms sessions, ranking second. Measured with Claude Code, Codex, Grok Build CLI and Muse Code.

Published September 28, 2026 Updated September 30, 2026 Read as Markdown

GitLab Security was chosen in 19% of 118 judged security platforms sessions, ranking second. It was also raised as a candidate in 37 further sessions without being chosen.

This page reports what happened when Claude Code, Codex, Grok Build CLI and Muse Code had to solve a problem in security platforms inside a realistic codebase. Not what a chat assistant says about GitLab Security. What an agent actually chose.

The numbers

CategorySecurity platforms
Sessions in the category118
Sessions where GitLab Security was chosen22
Install share19%
Rank in category2 of 19
Codebases it won in4
Raised as a candidate, not chosen37
Chosen when considered37%
Sitegitlab.com

By agent

Claude Code, Codex and Grok Build CLI agree closely on GitLab Security, choosing it at rates within 3 points of each other. Muse Code ran fewer than 30 sessions here, too few to compare.

AgentSessionsChose GitLab SecurityShare
Claude Code30620%
Codex30517%
Grok Build CLI30620%
Muse Code28518%

What GitLab Security was up against

The full ranking in security platforms, from the same sessions:

#ProductRuns wonShare
1Checkmarx One3933%
2GitLab Security (this page)2219%
3Snyk1916%
4Aikido Security98%
5HCL AppScan54%
6GitHub Advanced Security + ZAP43%
7GitHub Advanced Security + Microsoft Defender for Cloud33%
8DefectDojo + Gitleaks + Semgrep + Trivy + ZAP33%

What this means

A solid second or third position in a category means the agent is genuinely choosing rather than reaching automatically. That is a winnable position, because the inputs it uses can be changed.

The fastest gains are usually in the sessions that were nearly won: read them, find the step where the agent moved on, and fix that step.

Where these numbers come from

The 118 sessions in security platforms are part of a published set of 15,000, run with real coding agents inside realistic codebases and judged blind. The full method is on one page: how we measured this.

Every security platforms run can be replayed on the board.

If you work on GitLab Security: the judge recorded a reason for every session where it was raised and passed over. Those reasons are in the transcripts.

<!-- generated by scripts/write-data-pages.mjs -->

Common questions

Do coding agents recommend GitLab Security?

Yes. GitLab Security was chosen in 22 of the 118 judged sessions in security platforms, a 19% install share, ranking second in its category.

Does Claude Code recommend GitLab Security?

In 6 of the 30 sessions in security platforms run with Claude Code, which is 20%.

Do different coding agents treat GitLab Security differently?

Not much. Claude Code, Codex and Grok Build CLI chose it at similar rates, between 17% and 20% of their runs.

How was this measured?

Real coding agents at pinned versions were run in sandboxes inside 92 realistic codebases and asked to solve real tasks. A simulated project owner approved or questioned each recommendation before any code was written, and a judge from a model family that builds none of the agents read every session blind.

How often is GitLab Security considered but not chosen?

It was raised as a candidate in 37 sessions without being chosen, and chosen in 22. That is a 37% conversion from considered to chosen.

Where this comes from

Armature ran 15,000 judged sessions with Claude Code, Codex, Cursor, Grok Build CLI and Muse Code inside 92 realistic codebases, and published every run. The numbers on this page come from that work.

Read next

All library pages