# Do coding agents recommend GitLab Security?

> GitLab Security was chosen in 19% of 118 judged security platforms sessions, ranking second. Measured with Claude Code, Codex, Grok Build CLI and Muse Code.

Source: https://armature.tech/library/do-coding-agents-recommend-gitlab-security
Published: 2026-09-28 · Updated: 2026-09-30
Publisher: Armature, Inc. (https://armature.tech)

---

> GitLab Security was chosen in 19% of 118 judged security platforms sessions, ranking second. It was also raised as a candidate in 37 further sessions without being chosen.

This page reports what happened when Claude Code, Codex, Grok Build CLI and Muse Code had to solve a problem in security platforms inside a realistic codebase. Not what a chat assistant says about GitLab Security. What an agent actually chose.

## The numbers

| | |
| --- | --- |
| Category | Security platforms |
| Sessions in the category | 118 |
| Sessions where GitLab Security was chosen | 22 |
| Install share | 19% |
| Rank in category | 2 of 19 |
| Codebases it won in | 4 |
| Raised as a candidate, not chosen | 37 |
| Chosen when considered | 37% |
| Site | gitlab.com |

## By agent

Claude Code, Codex and Grok Build CLI agree closely on GitLab Security, choosing it at rates within 3 points of each other. Muse Code ran fewer than 30 sessions here, too few to compare.

| Agent | Sessions | Chose GitLab Security | Share |
| --- | --- | --- | --- |
| Claude Code | 30 | 6 | 20% |
| Codex | 30 | 5 | 17% |
| Grok Build CLI | 30 | 6 | 20% |
| Muse Code | 28 | 5 | 18% |

## What GitLab Security was up against

The full ranking in security platforms, from the same sessions:

| # | Product | Runs won | Share |
| --- | --- | --- | --- |
| 1 | Checkmarx One | 39 | 33% |
| 2 | GitLab Security **(this page)** | 22 | 19% |
| 3 | Snyk | 19 | 16% |
| 4 | Aikido Security | 9 | 8% |
| 5 | HCL AppScan | 5 | 4% |
| 6 | GitHub Advanced Security + ZAP | 4 | 3% |
| 7 | GitHub Advanced Security + Microsoft Defender for Cloud | 3 | 3% |
| 8 | DefectDojo + Gitleaks + Semgrep + Trivy + ZAP | 3 | 3% |

## What this means

A solid second or third position in a category means the agent is genuinely choosing rather than reaching automatically. That is a winnable position, because the inputs it uses can be changed.

The fastest gains are usually in the sessions that were nearly won: read them, find the step where the agent moved on, and fix that step.

## Where these numbers come from

The 118 sessions in security platforms are part of a published set of 15,000, run with real coding agents inside realistic codebases and judged blind. The full method is on one page: [how we measured this](/library/how-we-measured-this).

Every security platforms run can be replayed on [the board](/leaderboards/security-platforms).

If you work on GitLab Security: the judge recorded a reason for every session where it was raised and passed over. Those reasons are in the transcripts.

<!-- generated by scripts/write-data-pages.mjs -->

## Common questions

### Do coding agents recommend GitLab Security?

Yes. GitLab Security was chosen in 22 of the 118 judged sessions in security platforms, a 19% install share, ranking second in its category.

### Does Claude Code recommend GitLab Security?

In 6 of the 30 sessions in security platforms run with Claude Code, which is 20%.

### Do different coding agents treat GitLab Security differently?

Not much. Claude Code, Codex and Grok Build CLI chose it at similar rates, between 17% and 20% of their runs.

### How was this measured?

Real coding agents at pinned versions were run in sandboxes inside 92 realistic codebases and asked to solve real tasks. A simulated project owner approved or questioned each recommendation before any code was written, and a judge from a model family that builds none of the agents read every session blind.

### How often is GitLab Security considered but not chosen?

It was raised as a candidate in 37 sessions without being chosen, and chosen in 22. That is a 37% conversion from considered to chosen.

## Read next

- [How to get picked for security platforms by coding agents](https://armature.tech/library/security-platforms-coding-agents-playbook) (Markdown: https://armature.tech/library/security-platforms-coding-agents-playbook.md)
- [Do coding agents recommend Checkmarx One?](https://armature.tech/library/do-coding-agents-recommend-checkmarx-one) (Markdown: https://armature.tech/library/do-coding-agents-recommend-checkmarx-one.md)
- [Do Claude Code, Codex and Cursor pick the same tools?](https://armature.tech/library/do-claude-code-and-codex-agree) (Markdown: https://armature.tech/library/do-claude-code-and-codex-agree.md)

---

Armature helps software products get discovered and used by coding agents.
Service: https://armature.tech/discoverability · Results: https://armature.tech/leaderboards/sectors · Contact: contact@armature.tech
