# Do coding agents recommend StackHawk?

> StackHawk was chosen in 3% of 460 judged security testing sessions, ranking seventh. Measured with Claude Code, Codex, Grok Build CLI and Muse Code.

Source: https://armature.tech/library/do-coding-agents-recommend-stackhawk
Published: 2026-09-28 · Updated: 2026-09-29
Publisher: Armature, Inc. (https://armature.tech)

---

> StackHawk was chosen in 3% of 460 judged security testing sessions, ranking seventh. It was also raised as a candidate in 57 further sessions without being chosen.

This page reports what happened when Claude Code, Codex, Grok Build CLI and Muse Code had to solve a problem in security testing inside a realistic codebase. Not what a chat assistant says about StackHawk. What an agent actually installed.

## The numbers

| | |
| --- | --- |
| Category | Security testing |
| Sessions in the category | 460 |
| Sessions where StackHawk was chosen | 12 |
| Install share | 3% |
| Rank in category | 7 of 65 |
| Codebases it won in | 2 |
| Raised as a candidate, not chosen | 57 |
| Chosen when considered | 17% |
| Site | stackhawk.com |

## By agent

With 12 wins spread across 4 agents, the rates below are small numbers and a difference between them is not yet a finding. They are here because the direction is worth knowing, not because the gap is established.

| Agent | Sessions | Chose StackHawk | Share |
| --- | --- | --- | --- |
| Claude Code | 116 | 0 | 0% |
| Codex | 116 | 1 | 1% |
| Grok Build CLI | 116 | 4 | 3% |
| Muse Code | 112 | 7 | 6% |

## What StackHawk was up against

The full ranking in security testing, from the same sessions:

| # | Product | Runs won | Share |
| --- | --- | --- | --- |
| 1 | ZAP | 111 | 24% |
| 2 | Semgrep | 78 | 17% |
| 3 | SonarQube | 66 | 14% |
| 4 | Burp Suite | 30 | 7% |
| 5 | GitHub Advanced Security | 25 | 5% |
| 6 | Trivy | 14 | 3% |
| 7 | StackHawk **(this page)** | 12 | 3% |
| 8 | Strix | 11 | 2% |

## What this means

This is an integration problem, not a presence problem. Agents raised StackHawk in 57 sessions and chose it in 12, so it reaches the shortlist and then loses. Something at the last step is costing the session, and in our data that is usually a quickstart that does not run when pasted, documentation describing an interface that changed, or a package name that does not match the product name.

That is the cheaper of the two problems to have. The reason is written down in each losing transcript.

## Where these numbers come from

The 460 sessions in security testing are part of a published set of 15,000, run with real coding agents inside realistic codebases and judged blind. The full method is on one page: [how we measured this](/library/how-we-measured-this).

Every security testing run can be replayed on [the board](/leaderboards/security-testing).

If you work on StackHawk: the judge recorded a reason for every session where it was raised and passed over. Those reasons are in the transcripts.

<!-- generated by scripts/write-data-pages.mjs -->

## Common questions

### Do coding agents recommend StackHawk?

Yes. StackHawk was chosen in 12 of the 460 judged sessions in security testing, a 3% install share, ranking seventh in its category.

### Does Claude Code recommend StackHawk?

In 0 of the 116 sessions in security testing run with Claude Code, which is 0%.

### Do different coding agents treat StackHawk differently?

Not much. Claude Code, Codex, Grok Build CLI and Muse Code chose it at similar rates, between 0% and 6% of their runs.

### How was this measured?

Real coding agents at pinned versions were run in sandboxes inside 92 realistic codebases and asked to solve real tasks. A simulated project owner approved or questioned each recommendation before any code was written, and a judge from a model family that builds none of the agents read every session blind.

### How often is StackHawk considered but not chosen?

It was raised as a candidate in 57 sessions without being chosen, and chosen in 12. That is a 17% conversion from considered to chosen.

## Read next

- [How to get picked for security testing by coding agents](https://armature.tech/library/security-testing-coding-agents-playbook) (Markdown: https://armature.tech/library/security-testing-coding-agents-playbook.md)
- [Do coding agents recommend ZAP?](https://armature.tech/library/do-coding-agents-recommend-zap) (Markdown: https://armature.tech/library/do-coding-agents-recommend-zap.md)
- [Do coding agents recommend Semgrep?](https://armature.tech/library/do-coding-agents-recommend-semgrep) (Markdown: https://armature.tech/library/do-coding-agents-recommend-semgrep.md)
- [Do Claude Code, Codex and Cursor pick the same tools?](https://armature.tech/library/do-claude-code-and-codex-agree) (Markdown: https://armature.tech/library/do-claude-code-and-codex-agree.md)

---

Armature helps software products get discovered and used by coding agents.
Service: https://armature.tech/discoverability · Results: https://armature.tech/leaderboards/sectors · Contact: contact@armature.tech
