# How to get picked for security platforms by coding agents

> Checkmarx One took 33% of 118 judged security platforms sessions. What the numbers say a vendor in this category should do.

Source: https://armature.tech/library/security-platforms-coding-agents-playbook
Published: 2026-09-28 · Updated: 2026-09-30
Publisher: Armature, Inc. (https://armature.tech)

---

If you sell security platforms, this page is the part of the market no dashboard shows you: what a coding agent does when a developer asks for security platforms and never compares vendors.

The numbers come from 118 judged sessions with Claude Code, Codex, Grok Build CLI and Muse Code, spread across 7 realistic codebases, with every session read by a judge.


## What coding agents choose for security platforms

> Across 118 judged sessions, **Checkmarx One** was chosen most often, in **33%** of runs. GitLab Security was second with 19%.

| # | Product | Runs won | Share |
| --- | --- | --- | --- |
| 1 | Checkmarx One | 39 | 33% |
| 2 | GitLab Security | 22 | 19% |
| 3 | Snyk | 19 | 16% |
| 4 | Aikido Security | 9 | 8% |
| 5 | HCL AppScan | 5 | 4% |
| 6 | GitHub Advanced Security + ZAP | 4 | 3% |
| 7 | GitHub Advanced Security + Microsoft Defender for Cloud | 3 | 3% |
| 8 | DefectDojo + Gitleaks + Semgrep + Trivy + ZAP | 3 | 3% |
| 9 | DefectDojo | 2 | 2% |
| 10 | DefectDojo + Gitleaks + SonarQube + Trivy + ZAP | 1 | 1% |

Full board, every run replayable: [the security platforms leaderboard](/leaderboards/security-platforms).

## What the shape of this category means

The leader takes only 33% of runs. This category is genuinely open and the ordering can be moved.

With the top product at 33%, security platforms is decided in the moment, from what the agent reads and what it finds in the repository. Nothing is locked in, which is the best situation a vendor can be in and the one where the work pays fastest.

The order here is set by the quality of what an agent can read and by whether your product is already present in the codebase. Both are things you can change.

## The agents do not agree with each other

In this category Claude Code and Codex put Checkmarx One first, which is less common than it sounds: across the 31 categories we measured, Claude Code and Codex disagreed on the leader in 15 of them.

Grok Build CLI (30 sessions) and Muse Code (28 sessions) join this table with fewer runs, so read their rows as indicative.

| Agent | Runs | Picked most often |
| --- | --- | --- |
| Claude Code | 30 | Checkmarx One (11) |
| Codex | 30 | Checkmarx One (15) |
| Grok Build CLI | 30 | Checkmarx One (12) |
| Muse Code | 28 | Snyk (11) |

Even where they agree, they get there differently. In this category Codex ran a web search in 100% of its sessions and Claude Code in 70%, so what you publish reaches nearly all of Codex's security platforms sessions and most of Claude Code's.

## What you are really competing against

In this category agents never chose to build it themselves. All but 2 sessions ended with a product. That is good news: you are in a straight vendor comparison, and the levers that work are the ones you control.

## Considered, and never chosen

Because the judge records every product an agent raised and not only the one it picked, this board also shows who kept reaching the shortlist and losing. In security platforms the clearest case is Veracode: on the table in 28 sessions, chosen in none.

| Product | Raised in | Chosen in |
| --- | --- | --- |
| Veracode | 28 sessions | 0 |
| Probely | 28 sessions | 0 |

Being rejected is a better position than being unknown, and a cheaper one to fix. The product is already in the agent's head and on the list. Whatever ended those 56 sessions is recorded in each transcript, one reason at a time.

## What to do about it in security platforms

1. **Skip the build-versus-buy argument.** No security platforms session in this experiment ended with the agent writing its own implementation. All but 2 adopted a product, so the whole contest is against the other names in the table above.

2. **Aim at second place first.** Checkmarx One holds 33% and GitLab Security holds 19%. The gap between the default and the field is where the reachable sessions are.

The work that applies to every category rather than to this one is written up separately: [audit your documentation](/library/audit-your-docs-for-coding-agents), [write a quickstart an agent can follow](/library/write-a-quickstart-an-agent-can-follow), and [how to measure install share](/library/how-to-measure-install-share).

## Every security platform on this board

One page per product, with its install share, the per-agent split, and how often it was raised without being chosen.

- [Do coding agents recommend Checkmarx One?](/library/do-coding-agents-recommend-checkmarx-one) — chosen in 33% of sessions
- [Do coding agents recommend GitLab Security?](/library/do-coding-agents-recommend-gitlab-security) — chosen in 19% of sessions
- [Do coding agents recommend Aikido Security?](/library/do-coding-agents-recommend-aikido-security) — chosen in 8% of sessions
- [Do coding agents recommend GitHub Advanced Security?](/library/do-coding-agents-recommend-github-advanced-security) — chosen in 1% of sessions

## Where these numbers come from

118 judged sessions in security platforms across 7 codebases, part of a published set of 15,000. Real coding agents at pinned versions, in sandboxes, inside realistic codebases, with a simulated project owner in the loop and a blind judge on every session. The full method is on one page: [how we measured this](/library/how-we-measured-this).

Every security platforms run can be replayed on [the board](/leaderboards/security-platforms).

<!-- generated by scripts/write-data-pages.mjs -->

## Common questions

### How many codebases is this based on?

118 judged sessions across 7 realistic codebases. A category only runs on repositories where its seam is open, so coverage differs: some categories ran on more than ten codebases and some on two.

### What security platform do coding agents choose?

Across 118 judged sessions, Checkmarx One was chosen most often, in 33% of runs. GitLab Security was second with 19%. The result changes by agent.

### Do Claude Code and Codex pick the same security platform?

Yes. Claude Code and Codex both put Checkmarx One first in this category, which is less common than it sounds: they disagree on the leader in 15 of the 31 categories we measured.

### How often do agents build security platforms themselves instead of installing something?

Never, in this category. No session ended with the agent writing the code itself. All but 2 adopted a product; the rest used built-in tools or made no choice.

### How can a vendor improve its position here?

Make the quickstart run when pasted, state the current version on the documentation page, use one name across product, package and import, write pages for the symptoms users describe rather than only the category name, and get into the repository through templates and framework integrations.

### Which security platforms do agents consider but never choose?

Veracode (raised in 28 sessions, chosen in none), Probely (raised in 28 sessions, chosen in none). Being considered and not chosen is a different problem from being unknown, and it is usually fixable.

## Read next

- [Agent discoverability: the complete guide](https://armature.tech/library/agent-discoverability) (Markdown: https://armature.tech/library/agent-discoverability.md)
- [How coding agents choose tools](https://armature.tech/library/how-coding-agents-choose-tools) (Markdown: https://armature.tech/library/how-coding-agents-choose-tools.md)
- [Do coding agents recommend Checkmarx One?](https://armature.tech/library/do-coding-agents-recommend-checkmarx-one) (Markdown: https://armature.tech/library/do-coding-agents-recommend-checkmarx-one.md)
- [Do coding agents recommend GitLab Security?](https://armature.tech/library/do-coding-agents-recommend-gitlab-security) (Markdown: https://armature.tech/library/do-coding-agents-recommend-gitlab-security.md)

---

Armature helps software products get discovered and used by coding agents.
Service: https://armature.tech/discoverability · Results: https://armature.tech/leaderboards/sectors · Contact: contact@armature.tech
