StackHawk Documentation StackHawk Logo HawkDocs

No results found

Try different keywords or check your spelling

Search documentation

Find guides, API references, and more

esc

Agentic DAST

StackHawk brings dynamic application security testing directly into the AI development lifecycle. Your AI coding agent already understands your application — its architecture, its dependencies, its patterns. It also inherits your organization’s other skills, coding standards, and institutional knowledge. Agentic DAST lets that same agent run security scans against your live app, interpret the findings with full codebase context, fix vulnerabilities using the patterns and conventions your team already follows, and verify the fixes by rescanning. Security testing becomes part of how the agent builds, not a separate step after the fact.

Two Approaches

StackHawk offers two ways to add security testing to your AI coding tools:

Which Should I Use?

Agent SkillsMCP Server
Install methodMarketplace one-linerPython + uv
DependenciesNone (just HawkScan CLI)Python 3.10+, uv
PlatformsClaude Code, Codex, Gemini, Copilot, CursorCursor, Claude Code, Windsurf
How it worksTeaches the agent via instruction setsRuns as a local server the agent calls
Autonomous scanningYes — scans after feature completionOn request
Best forDevelopers who want zero-setup DAST in their agentTeams already using MCP servers

Your privacy settings

We use first and third party cookies to ensure that we give you the best experience on our website and in our products.