StackHawk Documentation StackHawk Logo HawkDocs

No results found

Try different keywords or check your spelling

Search documentation

Find guides, API references, and more

esc

Agent Skills

StackHawk agent skills are instruction sets that teach AI coding agents how to run security scans, parse findings, fix vulnerabilities, and verify fixes. Install a skill and your agent gains full DAST capability — no separate tools, no context switching.

How Agent Skills Work

When you install a StackHawk agent skill, your AI coding agent learns how to:

  1. Configure — Generate a stackhawk.yml config file based on your app type, host, and auth pattern
  2. Scan — Run HawkScan against your running application
  3. Parse — Read structured JSON findings with vulnerability type, severity, affected path, and method
  4. Fix — Remediate vulnerabilities directly in your codebase (parameterized queries, output encoding, security headers, etc.)
  5. Verify — Rescan to confirm all fixes are effective

When you finish building a feature, the agent automatically runs this loop — “done” means “done and secure.”

Supported Platforms

Prerequisites

  • A StackHawk account (Secure, Scale, or Vibe)
  • A StackHawk API key (generate at app.stackhawk.com → Settings → API Keys)
  • HawkScan CLI or Docker — see Install and Run HawkScan for signed installers (macOS .pkg, Windows .msi, Linux .zip) or Homebrew
  • An application running locally that the scanner can reach

Two Skills Included

The StackHawk agent skills package includes two skills:

SkillPurpose
HawkScanConfigure, run, and interpret DAST scans. Fix vulnerabilities and verify fixes.
APIQuery the StackHawk platform for security posture, findings reports, scan history, and triage status.

Your privacy settings

We use first and third party cookies to ensure that we give you the best experience on our website and in our products.