StackHawk Documentation StackHawk Logo HawkDocs

No results found

Try different keywords or check your spelling

Search documentation

Find guides, API references, and more

esc

Agent Skills

StackHawk agent skills are instruction sets that teach AI coding agents how to run security scans, parse findings, fix vulnerabilities, and verify fixes. Install a skill and your agent gains full DAST capability — no separate tools, no context switching.

When you install a StackHawk agent skill, your AI coding agent learns how to:

  1. Configure — Generate a stackhawk.yml config file based on your app type, host, and auth pattern
  2. Scan — Run HawkScan against your running application
  3. Parse — Read structured JSON findings with vulnerability type, severity, affected path, and method
  4. Fix — Remediate vulnerabilities directly in your codebase (parameterized queries, output encoding, security headers, etc.)
  5. Verify — Rescan to confirm all fixes are effective

When you finish building a feature, the agent automatically runs this loop — “done” means “done and secure.”

  • A StackHawk account (Secure, Scale, or Vibe)
  • A StackHawk API key (generate at app.stackhawk.com → Settings → API Keys)
  • HawkScan CLI or Docker — see Install and Run HawkScan for signed installers (macOS .pkg, Windows .msi, Linux .zip) or Homebrew
  • An application running locally that the scanner can reach

The StackHawk agent skills package includes two skills:

SkillPurpose
HawkScanConfigure, run, and interpret DAST scans. Fix vulnerabilities and verify fixes.
APIQuery the StackHawk platform for security posture, findings reports, scan history, and triage status.

Your privacy settings

We use first and third party cookies to ensure that we give you the best experience on our website and in our products.