What happened
42Crunch launched (announced ~July 17, 2026) a deterministic API Security Testing plugin for GitHub Copilot that continuously audits, tests, and remediates API vulnerabilities generated by AI coding agents directly inside the Copilot workflow, citing that 45% of AI-generated code contains known OWASP Top 10 vulnerabilities.
Why it matters
Addresses a concrete, measured risk in agentic/AI-assisted software development (vulnerable AI-generated API code) with inline deterministic guardrails rather than post-hoc scanning, integrated into one of the most widely used AI coding assistants.
Applicability
AppSec and platform engineering teams using GitHub Copilot for API development should pilot the plugin to catch AI-introduced API vulnerabilities before merge.