Download PDF version Contact company

Checkmarx, the global pioneer in application security solutions, announced its CheckAI Plugin for ChatGPT, the industry’s first plugin to detect and prevent potential attacks against ChatGPT-generated code.

The plugin enables developers and security teams to protect against attacks caused by malicious open-source packages and dependencies while working within the ChatGPT interface.

GenAI-generated code

Nothing more perfectly represents the decision-making tension faced by CISOs than the existence of both significant opportunities and new vulnerabilities presented by open source and GenAI-generated code,” said Sandeep Johri, CEO at Checkmarx.

He adds, “Checkmarx has long been a pioneer in application security for enterprise customers and, with GenAI playing an increasing role in application development, we’re pleased to provide the first solution to help protect against the new generation of attacks already emerging."

CheckAI plugin

With CheckAI, CISOs can rest assured that the superior developer experience will ensure that AppSec standards are met"

Sandeep Johri continues, "With CheckAI, CISOs can rest assured that the superior developer experience will ensure that AppSec standards are met, while accelerating applications’ time-to-delivery.”

With the CheckAI Plugin for ChatGPT in combination with Supply Chain Threat Intelligence from Checkmarx, CISOs, and application security pioneers can ensure that development teams take advantage of time-saving GenAI tools like ChatGPT while remaining aligned and compliant with AppSec standards.

Features

Within a highly productive environment featuring a superior developer experience, development teams can readily:

  • Scan their GPT-generated code for vulnerabilities within the ChatGPT interface.
  • Receive instant feedback on potential vulnerabilities or validation of open-source packages.
  • Employ protection against malicious open-source packages.

Protection from GenAI hazards

With the CheckAI Plugin for ChatGPT, we’re able to protect our developers against new types of attack" 

"With GenAI disrupting how we develop software we need to make sure we provide the right tools and governance to our developers for utilising GPT. Nobody is slowing down," said Sharon Uda, VP of Engineering at CHEQ.

Sharon Uda adds, "For CHEQ, as the pioneer in protecting marketing teams from the hazards of GenAI, protecting our developers is as important. With the CheckAI Plugin for ChatGPT, we’re able to protect our developers against the new types of attack that GenAI brings to the table."

AppSec vendor

We’re already seeing new attacks against GenAI solutions, including ‘AI hallucinations’ and prompt injections, and the OWASP Foundation has already published the first draft of the OWASP Top 10 list for LLMs,” said Ori Bendet, VP of Product Management at Checkmarx. 

Ori Bendet adds, “We’re very excited to be the first AppSec vendor to provide real solutions to protect against these new types of attacks and encourage all GenAI solution providers to partner with us as we continue to expose new ones.”

Safe and powerful AI

In December of 2022, Checkmarx AppSec security researchers discovered a vulnerability in the OpenAI signup process that could have allowed unlimited credit on new accounts.

The team reported the vulnerability to OpenAI, who rapidly worked to resolve it. OpenAI is a research and development company with a mission to create safe and powerful AI that benefits all of humanity.

Protection against malicious packages

The CheckAI Plugin for ChatGPT is available as part of the ChatGPT plugins beta

The CheckAI Plugin for ChatGPT is available as part of the ChatGPT plugins beta, which is currently available to all ChatGPT Plus users and protects against malicious packages and open-source dependencies. 

Additional use cases, such as prompt protection, IaC validations, API validation, and more will be added as part of planned future releases.

Application security platform

CheckAI is powered by Checkmarx One, the industry's most comprehensive application security platform, together with Checkmarx's Supply Chain Threat Intelligence for detecting malicious open source packages.

Purpose-built for cloud-native application development, Checkmarx One is highly scalable and integrates seamlessly with developers’ tools and development environments of choice.

Download PDF version Download PDF version

In case you missed it

What will be the big news for security in 2025?
What will be the big news for security in 2025?

2025 is likely to see further advancements in artificial intelligence, with potential impacts on various aspects of society, including the security industry. The new year will also...

How did security change for the better in 2024?
How did security change for the better in 2024?

2024 was a year of significant challenges and remarkable progress in a world that is more interconnected than ever. Global collaboration continues to point the way toward continuin...

Keyless security with ASSA ABLOY at Helsinki Airport
Keyless security with ASSA ABLOY at Helsinki Airport

Managing access to and around Helsinki Airport is a complex task. Around 15,000 people work there daily pre-pandemic passenger numbers hovered around 60,000 to 70,000. Challenges...

Quick poll
Which AI-powered capability will dominate in the years ahead?