VibeDefend by CybeDefend - The one command line to secure your Cursor and Claude Code

by•
VibeDefend installs on your AI coding agent (Claude Code, Cursor, Windsurf, Copilot, Codex and more) with one command. From then on the agent writes with your business rules, mined from your repo, and your security rules in its context. It scans each diff while the file is still open, and a guard refuses rm -rf, sudo or a read of your secrets before it runs. Scanners check code after the commit, this runs before the line is written. Free plan, no card.

Add a comment

Replies

Best

Hey Product Hunt ! 👋 I’m Axel, the third co-founder, handling Growth and Go-To-Market here at CybeDefend


shared our origin story, and highlighted the tech. I want to talk about what happens when you actually put VibeDefend in the hands of a dev team.

When we ran our study, we found something crazy: left to their own devices, AI agents ignored internal business and compliance rules in 88% of cases. They write fast, but they accumulate silent technical debt just as quickly.

By governing the agent at the exact moment the code is written (an approach we call "Shift-0"), VibeDefend brings that rule compliance up to 89%.

It’s not just a security tool; it’s an enabler. It allows your team to confidently scale "vibe-coding" without the CISO or the Lead Dev losing sleep over what’s being shipped to production.


I’ll be hanging out in the comments all day with the team. I'd love to know: what is the main risk keeping your team from giving full autonomy to AI coding agents right now? Let's chat!

What is the main risk keeping your team from giving full autonomy to AI coding agents right now?

fun fact: 81% of the community is a 'human-in-the-loop' type of developer, according to .

 i think the main concern for us is data leakage and accidental secret exposures when agents auto-commit. best of luck for launch

 Hey Vikram, thanks for the support! 🙌

You hit the nail on the head. Accidental secret exposure and data leakage are the exact nightmares keeping engineering leaders from adopting fully autonomous agents. Agents are incredibly fast, but they often lack the contextual awareness of what is sensitive.


This is exactly what CybeDefend is built to prevent. Because we operate at the "Shift-0" level (intercepting right at the generation phase, before any auto-commit), we act as a hard boundary. If an agent tries to leak a secret, push PII, or bypass a core security rule, we instantly block that specific dangerous action in real-time, without breaking the rest of the agent's workflow.

Hey Product Hunt 👋 Florentin, one of the three co-founders with Julien and Axel. I lead product vision and tech.

Quick one from the tech side. The bugs that scare me most in AI-written code aren't injections, scanners already catch those. It's the agent happily shipping an endpoint where user A can read user B's data, because nobody ever told it that rule. That's why VibeDefend mines your business rules from your repo and puts them in the agent's context before it writes.

Testing it takes a couple of minutes and it's free, no card needed. If you go further, WELCOME50 gets you 50% off your first month:

And please, tell us everything: what you love, what annoys you, what's missing. We genuinely love collecting feedback and shaping the product around what you actually need.

npx -y /vibedefend@latest install
💎 Pixel perfection

   If this actually works as seamlessly as describe it’s a total game changer for our workflow. congrats team for second launch🙌

If this actually works as seamlessly as describe it’s a total game changer...

yes, it does! one command line to secure your AI coding agent -- , , or else:

npx -y /vibedefend@latest install

@priya_kushwaha1 Thank you Priya! This one is about a single idea the agent already knows how to code, what it lacks is your context, the rules that live in your repo and in your engineers' heads. If you try it on one project, tell us which rule it caught first, that's the story we love hearing :) If you want the five-minute version first:

Hey! Solid launch! I wonder how can I integrate this application into my current setup

 Hey Matheus, thanks a lot for the support! 🙌


Integration is actually designed to be super straightforward. You can check out the step-by-step guides for different environments right here in our documentation:

To point you in the exact right direction, I'd love to know a bit more about your current setup!
Let me know, I'd be happy to walk you through how it would fit perfectly into your workflow! 🚀

   You'll also find all the native integrations we offer here, and I'm happy to help if you need anything:

   Looking good! Having support for codex could also be extra useful there!

   We actually already support OpenAI Codex just as seamlessly as Claude.

wrote a deep dive on Codex security risks and best practices if you want to take a look:

Does the secrets scanner also check files that are generated or modified indirectly by the coding agent?

 Yes, in two ways:

  1. Files the agent edits directly are scanned at the end of the session.

  2. If the agent commits during the session, the scan also covers the full git diff of those commits, so files generated or modified indirectly (codegen, scripts, shell commands) are included too.

Upstream, the secret guard also blocks the agent from reading raw secrets (like .env files) and points it to the managed reference instead, so secrets are much less likely to end up in generated code in the first place.

Anything not committed during the session gets picked up by your regular CybeDefend scans (CI or repo) as soon as it lands in the codebase.

@jackthompson68 Good question. Two layers, upstream, the guard refuses the read of .env or of a secret in the first place, so it never enters the agent's context and can't be copied into a generated file. Then the end-of-session scan covers what the session changed like Florentin explained. The hook layer, what fires on each tool call and at session end, is described here:

Hey Product Hunt 👋

I'm Julien, one of the three co-founders of CybeDefend with Florentin and Axel. We're in our mid-twenties and we started the company in Lille in January 2025. Every vibe-coded app I scanned was hackable in five minutes, and that is the problem we work on every day.

The idea we started with is that security should speed you up, not stand in your way. AI agents now ship thousands of lines a day and a human can't read all of it, so we moved the check to the place where the code gets written.

VibeDefend plugs into your agent with one command. It gives the agent your business rules, mined from your repo, and your security rules before it writes a line, scans each diff while the file is still open, and stops rm -rf, sudo or a read of your secrets before they run.

We want every line an AI agent writes to already follow your rules, including the ones you never wrote down.

npx -y /vibedefend@latest install

It's free to start, no card:

Tell me what your agent did last week that scared you, I'm here all day to answer!

The State of Vibe Coding 2025 report highlighted 3 types of vulnerabilities: exposing secrets, access misconfigurations, hardcoded credentials. Do you share this opinion? or have you found more patterns based your user interviews and research?

[1]

  Those three for sure, and secrets are the easiest to stop, the guard refuses the read of a .env before the value ever reaches the agent's context. I'd add the rule that only lives in someone's head, like 'an invoice can't be edited once it's sent', where the code is clean and every scanner passes it. That one has to reach the agent before it writes the endpoint, which is what we built VibeDefend around. More on that family of bugs: cybedefend.com/en/blog/business-logic-flaws-ai-generated-code

💎 Pixel perfection

How much control do teams have over the business rules mined from the repo?

 Great question! Rules come from two sources, and your team stays in control of both.

  1. At the first scan, our miner analyzes the repo and extracts the most consistent coding conventions and business rules, so the agent starts with a solid corpus from day one.

  2. Then the corpus keeps growing as you code. When a business rule emerges during a session, either because the agent realized it made a mistake or because you corrected it, it can propose that rule at the end of the session. Your rule base gets enriched automatically, session after session.

On the control side:

Session proposals are never applied silently: they land in a review inbox and your team accepts or rejects each one. By default, the agent even asks you in chat before drafting one.

Curious to hear how your team manages these rules today!

@devinstone Adding one important point, because it's the part teams ask about most, what you can do with the rules once they exist. Every rule lives in the VibeDefend tab of your project dashboard, as a plain sentence you can read, edit, rewrite or delete. A new rule always lands as a proposal first, whether it was mined at the first scan or suggested after a session, and the people in charge of the project decide which ones go active. Once active, a rule applies to every agent and every developer connected to that project, Claude Code, Cursor or Copilot alike, so there is one rule base and not one file per person to summarize, mining gives you the starting point, the review is where the team makes it theirs. The proposals inbox and the end-of-session gap analysis are documented here: , and there's a longer piece on giving the agent business context rather than conventions:

 curious: how do you currently manage your business and security rules with your team?

Can teams define their own blocked commands based on their internal security policies?

 Yes, absolutely! VibeDefend ships with default presets across 5 categories: Filesystem, Shell & commands, Network, Git and Process. They block the most dangerous actions and warn on unusual behavior, which also acts as a safety net if the agent ever gets hijacked (prompt injection, poisoned context...).

From there, everything is configurable:

  1. Switch any preset between warn and block, or disable it entirely.

  2. Create your own blocking rules directly in the VibeDefend tab of your project, to match your internal security policies.

  3. Rules live at the project level, so every AI agent working on that project gets the same policy.

You can cover file reads and writes, deletions, privileged actions like sudo, package installs, destructive Terraform actions, specific processes, git operations, HTTP and network calls, access to specific environment variables, and more.

Happy to walk you through it if you have a specific policy in mind!

@john_michael31 Florentin has the config covered, so a different angle. Blocking rm -rf is the floor, every team should have it and it takes a minute. The part that changed how our users work is that the same project policy carries the business rules too, and every agent on the project gets it, Claude Code, Cursor, Copilot, whichever a developer prefers.

One policy, mined once from the repo, served at the edit. Otherwise you end up with a CLAUDE.md here, a .cursorrules there, and three versions of the truth.. The guards are documented here: docs.cybedefend.com/latest/agent-ai-integration/vibedefend, and if your team runs Claude Code with --dangerously-skip-permissions, this explains what that flag skips and what still blocks:

Hey, what an amazing idea ! Is it easy to integrate to any project ?

 Thank you so much! 🙏

Yes, it's a single command:

npx -y /vibedefend@latest install

The installer walks you through it: pick your region (EU or US), sign in, and it auto-detects the agents you have installed (Claude Code, Cursor, Codex, Windsurf, VS Code Copilot) and wires them up. It works on macOS, Linux and Windows.

You can try it for free, no credit card required. Let me know how it goes!

  It installs on the agent and not on the project, with one npx command, then you link a repo by dropping its project id in a small config file at the root. The docs walk through it:

this just makes so much sense. security is an everyone problem, and makes it a no brainer.

s/o ?makers for the great work on this new launch.

💎 Pixel perfection

Does the agent get the security feedback immediately so it can fix the issue in the same coding session?

 Yes! At the end of the session or when he finished part of the deliverable before the pull request, VibeDefend runs a scan on the agent's work. It runs in the background, so the agent can keep going and gets notified as soon as the scan is done, then fixes the findings in the same session.

The scan only covers the files the agent modified, so it's very fast and focused on the work it just did. For example, if it introduces a SQL injection, it gets the finding and switches to a parameterized query before you even commit.

The result: far fewer alerts further down the pipeline.

One other thing on what that feedback actually contains, because it's where we spend our energy. A SQL injection is the easy part, every scanner catches it. 43% of API vulnerabilities exploit business logic, not a CVE (Wallarm, 2026), and no scanner sees that a refund above 500 euros needs a finance manager.

So the rules are mined from your repo at the first scan, then served to the agent right before it writes the feature the developer asked for, the right rule at the right moment in the right file. We measured the difference on tickets with the same model, and the whole study is public: . More on why scanners are blind to this:

 thanks for the support! curious what's your stack btw? anything your coding agents did that scared you lately? ping ?makers

12
Next