VibeDefend by CybeDefend - The one command line to secure your Cursor and Claude Code

by•
VibeDefend installs on your AI coding agent (Claude Code, Cursor, Windsurf, Copilot, Codex and more) with one command. From then on the agent writes with your business rules, mined from your repo, and your security rules in its context. It scans each diff while the file is still open, and a guard refuses rm -rf, sudo or a read of your secrets before it runs. Scanners check code after the commit, this runs before the line is written. Free plan, no card.

Add a comment

Replies

Best

great to have new security products in the devtools space. I love that you have dedicated comparison pages for existing tools - really easy to differentiate. kudos on the launch!

you rock! what's your preferred AI coding agent btw? anything they did that scared you lately?

  Glad they help! They mostly answer one question, and the honest answer is that you keep the scanner you already run and add the part that lives inside the agent, the rules before each edit and the guard on each tool call. They're all here for the side by side: cybedefend.com/en/compare

Quick update for the community! 📣


Seeing all the great discussions today in the comments about the risks of AI coding agents (like data leakage and compliance rules), I thought this would be the perfect place to share an upcoming event we are super excited about.


We’re hosting a live webinar with Jason Lee (former CISO at Zoom, Splunk, and F5) entirely dedicated to the security of AI coding agents. We'll be diving deep into how engineering teams can actually scale these autonomous tools safely without giving the security team a heart attack.

If today's launch caught your interest and you want to dig deeper into the topic with a top-tier cybersecurity expert, we'd love to have you join the conversation.


You can grab your spot right here:


Would love to see some of you there! Let me know if there are specific questions you'd like us to ask him. 👇

What if there is a conflict between the security directive and the instruction from the developer to the agent?
Btw, Congratulations Team VibeDefend by CybeDefend ✌️

 Thank you so much, really appreciated! 🙏 Great question. When a developer's instruction contradicts a rule injected into the agent's context, the agent doesn't silently pick a side: it flags the conflict, explains which rule is at stake, and the developer decides.

If the instruction reflects a legitimate change (an outdated rule, for example), that correction can feed a new rule proposal at the end of the session, so your rule base keeps up with the code.

And there are two safety nets on top of that:

  • The end-of-session scan still checks the code, so if the override introduces a vulnerability, the agent gets the finding and can fix it.

  • For the most critical actions (rm -rf, secret access, destructive commands...), Action Guards enforce the rule outside the model: there, the security policy always wins.

Being on the AWS marketplace makes procurement so much easier, smart move 🙃

Mining rules from the repo worries me a bit on older codebases. I audited one last month where four different places decided who counts as an admin, and they disagreed: two lower cased the email, two didn't. "Most consistent convention" there is a two against two tie, and either winner is a bug.

Does the miner flag contradictions like that for a human, or pick one? I'd rather get the list of disagreements than the rules.

 Great example, and exactly why the miner doesn't pick. When implementations contradict each other, like your 2 vs 2 admin check, it flags the contradiction for a human to arbitrate instead of turning either side into a rule. As you said, either winner would be a bug.

So you get the disagreements as disagreements. Once your team settles on the right behavior, it becomes the rule and the agent stops reproducing the inconsistency.