CybeDefend secures the code your AI agent writes, from inside the agent. One command installs VibeDefend on Claude Code, Cursor, Windsurf, Copilot, Codex and other agents. The agent then codes with your business rules, mined from your repo, and your security rules in its context. Each diff is scanned while the file is open, and a guard stops rm -rf, sudo or secret reads before they run. SAST, SCA, secrets, IaC, CI/CD and container scanning are included. Free plan, no card.
This is the 2nd launch from CybeDefend. View more

VibeDefend by CybeDefend
Launched this week
VibeDefend installs on your AI coding agent (Claude Code, Cursor, Windsurf, Copilot, Codex and more) with one command. From then on the agent writes with your business rules, mined from your repo, and your security rules in its context. It scans each diff while the file is still open, and a guard refuses rm -rf, sudo or a read of your secrets before it runs. Scanners check code after the commit, this runs before the line is written. Free plan, no card.







Free Options
Launch Team / Built With





CybeDefend
Quick update for the community! 📣
Seeing all the great discussions today in the comments about the risks of AI coding agents (like data leakage and compliance rules), I thought this would be the perfect place to share an upcoming event we are super excited about.
We’re hosting a live webinar with Jason Lee (former CISO at Zoom, Splunk, and F5) entirely dedicated to the security of AI coding agents. We'll be diving deep into how engineering teams can actually scale these autonomous tools safely without giving the security team a heart attack.
If today's launch caught your interest and you want to dig deeper into the topic with a top-tier cybersecurity expert, we'd love to have you join the conversation.
You can grab your spot right here: https://www.cybedefend.com/en/webinar
Would love to see some of you there! Let me know if there are specific questions you'd like us to ask him. 👇
Mastra
to clarify, is the workshop more aimed at developers evaluating whether to adopt @CybeDefend, or hands-on for people already building with it?
asking for a friend
CybeDefend
@fmerian Haha, great question! Tell your "friend" it’s definitely the first option. 😉
Since we have Jason Lee joining us, the session is highly strategic. It's not a hands-on product tutorial, but a deep dive into the real-world risks of AI agents, DevSecOps best practices, and the "Shift-0" methodology. It’s perfect for engineering and security leaders figuring out how to scale these tools safely, whether they end up using CybeDefend or building their own internal guardrails. They will walk away with actionable insights!
Almost had an agent read my .env file before I caught it manually. Guard that stops reading my secrets before it happens would have saved me a very uncomfortable five minutes. Does it work for my cloud credentials file as well as for my local secrets?
CybeDefend
CybeDefend
Mining rules from the repo worries me a bit on older codebases. I audited one last month where four different places decided who counts as an admin, and they disagreed: two lower cased the email, two didn't. "Most consistent convention" there is a two against two tie, and either winner is a bug.
Does the miner flag contradictions like that for a human, or pick one? I'd rather get the list of disagreements than the rules.
CybeDefend
@dalemooney Great example, and exactly why the miner doesn't pick. When implementations contradict each other, like your 2 vs 2 admin check, it flags the contradiction for a human to arbitrate instead of turning either side into a rule. As you said, either winner would be a bug.
So you get the disagreements as disagreements. Once your team settles on the right behavior, it becomes the rule and the agent stops reproducing the inconsistency.
Mastra
@dalemooney anything @CybeDefend should build/improve/fix from your perspective?
@fmerian one thing: show where each mined rule came from, the files it was seen in. A rule written as a plain sentence is easy to approve without checking, and the evidence is what I'd actually review.
Florentin, flagging it for a human is the behaviour I'd want.
Dial
the 88% to 89% jump is the number I'd want more detail on, not because it's small, but because it implies 11% of cases still slip through even with the agent governed at write-time. what does that residual 11% look like in practice, is it mostly novel command patterns your ruleset hasn't seen yet, or edge cases where the agent works around the guard through a legitimate-looking path (like writing to a file that gets executed later instead of running the command directly)?
CybeDefend
@galdayan Really sharp question, thanks. One clarification first: the 89% isn't a guard metric. It measures business-rule conformance: with VibeDefend, the agent implemented 57 of 64 graded rule specifics exactly, vs 12% for the bare agent and 13% with a realistic rules file.
The residual 11% is 7 deviations, and none of them is the agent routing around a guard:
4 are rules that were never delivered: a retrieval recall gap when the rule belongs to a different family than the ticket (e.g. a loyalty rule on a refund ticket).
3 were delivered but not implemented to the letter: a mis-arbitrated price edge case, a threshold the agent argued against in writing, and one rule served 13 times that the agent still dropped because the ticket explicitly asked for the opposite. Lesson learned: injection informs, it doesn't enforce.
On guards specifically: 1,769 shell commands checked, 17 refused, including one real attempt to pull a stored credential. The indirect path you describe (writing a script that runs later) is exactly what the AI judgment layer is there for, beyond literal command patterns.
Every case is detailed with its traces here: https://github.com/CybeDefend/vibedefend-xp
Dial
@florentin_ledy the "injection informs, it doesn't enforce" line is the real answer here, that one rule served 13 times and still dropped because the ticket asked for the opposite is a much better example than a clean number would've been. the retrieval-recall-gap being 4 of the 7 (rule exists but wrong family gets matched to the ticket) also makes sense as the harder failure mode, that's a search problem more than a security one. is that the piece you're actively working on improving, or is manual review of the miss list just the accepted cost for now since it's a small enough number.
CybeDefend
@galdayan It is absolutely a context and search problem.
While we are actively improving the retrieval engine, this is exactly why we allow teams to manually complete and curate the rule corpus. It acts as a centralized, living source of truth to keep all business rules up to date and explicitly documented across the board.
Dial
@axel_paulin fair, and honestly "curated by the team" is a reasonable answer for something that's fundamentally a retrieval problem, not every gap needs a model fix. thanks for the detailed numbers throughout this thread, that's rare for a launch day comment section.
Your vibe-coded PR now has a bouncer. I can live with that.
CybeDefend
@zach_francis Haha, best analogy of the day!