CybeDefend secures the code your AI agent writes, from inside the agent. One command installs VibeDefend on Claude Code, Cursor, Windsurf, Copilot, Codex and other agents. The agent then codes with your business rules, mined from your repo, and your security rules in its context. Each diff is scanned while the file is open, and a guard stops rm -rf, sudo or secret reads before they run. SAST, SCA, secrets, IaC, CI/CD and container scanning are included. Free plan, no card.
This is the 2nd launch from CybeDefend. View more

VibeDefend by CybeDefend
Launching today
VibeDefend installs on your AI coding agent (Claude Code, Cursor, Windsurf, Copilot, Codex and more) with one command. From then on the agent writes with your business rules, mined from your repo, and your security rules in its context. It scans each diff while the file is still open, and a guard refuses rm -rf, sudo or a read of your secrets before it runs. Scanners check code after the commit, this runs before the line is written. Free plan, no card.







Free Options
Launch Team / Built With





Can teams define their own blocked commands based on their internal security policies?
CybeDefend
@john_michael31Β Yes, absolutely! VibeDefend ships with default presets across 5 categories: Filesystem, Shell & commands, Network, Git and Process. They block the most dangerous actions and warn on unusual behavior, which also acts as a safety net if the agent ever gets hijacked (prompt injection, poisoned context...).
From there, everything is configurable:
Switch any preset between warn and block, or disable it entirely.
Create your own blocking rules directly in the VibeDefend tab of your project, to match your internal security policies.
Rules live at the project level, so every AI agent working on that project gets the same policy.
You can cover file reads and writes, deletions, privileged actions like sudo, package installs, destructive Terraform actions, specific processes, git operations, HTTP and network calls, access to specific environment variables, and more.
Happy to walk you through it if you have a specific policy in mind!
CybeDefend
@john_michael31 Florentin has the config covered, so a different angle. Blocking rm -rf is the floor, every team should have it and it takes a minute. The part that changed how our users work is that the same project policy carries the business rules too, and every agent on the project gets it, Claude Code, Cursor, Copilot, whichever a developer prefers.
One policy, mined once from the repo, served at the edit. Otherwise you end up with a CLAUDE.md here, a .cursorrules there, and three versions of the truth.. The guards are documented here: docs.cybedefend.com/latest/agent-ai-integration/vibedefend, and if your team runs Claude Code with --dangerously-skip-permissions, this explains what that flag skips and what still blocks: cybedefend.com/en/blog/claude-code-dangerously-skip-permissions-explained
What if there is a conflict between the security directive and the instruction from the developer to the agent?
Btw, Congratulations Team VibeDefend by CybeDefend βοΈ
CybeDefend
@aymi_malikΒ Thank you so much, really appreciated! π Great question. When a developer's instruction contradicts a rule injected into the agent's context, the agent doesn't silently pick a side: it flags the conflict, explains which rule is at stake, and the developer decides.
If the instruction reflects a legitimate change (an outdated rule, for example), that correction can feed a new rule proposal at the end of the session, so your rule base keeps up with the code.
And there are two safety nets on top of that:
The end-of-session scan still checks the code, so if the override introduces a vulnerability, the agent gets the finding and can fix it.
For the most critical actions (rm -rf, secret access, destructive commands...), Action Guards enforce the rule outside the model: there, the security policy always wins.
BuildShip
great to have new security products in the devtools space. I love that you have dedicated comparison pages for existing tools - really easy to differentiate. kudos on the launch!
Kilo Code
you rock! what's your preferred AI coding agent btw? anything they did that scared you lately?
CybeDefend
@mufassir_kaziΒ Glad they help! They mostly answer one question, and the honest answer is that you keep the scanner you already run and add the part that lives inside the agent, the rules before each edit and the guard on each tool call. They're all here for the side by side: cybedefend.com/en/compare
CybeDefend
Hey Product Hunt π Florentin, one of the three co-founders with Julien and Axel. I lead product vision and tech.
Quick one from the tech side. The bugs that scare me most in AI-written code aren't injections, scanners already catch those. It's the agent happily shipping an endpoint where user A can read user B's data, because nobody ever told it that rule. That's why VibeDefend mines your business rules from your repo and puts them in the agent's context before it writes.
Testing it takes a couple of minutes and it's free, no card needed. If you go further, WELCOME50 gets you 50% off your first month: cybedefend.com
And please, tell us everything: what you love, what annoys you, what's missing. We genuinely love collecting feedback and shaping the product around what you actually need.
@cybedefendΒ @florentin_ledyΒ If this actually works as seamlessly as describe itβs a total game changer for our workflow. congrats team for second launchπ
Kilo Code
yes, it does! one command line to secure your AI coding agent -- @Cursor, @Claude Code, or else:
CybeDefend
@priya_kushwaha1 Thank you Priya! This one is about a single idea the agent already knows how to code, what it lacks is your context, the rules that live in your repo and in your engineers' heads. If you try it on one project, tell us which rule it caught first, that's the story we love hearing :) If you want the five-minute version first: cybedefend.com/en/blog/secure-app-in-5-minutes-ai-agent
CybeDefend
Hey Product Hunt π
I'm Julien, one of the three co-founders of CybeDefend with Florentin and Axel. We're in our mid-twenties and we started the company in Lille in January 2025. Every vibe-coded app I scanned was hackable in five minutes, and that is the problem we work on every day.
The idea we started with is that security should speed you up, not stand in your way. AI agents now ship thousands of lines a day and a human can't read all of it, so we moved the check to the place where the code gets written.
VibeDefend plugs into your agent with one command. It gives the agent your business rules, mined from your repo, and your security rules before it writes a line, scans each diff while the file is still open, and stops rm -rf, sudo or a read of your secrets before they run.
We want every line an AI agent writes to already follow your rules, including the ones you never wrote down.
It's free to start, no card: cybedefend.com
Tell me what your agent did last week that scared you, I'm here all day to answer!
Kilo Code
The State of Vibe Coding 2025 report [1] highlighted 3 types of vulnerabilities: exposing secrets, access misconfigurations, hardcoded credentials. Do you share this opinion? or have you found more patterns based your user interviews and research?
[1] The State of Vibe Coding 2025 in /p/vibecoding
CybeDefend
@fmerianΒ Those three for sure, and secrets are the easiest to stop, the guard refuses the read of a .env before the value ever reaches the agent's context. I'd add the rule that only lives in someone's head, like 'an invoice can't be edited once it's sent', where the code is clean and every scanner passes it. That one has to reach the agent before it writes the endpoint, which is what we built VibeDefend around. More on that family of bugs: cybedefend.com/en/blog/business-logic-flaws-ai-generated-code
CybeDefend
Quick update for the community! π£
Seeing all the great discussions today in the comments about the risks of AI coding agents (like data leakage and compliance rules), I thought this would be the perfect place to share an upcoming event we are super excited about.
Weβre hosting a live webinar with Jason Lee (former CISO at Zoom, Splunk, and F5) entirely dedicated to the security of AI coding agents. We'll be diving deep into how engineering teams can actually scale these autonomous tools safely without giving the security team a heart attack.
If today's launch caught your interest and you want to dig deeper into the topic with a top-tier cybersecurity expert, we'd love to have you join the conversation.
You can grab your spot right here: https://www.cybedefend.com/en/webinar
Would love to see some of you there! Let me know if there are specific questions you'd like us to ask him. π
free plan says 10 static scans. does every diff the agent writes count as one of those? an agent session would burn through 10 before lunch