Cyber Protection
Help the agent notice security risks it might otherwise overlook.
Cyber Protection is an extra review aid for the current agent. It helps the agent surface possible security concerns it might otherwise overlook while reading or changing a project. Open the model picker in the composer and turn on Cyber Protection before asking for a security-focused review.
It is not a promise that the project is secure, a complete vulnerability audit, or a replacement for experienced human review, runtime testing, and dedicated security tools.
Turn it on
Section titled “Turn it on”- Open the model picker in the composer.
- Enable Cyber Protection.
- Describe the part of the project you want reviewed and any specific concerns.
- Ask the agent to separate confirmed findings from leads that still need investigation.
The expected result is a review with evidence and limitations—not a security certificate.
What changes when it is on
Section titled “What changes when it is on”The agent can start with the built-in security_scan tool. On supported workspace source,
the scanner builds a code-property graph and looks for suspicious paths from untrusted
data toward dangerous operations. It can flag patterns associated with SQL and command
injection, cross-site scripting, server-side request forgery, path traversal, prototype
pollution, unsafe deserialization, regular-expression denial of service, hardcoded
secrets, and weak cryptography.
The agent is then prompted to consider concerns a pattern scanner cannot decide by itself, such as ownership checks, authorization, rate limits, payment or role logic, and other application-specific trust boundaries. These are review leads, not automatically verified vulnerabilities.
Read the results critically
Section titled “Read the results critically”Potential findings include a location, severity, explanation, and suggested repair. A scan journal
under .v3code/ lets later runs distinguish new, fixed, and still-open findings.
The scanner currently models JavaScript and TypeScript most deeply, with partial Python coverage. Unsupported languages and framework-specific behavior still require manual review. False positives and missed issues are possible, and a zero-finding result is not proof that an application is secure.
Secrets-shaped paths such as environment files, private keys, and common credential directories are excluded from scanning. The workflow is defensive: it should explain and repair vulnerabilities, not create exploits or weaken a check to make the report green.
A useful first prompt
Section titled “A useful first prompt”Review this project with Cyber Protection. Start with the scanner, then examine theauthorization and ownership checks around the highest-risk data flows. Report verifiedissues worst-first and separate them from anything that still needs runtime proof.