Skip to content
Start here

POPULAR GUIDES

    FROM THE DOCUMENTATION

    Open this guide ↗
    ↑ ↓ select ↵ open esc closeV3Code Docs
    The editoreditor

    Cyber Protection

    ↗ View as Markdown

    Help the agent notice security risks it might otherwise overlook.

    Cyber Protection is an extra review aid for the current agent. It helps the agent surface possible security concerns it might otherwise overlook while reading or changing a project. Open the model picker in the composer and turn on Cyber Protection before asking for a security-focused review.

    It is not a promise that the project is secure, a complete vulnerability audit, or a replacement for experienced human review, runtime testing, and dedicated security tools.

    Cyber Protection is an option in the composer’s model picker, not a separate chat mode. Screenshot supplied September 17, 2026.
    Model picker options with the Cyber Protection toggle below Design

    Cyber Protection is an option in the composer’s model picker, not a separate chat mode. Screenshot supplied September 17, 2026.

    1. Open the model picker in the composer.
    2. Enable Cyber Protection.
    3. Describe the part of the project you want reviewed and any specific concerns.
    4. Ask the agent to separate confirmed findings from leads that still need investigation.

    The expected result is a review with evidence and limitations—not a security certificate.

    The agent can start with the built-in security_scan tool. On supported workspace source, the scanner builds a code-property graph and looks for suspicious paths from untrusted data toward dangerous operations. It can flag patterns associated with SQL and command injection, cross-site scripting, server-side request forgery, path traversal, prototype pollution, unsafe deserialization, regular-expression denial of service, hardcoded secrets, and weak cryptography.

    The agent is then prompted to consider concerns a pattern scanner cannot decide by itself, such as ownership checks, authorization, rate limits, payment or role logic, and other application-specific trust boundaries. These are review leads, not automatically verified vulnerabilities.

    Potential findings include a location, severity, explanation, and suggested repair. A scan journal under .v3code/ lets later runs distinguish new, fixed, and still-open findings.

    The scanner currently models JavaScript and TypeScript most deeply, with partial Python coverage. Unsupported languages and framework-specific behavior still require manual review. False positives and missed issues are possible, and a zero-finding result is not proof that an application is secure.

    Secrets-shaped paths such as environment files, private keys, and common credential directories are excluded from scanning. The workflow is defensive: it should explain and repair vulnerabilities, not create exploits or weaken a check to make the report green.

    Review this project with Cyber Protection. Start with the scanner, then examine the
    authorization and ownership checks around the highest-risk data flows. Report verified
    issues worst-first and separate them from anything that still needs runtime proof.