# Cyber Protection Cyber Protection is an extra review aid for the current agent. It helps the agent surface possible security concerns it might otherwise overlook while reading or changing a project. Open the model picker in the composer and turn on **Cyber Protection** before asking for a security-focused review. It is not a promise that the project is secure, a complete vulnerability audit, or a replacement for experienced human review, runtime testing, and dedicated security tools. ## Turn it on ![Model picker options with the Cyber Protection toggle below Design](/images/composer-options-0098.png) Cyber Protection is an option in the composer’s model picker, not a separate chat mode. Screenshot supplied September 17, 2026. 1. Open the model picker in the composer. 2. Enable **Cyber Protection**. 3. Describe the part of the project you want reviewed and any specific concerns. 4. Ask the agent to separate confirmed findings from leads that still need investigation. The expected result is a review with evidence and limitations—not a security certificate. ## What changes when it is on The agent can start with the built-in `security_scan` tool. On supported workspace source, the scanner builds a code-property graph and looks for suspicious paths from untrusted data toward dangerous operations. It can flag patterns associated with SQL and command injection, cross-site scripting, server-side request forgery, path traversal, prototype pollution, unsafe deserialization, regular-expression denial of service, hardcoded secrets, and weak cryptography. The agent is then prompted to consider concerns a pattern scanner cannot decide by itself, such as ownership checks, authorization, rate limits, payment or role logic, and other application-specific trust boundaries. These are review leads, not automatically verified vulnerabilities. ## Read the results critically Potential findings include a location, severity, explanation, and suggested repair. A scan journal under `.v3code/` lets later runs distinguish new, fixed, and still-open findings. The scanner currently models JavaScript and TypeScript most deeply, with partial Python coverage. Unsupported languages and framework-specific behavior still require manual review. False positives and missed issues are possible, and a zero-finding result is not proof that an application is secure. Secrets-shaped paths such as environment files, private keys, and common credential directories are excluded from scanning. The workflow is defensive: it should explain and repair vulnerabilities, not create exploits or weaken a check to make the report green. ## A useful first prompt ```text Review this project with Cyber Protection. Start with the scanner, then examine the authorization and ownership checks around the highest-risk data flows. Report verified issues worst-first and separate them from anything that still needs runtime proof. ``` > Tip: > > Run the scan again after the fixes. The journal comparison is more useful than treating > one report as a security verdict.