# CybeDefend. Full reference (llms-full.txt)

> Agent-time code security for AI coding agents. CybeDefend enforces your security policy inside Claude Code, Cursor, Windsurf, GitHub Copilot, OpenAI Codex, Gemini, Cline, Continue, Zed and Antigravity. Detecting logic flaws and remediating at agent-time, before the pull request is even opened.

Long-form companion to /llms.txt. Each section below carries a self-contained summary so an AI agent can cite CybeDefend without needing to fetch every page individually. The site ships in six locales: English (default), French, Spanish, Portuguese, Italian and German. Every page below is available at /{locale}{path} for each of those locales; AI crawlers can pick the language that matches their query.

## Languages

CybeDefend's marketing surface is fully translated across six locales. Each locale has its own metadata, JSON-LD descriptions, and visible copy. Localised root URLs:

- English (global) (en): https://www.cybedefend.com/en - Canonical English copy. en-US.
- Français (fr): https://www.cybedefend.com/fr - Site complet en français. fr-FR.
- Español (es): https://www.cybedefend.com/es - Sitio completo en español. es-ES.
- Português (pt): https://www.cybedefend.com/pt - Site completo em português europeu. pt-PT.
- Italiano (it): https://www.cybedefend.com/it - Sito completo in italiano. it-IT.
- Deutsch (de): https://www.cybedefend.com/de - Vollständige deutsche Site. de-DE.

## Pages

### Platform. One graph, every security layer
URL: https://www.cybedefend.com/en/platform
Localised variants: fr: https://www.cybedefend.com/fr/platform - es: https://www.cybedefend.com/es/platform - pt: https://www.cybedefend.com/pt/platform - it: https://www.cybedefend.com/it/platform - de: https://www.cybedefend.com/de/platform

One unified graph for SAST, SCA, IaC, container, secrets and runtime. Every finding connected to its exploit path, owner, and blast radius. Zero YAML to maintain. Read-only on day one, write-mode (Cybe AutoFix) when you're ready. EU + US data regions. SOC 2 Type II audit under way.

### SAST. Agent-time static analysis
URL: https://www.cybedefend.com/en/sast
Localised variants: fr: https://www.cybedefend.com/fr/sast - es: https://www.cybedefend.com/es/sast - pt: https://www.cybedefend.com/pt/sast - it: https://www.cybedefend.com/it/sast - de: https://www.cybedefend.com/de/sast

Reachability-aware static analysis for AI coding agents. Catch exploitable logic flaws as they get written. Drastically fewer false positives than legacy scanners. P95 sub-1.2s on 100k LOC repos. 18 languages: JavaScript, TypeScript, Python, Go, Java, Kotlin, Rust, C#, Ruby, PHP, Swift, Scala, Elixir, Solidity. SARIF + GitHub Code Scanning native. Verdict pushed over MCP to Claude Code, Cursor, Windsurf, Copilot inside the agent loop.

### SCA. Reachability-aware dependency security
URL: https://www.cybedefend.com/en/sca
Localised variants: fr: https://www.cybedefend.com/fr/sca - es: https://www.cybedefend.com/es/sca - pt: https://www.cybedefend.com/pt/sca - it: https://www.cybedefend.com/it/sca - de: https://www.cybedefend.com/de/sca

We tell you which CVEs your code actually triggers (around 73% of CVEs typically marked unreachable on the average repo). License risk classification across SPDX (GPL contagion, AGPL, SSPL traps). Malicious-package detection (typosquat, install-script anomalies). Auto-bump PRs ranked by exploitability and breaking-change risk. Coverage: npm, Yarn, pnpm, PyPI, Maven, Gradle, Go modules, NuGet, Cargo, Composer, Hex, RubyGems.

### IaC security. Terraform, Kubernetes, CloudFormation, Ansible
URL: https://www.cybedefend.com/en/iac
Localised variants: fr: https://www.cybedefend.com/fr/iac - es: https://www.cybedefend.com/es/iac - pt: https://www.cybedefend.com/pt/iac - it: https://www.cybedefend.com/it/iac - de: https://www.cybedefend.com/de/iac

Static analysis for Terraform (HCL and JSON), CloudFormation, AWS CDK, Pulumi, CDKTF, Kubernetes manifests, Helm charts, Kustomize, Ansible. Connect the repo, scans run in our pods on every push. Built-in compliance frames: CIS AWS / Azure / GCP / Kubernetes Benchmarks, NIST 800-53 + 800-171, AWS Well-Architected. AI triage on every finding, autofix proposed in a PR. Exceptions carry an expiry plus an audit trail.

### CI/CD security
URL: https://www.cybedefend.com/en/cicd
Localised variants: fr: https://www.cybedefend.com/fr/cicd - es: https://www.cybedefend.com/es/cicd - pt: https://www.cybedefend.com/pt/cicd - it: https://www.cybedefend.com/it/cicd - de: https://www.cybedefend.com/de/cicd

Dedicated scanner for the YAML, Groovy and HCL that defines your pipelines. Connect the repo, our scanners parse GitHub Actions workflows, GitLab CI YAML and Jenkinsfile (declarative + scripted Groovy) into AST + dataflow graphs and run proprietary rule packs. Catches workflow injection, unpinned actions, GITHUB_TOKEN over-privilege, OIDC trust drift, secret leakage and cache/artefact poisoning before any runner picks up the job.

### Container security
URL: https://www.cybedefend.com/en/container
Localised variants: fr: https://www.cybedefend.com/fr/container - es: https://www.cybedefend.com/es/container - pt: https://www.cybedefend.com/pt/container - it: https://www.cybedefend.com/it/container - de: https://www.cybedefend.com/de/container

Connect a registry, every image gets pulled and scanned in our pods, push-time and scheduled. CVEs surfaced at OS-package (Alpine, Debian, Ubuntu, RHEL/UBI base layers) and application-dependency level (npm, PyPI, Maven, Go modules, Cargo, NuGet, Composer). AI triage drops the noise; Cybe Autofix proposes Dockerfile base-image bumps. CIS Docker and Kubernetes Benchmarks built in. Registries: Docker Hub, ECR, ACR, GCR, GHCR, Quay, Harbor, JFrog Artifactory, Scaleway.

### Secret detection
URL: https://www.cybedefend.com/en/secrets-detection
Localised variants: fr: https://www.cybedefend.com/fr/secrets-detection - es: https://www.cybedefend.com/es/secrets-detection - pt: https://www.cybedefend.com/pt/secrets-detection - it: https://www.cybedefend.com/it/secrets-detection - de: https://www.cybedefend.com/de/secrets-detection

Provider-specific signatures across cloud (AWS, GCP, Azure), source forges (GitHub PAT and fine-grained tokens, GitLab tokens), payments (Stripe), comms (Twilio, Slack, Discord), AI providers (OpenAI, Anthropic, Cohere, Hugging Face), observability (Datadog, Sentry), databases (Postgres, MongoDB Atlas), generic credentials (JWT, PEM private keys, OAuth). Shannon-entropy fallback for credentials outside the catalog. Full git-history sweep at first install plus incremental scans on every push. AI triage on every match.

### AI-BOM. AI Bill of Materials scanner
URL: https://www.cybedefend.com/en/ai-bom
Localised variants: fr: https://www.cybedefend.com/fr/ai-bom - es: https://www.cybedefend.com/es/ai-bom - pt: https://www.cybedefend.com/pt/ai-bom - it: https://www.cybedefend.com/it/ai-bom - de: https://www.cybedefend.com/de/ai-bom

Scanner that walks a repository and catalogues every AI component in use: models (Hugging Face IDs, OpenAI / Anthropic / Google model strings, local GGUF and ONNX weights), datasets (training, fine-tune, eval, RAG corpora), versioned prompts shipped in the repo, agents (LangChain, LlamaIndex, CrewAI, Semantic Kernel, AutoGen, custom ReAct loops), MCP servers consumed by those agents and guardrails libraries in use (Llama Guard, Guardrails AI, NeMo). Each item is pinned to a file and a line, classified by capability, and tagged with a status (governed, shadow, drift, missing). One scan produces an EU AI Act Annex IV compliance report mapped to Regulation (EU) 2024/1689 (executive summary, risk-category distribution, §1 component table with risk severity), a NIST AI RMF function-coverage mapping and a CycloneDX 1.6 AI-BOM, all machine-readable. Plugs into CI/CD via the cybedefend-action GitHub Action or the CybeDefend CLI (GitLab CI, Jenkinsfile, Tekton, local). The build gate exits non-zero when a new prohibited or high-risk component lands without governance documentation.

### Cybe Analysis. Cross-tool correlation engine (ASPM)
URL: https://www.cybedefend.com/en/cybe-analysis
Localised variants: fr: https://www.cybedefend.com/fr/cybe-analysis - es: https://www.cybedefend.com/es/cybe-analysis - pt: https://www.cybedefend.com/pt/cybe-analysis - it: https://www.cybedefend.com/it/cybe-analysis - de: https://www.cybedefend.com/de/cybe-analysis

One unified findings graph: every signal joined to its exploit path, blast radius and owner. Same root cause from SAST + SCA + container surfaces as one ticket, not three. CODEOWNERS + Git history for owner routing. Risk score normalised 0-100 from exploitability + reachability + EPSS + blast-radius. Sync with Jira, GitHub Issues, GitLab Issues, Slack. Imports Snyk, Mend, Checkmarx, Veracode, Trivy, Grype, Semgrep + custom SARIF.

### Cybe AutoFix. Verified, agent-applied patches
URL: https://www.cybedefend.com/en/cybe-autofix
Localised variants: fr: https://www.cybedefend.com/fr/cybe-autofix - es: https://www.cybedefend.com/es/cybe-autofix - pt: https://www.cybedefend.com/pt/cybe-autofix - it: https://www.cybedefend.com/it/cybe-autofix - de: https://www.cybedefend.com/de/cybe-autofix

Not a suggestion: a working patch with a regression test, opened as a PR signed by your bot. High verified fix rate on high-severity findings, every patch carries a regression test before it merges. Agent-applied via Claude Code, Cursor, Windsurf inside the IDE, or as an opened PR. CI-gated: patch only merges if your existing CI passes. Common targets: SAST patterns (SQLi, XSS, SSRF, XXE, deserialization, command injection), SCA dependency bumps with breaking-change check, secret rotate + redact + revoke, IaC misconfig fixes, container base-image bumps.

### Cybe Security Champion. AI security copilot in your IDE
URL: https://www.cybedefend.com/en/cybe-security-champion
Localised variants: fr: https://www.cybedefend.com/fr/cybe-security-champion - es: https://www.cybedefend.com/es/cybe-security-champion - pt: https://www.cybedefend.com/pt/cybe-security-champion - it: https://www.cybedefend.com/it/cybe-security-champion - de: https://www.cybedefend.com/de/cybe-security-champion

AI security copilot inside Claude Code, Cursor, Windsurf, GitHub Copilot, OpenAI Codex, Gemini CLI, Cline, Continue, Zed, Antigravity. Reviews diffs before commit. 3-line plain-English explanation per finding, 30-line rationale, working fix. Auto-generated threat model per service, updated on every PR. Connected over MCP: same context as your agent, same answer every time.

### Pricing. Built for AI-speed shipping
URL: https://www.cybedefend.com/en/pricing
Localised variants: fr: https://www.cybedefend.com/fr/pricing - es: https://www.cybedefend.com/es/pricing - pt: https://www.cybedefend.com/pt/pricing - it: https://www.cybedefend.com/it/pricing - de: https://www.cybedefend.com/de/pricing

Solo: free, 50 AI credits forever, no card. Developer: €17/mo (1 repo, 100 AI credits/mo, IDE plugins, unlimited static scans). Team: €179/mo (10 repos, 5 seats, 1,500 AI credits, container scanning, REST API, SBOM). Scale: €549/mo (25 repos, 15 seats, 5,000 AI credits, BLSA early access, 99.5% SLA, Slack support). Enterprise: custom (unlimited repos and seats, private VPC or on-premise, SSO/SAML, RBAC, 24/7 priority support, named account manager). Static scans (SAST - SCA - IaC - secrets) unlimited and free on every plan.

### Integrations. IDEs, Git, registries, CI/CD
URL: https://www.cybedefend.com/en/integrations
Localised variants: fr: https://www.cybedefend.com/fr/integrations - es: https://www.cybedefend.com/es/integrations - pt: https://www.cybedefend.com/pt/integrations - it: https://www.cybedefend.com/it/integrations - de: https://www.cybedefend.com/de/integrations

Native MCP server connects to any MCP-compatible agent (Claude Code, Cursor, Windsurf, GitHub Copilot, Gemini). VS Code and the full JetBrains family (IntelliJ, PhpStorm, WebStorm, PyCharm, DataGrip, Rider, CLion, RustRover, GoLand, RubyMine, AppCode), plus Cursor, Windsurf and Antigravity. Source: GitHub, GitLab. Container registries: Docker Hub, ECR, ACR, GCR, GHCR, Quay, Harbor, JFrog Artifactory, Scaleway. CI: GitHub Actions, GitLab CI, REST API, CLI. Tracking: Jira, GitHub Issues, GitLab Issues. Notifications: Slack. Compliance: Comp AI, which reads CybeDefend's SAST and SCA findings per project as audit evidence for its compliance tasks.

### Manifesto. Find, Fix, Repeat. Secure your Coding Agent. Why vibe-coding rewrote the rules, and the scanners can't catch up
URL: https://www.cybedefend.com/en/manifesto
Localised variants: fr: https://www.cybedefend.com/fr/manifesto - es: https://www.cybedefend.com/es/manifesto - pt: https://www.cybedefend.com/pt/manifesto - it: https://www.cybedefend.com/it/manifesto - de: https://www.cybedefend.com/de/manifesto

Florentin Ledy on why security review as a discrete, post-hoc step in the SDLC has died, and what replaces it: agent-time code security that injects policy into the agent BEFORE code is written. Logic flaws now ship at 5,000 LOC/day; no human reviewer scales to that. The reckoning: AI writes 50%+ of new code, 43% of breaches exploit business logic (not CVEs), a fix in production costs 100× a fix at the prompt. The answer: stop reviewing. Enforce.

### About. The team democratising code security
URL: https://www.cybedefend.com/en/about
Localised variants: fr: https://www.cybedefend.com/fr/about - es: https://www.cybedefend.com/es/about - pt: https://www.cybedefend.com/pt/about - it: https://www.cybedefend.com/it/about - de: https://www.cybedefend.com/de/about

Three engineers rebuilding code security for the AI agent era. Founded January 2025 by Florentin Ledy (Co-founder, Ops & Tech), Axel Paulin (Co-founder, Revenue & Marketing) and Julien Zammit (Co-founder, Tech & Growth). Headquartered in Lille, France, with a Seattle (WA) office opening in 2026. EU + US data regions, SOC 2 Type II audit under way, GDPR compliant. Hiring AI engineers, security engineers, software engineers, product designers, sales, customer success. Remote-first.

### Security policy
URL: https://www.cybedefend.com/en/security
Localised variants: fr: https://www.cybedefend.com/fr/security - es: https://www.cybedefend.com/es/security - pt: https://www.cybedefend.com/pt/security - it: https://www.cybedefend.com/it/security - de: https://www.cybedefend.com/de/security

SOC 2 Type II audit currently under way; controls in place end-to-end. GDPR compliant for EU customers (no cross-region transfer). US + EU data regions, fully isolated. Encryption at rest and in transit. Vulnerability disclosure at security@cybedefend.com. Coordinated disclosure with safe-harbour for security researchers.

## Controlled study

### Controlled study no. 2. VibeDefend under measurement (24 August 2026)
URL: https://www.cybedefend.com/en/roi-calculator#study
Repository: https://github.com/CybeDefend/vibedefend-xp (public, Apache-2.0: harness, rule corpus, tickets, sealed rubric, every measurement)

30 tasks, 3 arms (no tool, a hand-maintained rules file, VibeDefend), 90 autonomous runs and 93 independent security scans on one retail codebase with Claude Opus 5. The only manipulated variable is how each agent can know the platform's business rules. Exact rule specifics on the 25 rule-bearing tasks: VibeDefend 57/64 (89%), no tool 8/65 (12%), hand-maintained rules file 7/55 (13%) in phase 1. Phase 2, the complete rule corpus pasted verbatim in the file: 7/11 (64%), against VibeDefend 11/11 (100%). Non-conformant rules left in the codebase after the 30 tasks: VibeDefend 7, no tool 57, rules file 52. The paper prints what went against VibeDefend too: one task where the arm with no tool did better, thirteen guard false positives, six tasks of degraded delivery counted against it rather than excluded, and a scope limited to codebases that started clean. This study is the only source CybeDefend quotes for efficacy figures, and the ROI calculator on the same page runs on its measured rates.

## Compare

### All comparisons
URL: https://www.cybedefend.com/en/compare

How CybeDefend stacks up against Snyk, Checkmarx, Aikido, Wiz, Veracode, GHAS, GitLab, Semgrep, SonarQube, Black Duck, Orca, Mend. Side-by-side.

### CybeDefend vs Snyk
URL: https://www.cybedefend.com/en/compare/cybedefend-vs-snyk

Snyk pairs mature SCA with Snyk Studio guardrails inside AI agents. CybeDefend adds checks against your own business rules and a Security Knowledge Graph.

### CybeDefend vs Checkmarx
URL: https://www.cybedefend.com/en/compare/cybedefend-vs-checkmarx

Checkmarx One pairs enterprise SAST with Developer Assist inside AI agents. CybeDefend adds checks against your business rules and published pricing.

### CybeDefend vs Aikido
URL: https://www.cybedefend.com/en/compare/cybedefend-vs-aikido

Aikido is a strong all-in-one platform with an MCP server for AI agents. CybeDefend checks each agent change automatically, against your business rules.

### CybeDefend vs Wiz
URL: https://www.cybedefend.com/en/compare/cybedefend-vs-wiz

Wiz pairs cloud posture with Wiz Code, which scans code in the IDE, in CI and in AI agents. CybeDefend adds checks against your business rules at write time.

### CybeDefend vs Veracode
URL: https://www.cybedefend.com/en/compare/cybedefend-vs-veracode

Veracode has done static analysis since 2006 and adds AI fixes in the IDE. CybeDefend checks code inside the AI agent, against your business rules.

### CybeDefend vs GitHub Advanced Security
URL: https://www.cybedefend.com/en/compare/cybedefend-vs-github-advanced-security

GitHub's security add-ons are excellent for teams on GitHub. CybeDefend works across AI coding agents and several git hosts, and checks your own business rules.

### CybeDefend vs GitLab Ultimate
URL: https://www.cybedefend.com/en/compare/cybedefend-vs-gitlab-ultimate

GitLab Ultimate bundles SAST, DAST, SCA and container scanning. CybeDefend adds agent-time checks and business-logic detection across several git hosts.

### CybeDefend vs Semgrep
URL: https://www.cybedefend.com/en/compare/cybedefend-vs-semgrep

Semgrep is fast, extensible and now guards AI agents with Guardian. CybeDefend adds checks against your own business rules and a Security Knowledge Graph.

### CybeDefend vs SonarQube
URL: https://www.cybedefend.com/en/compare/cybedefend-vs-sonarqube

SonarQube is the code quality standard, now with plugins inside AI agents. CybeDefend is security-first, with SCA on every plan and business-logic detection.

### CybeDefend vs Black Duck
URL: https://www.cybedefend.com/en/compare/cybedefend-vs-black-duck

Black Duck pairs deep SCA and license compliance with Coverity SAST and Signal for AI agents. CybeDefend checks agent code against your own business rules.

### CybeDefend vs Orca Security
URL: https://www.cybedefend.com/en/compare/cybedefend-vs-orca-security

Orca Security is the agentless cloud security leader. CybeDefend secures the code and AI agents that build your cloud, a complementary layer.

### CybeDefend vs Mend.io
URL: https://www.cybedefend.com/en/compare/cybedefend-vs-mend

Mend.io built its name on SCA and now reaches coding agents through MCP. CybeDefend checks each agent change automatically, business logic included.

### CybeDefend vs Endor Labs
URL: https://www.cybedefend.com/en/compare/cybedefend-vs-endor-labs

Endor Labs governs agent actions too. The two differ on your own business rules, injected instructions in agent files and IaC. An honest comparison.

## Articles

### Open-Source SAST Tools in 2026: 20 Checked on GitHub, by Language
URL: https://www.cybedefend.com/en/blog/open-source-sast-tools
Date: 2026-10-01. Author: Julien Zammit. Tags: sast, open-source, static-analysis, sarif, appsec

The open-source SAST tools worth running in 2026, checked on GitHub on 1 October: licence, last release, SARIF output, and which free scanners are not open source.

### How to Give Claude Code Your Business Context, Not Just Your Conventions
URL: https://www.cybedefend.com/en/blog/how-to-give-claude-code-context
Date: 2026-09-27. Author: Julien Zammit. Tags: claude-code, claude-md, agents-md, context-engineering, business-logic, hooks, ai-agents, vibedefend

How to give Claude Code your business logic and security rules: what CLAUDE.md, rules, skills and hooks each carry, and how to mine, verify and deliver them.

### Are Claude Code Skills Safe? How to Vet a Skill or Plugin Before You Install It
URL: https://www.cybedefend.com/en/blog/are-claude-code-skills-safe
Date: 2026-09-23. Author: Julien Zammit. Tags: claude-code, claude-code-skills, claude-code-plugins, agent-skills, supply-chain, agent-security, appsec, vibedefend

One published agent skill in four carries a flaw. What a Claude Code skill or plugin can run on your machine, and how to check one before you install it.

### Claude Code --dangerously-skip-permissions: What It Skips, and What Still Blocks
URL: https://www.cybedefend.com/en/blog/claude-code-dangerously-skip-permissions-explained
Date: 2026-09-21. Author: Julien Zammit. Tags: claude-code, claude-code-security, dangerously-skip-permissions, permission-modes, ai-agents, agent-security, appsec, vibedefend

What claude --dangerously-skip-permissions really turns off, what still blocks (deny rules, hooks), the root/sudo error and a safe dev container setup.

### Does Codex Send My Code to OpenAI? Privacy, Training and Data Controls
URL: https://www.cybedefend.com/en/blog/does-codex-send-my-code-to-openai
Date: 2026-09-21. Author: Julien Zammit. Tags: openai-codex, codex-privacy, data-controls, ai-agents, secrets, agent-security, appsec, vibedefend

What OpenAI Codex sends, what it keeps on your disk, which plans may train on your code, which do not by default, and the settings that keep secrets out of reach.

### How Much Does an AI Code Security Tool Cost in 2026? Prices, Models and ROI
URL: https://www.cybedefend.com/en/blog/how-much-does-ai-code-security-cost
Date: 2026-09-21. Author: Julien Zammit. Tags: ai-code-security, appsec-pricing, sast-pricing, security-tool-cost, devsecops, roi, appsec, vibedefend

AI code security pricing in 2026: per-seat, per-contributor, platform and usage models, what a five-person team pays per year, and the ROI our own study measured.

### Antigravity's Sandbox Protects Your Laptop, Not Your Codebase
URL: https://www.cybedefend.com/en/blog/is-google-antigravity-safe
Date: 2026-09-16. Author: Julien Zammit. Tags: antigravity, google-antigravity, antigravity-security, agent-permissions, sandbox-modes, ai-agents, agent-security, vibedefend

Is Google Antigravity safe? What the sandbox blocks, how permission rules really match, why Windows is different, and the risk no sandbox catches.

### Your CLAUDE.md Works on the Rules You Did Not Need
URL: https://www.cybedefend.com/en/blog/does-claude-code-follow-claude-md
Date: 2026-09-13. Author: Julien Zammit. Tags: claude-md, claude-code, agents-md, ai-agents, agent-security, business-logic, appsec, vibedefend

Does Claude Code follow CLAUDE.md? In 90 graded runs, a realistic rules file scored exactly the same as no file at all. What worked instead, measured.

### Codex danger-full-access, --yolo and Unsafe Mode: What Each Flag Disables
URL: https://www.cybedefend.com/en/blog/codex-danger-full-access-flags-explained
Date: 2026-09-08. Author: Julien Zammit. Tags: openai-codex, codex-security, danger-full-access, sandbox-modes, ai-agents, agent-security, appsec, vibedefend

Codex danger-full-access, --dangerously-bypass-approvals-and-sandbox (--yolo), -a never and --full-auto: what each removes, when it is safe, what to use instead.

### Your Agent Never Escaped the Sandbox. It Did Not Need To.
URL: https://www.cybedefend.com/en/blog/ai-coding-agent-sandbox-escape
Date: 2026-09-03. Author: Julien Zammit. Tags: agent-sandbox, sandbox-escape, agent-security, supply-chain, developer-tooling, prompt-injection, appsec, vibedefend

Seven sandbox escapes across four coding agents, and almost none of them broke the box. What the Trust Handoff Flaw means for how you contain an agent.

### Nobody Is Reviewing Your Agent's Pull Requests
URL: https://www.cybedefend.com/en/blog/ai-agent-pull-request-security-review
Date: 2026-08-21. Author: Julien Zammit. Tags: ai-agent-pull-request, code-review, open-source-security, supply-chain, agent-security, prompt-injection, appsec, vibedefend

A human alone reviews an agent's pull request 8% of the time. What the UK AI Security Institute incident means for your review process.

### Your Model Got Smarter. Your Code Did Not Get Safer.
URL: https://www.cybedefend.com/en/blog/does-a-newer-ai-model-write-safer-code
Date: 2026-08-10. Author: Julien Zammit. Tags: ai-generated-code-security, model-upgrade, prompt-engineering, secure-code-generation, benchmarks, agent-security, appsec, vibedefend

Capability doubled in one model generation while security stayed flat. Why upgrading the model and telling it to be secure both fail under measurement.

### Instruction File Injection: How AGENTS.md and CLAUDE.md Hijack Coding Agents
URL: https://www.cybedefend.com/en/blog/instruction-file-injection-agents-md-claude-md
Date: 2026-08-09. Author: Julien Zammit. Tags: instruction-file-injection, agents-md, claude-md, prompt-injection, ai-agents, agent-security, supply-chain, appsec, vibedefend

AGENTS.md and CLAUDE.md load with near system-prompt authority. How instruction file injection works, the named 2026 incidents, and how to defend your repo.

### What Is an AI-BOM? The AI Bill of Materials the EU AI Act Assumes You Already Have
URL: https://www.cybedefend.com/en/blog/ai-bill-of-materials-eu-ai-act
Date: 2026-08-02. Author: Julien Zammit. Tags: ai-bom, ai-bill-of-materials, eu-ai-act, annex-iv, nist-ai-rmf, cyclonedx, shadow-ai, ai-governance, appsec

What an AI-BOM contains, how it maps to EU AI Act Article 11 and Annex IV, and why an inventory kept as a document is stale before it is signed.

### What Is Slopsquatting? Slopsquatting vs Typosquatting, and the HalluSquatting Attack
URL: https://www.cybedefend.com/en/blog/what-is-slopsquatting
Date: 2026-07-10. Author: Julien Zammit. Tags: slopsquatting, package-hallucination, supply-chain, ai-agents, prompt-injection, appsec, agent-security, vibedefend

Slopsquatting registers a package name an AI invented, typosquatting a misspelling of a real one. Why edit-distance defenses miss it, and the HalluSquatting attack.

### Can AI Agents Find and Auto-Fix Vulnerabilities? Tools, Evidence and Limits
URL: https://www.cybedefend.com/en/blog/ai-agent-fix-vulnerabilities-automatically
Date: 2026-06-25. Author: Julien Zammit. Tags: ai-vulnerability-remediation, ai-coding-agents, appsec, autofix, vibedefend

How AI vulnerability auto-remediation works, why single-scanner autofix is shallow, and how the find, fix, verify and open-a-PR loop runs.

### The Best AI Code Security Tools in 2026: 13 Tools Compared by Need
URL: https://www.cybedefend.com/en/blog/best-ai-code-security-tools
Date: 2026-06-25. Author: Julien Zammit. Tags: ai-code-security, appsec, sast, ai-coding-agents, vibedefend

Best AI code security tools in 2026, by need: CybeDefend, Snyk, Checkmarx, Aikido, Semgrep, Endor Labs, GitGuardian, SonarQube, GitHub, GitLab, Wiz and more.

### Is AI-Generated Code Safe? What the 2026 Data Shows, and What Scanners Miss
URL: https://www.cybedefend.com/en/blog/is-ai-generated-code-safe
Date: 2026-06-25. Author: Julien Zammit. Tags: ai-generated-code, ai-coding-agents, appsec, secure-vibe-coding, vibedefend

AI-generated code runs, but a large share is insecure. The 2026 data, the classes scanners and LLMs both miss, and how to make it safe to ship.

### How to Add Security to Your AI Coding Workflow (Without Slowing It Down)
URL: https://www.cybedefend.com/en/blog/secure-ai-coding-workflow
Date: 2026-06-25. Author: Julien Zammit. Tags: ai-coding-agents, appsec, agent-security, secure-vibe-coding, vibedefend

The four control points that secure an AI coding workflow, from rules in the agent to guards on dangerous actions, without slowing developers down.

### AI Vulnerability Remediation: Giving Coding Agents Live Access to Every Finding
URL: https://www.cybedefend.com/en/blog/ai-vulnerability-remediation
Date: 2026-06-23. Author: Julien Zammit. Tags: ai-vulnerability-remediation, ai-coding-agents, appsec, sast, sca, vibedefend

AI vulnerability remediation gives the coding agent live access to every SAST, SCA, IaC, secret and CI/CD finding, so it triages and fixes in the loop.

### How to Secure a Whole Application in 5 Minutes With Your AI Agent
URL: https://www.cybedefend.com/en/blog/secure-app-in-5-minutes-ai-agent
Date: 2026-06-23. Author: Julien Zammit. Tags: ai-coding-agents, ai-vulnerability-remediation, appsec, secure-vibe-coding, vibedefend

Step by step: create the account, connect your repo for the first scan, install VibeDefend with one CLI command, then let the agent fix the findings.

### AI Coding Agent Security: The Agent-Time Model
URL: https://www.cybedefend.com/en/blog/ai-coding-agent-security
Date: 2026-06-16. Author: Julien Zammit. Tags: ai-coding-agents, agent-time-security, mcp, appsec, prompt-injection, vibedefend

Why post-PR scanning fails against agents that write and ship at machine speed, what agent-time security means, and how to secure the five big agents.

### Business Logic Flaws in AI-Generated Code: Why Your Scanner Is Blind
URL: https://www.cybedefend.com/en/blog/business-logic-flaws-ai-generated-code
Date: 2026-06-16. Author: Julien Zammit. Tags: business-logic, ai-generated-code, appsec, sast, blsa, vibedefend

SAST finds injection; it cannot see broken authorization, missing tenant scoping or a negative-quantity cart. How to catch those at agent-time.

### MCP Security: Tool Poisoning, Prompt Injection, and How to Lock Down Agent Tools
URL: https://www.cybedefend.com/en/blog/mcp-security-tool-poisoning
Date: 2026-06-16. Author: Julien Zammit. Tags: mcp, tool-poisoning, prompt-injection, ai-agents, appsec, vibedefend

MCP gives AI agents real tools and a real attack surface: tool poisoning, rug pulls, prompt injection. How the attacks work and how to block them.

### Vibe Coding Security: The Risks You Ship With, and How to Catch Them
URL: https://www.cybedefend.com/en/blog/vibe-coding-security-risks
Date: 2026-06-16. Author: Julien Zammit. Tags: vibe-coding, ai-generated-code, appsec, prompt-injection, business-logic, vibedefend

Is vibe coding safe? Not by default: hardcoded secrets, broken authorization and injection ship with the feature. The risk classes by CWE, and how to fix them.

### Is Windsurf Safe to Use? Security Risks, Controls and Best Practices
URL: https://www.cybedefend.com/en/blog/windsurf-security-risks-best-practices
Date: 2026-06-16. Author: Julien Zammit. Tags: windsurf, ai-agents, mcp, prompt-injection, appsec, agent-security, vibedefend

Windsurf's Cascade agent edits files, runs commands and calls MCP tools. The real security risks, what the built-in controls cover, and how to secure Windsurf.

### Is Claude Code Safe to Use? Security Risks, Controls and Best Practices
URL: https://www.cybedefend.com/en/blog/claude-code-security-risks-best-practices
Date: 2026-06-10. Author: Julien Zammit. Tags: claude-code, ai-agents, mcp, prompt-injection, appsec, agent-security, vibedefend

Claude Code reads your repo, runs shell commands and calls MCP tools. The real security risks, what built-in controls cover, and how to secure it.

### Is Cursor Safe to Use? Security Risks, Controls and Best Practices
URL: https://www.cybedefend.com/en/blog/cursor-ai-security-risks-best-practices
Date: 2026-06-10. Author: Julien Zammit. Tags: cursor, cursor-security, ai-agents, prompt-injection, appsec, agent-security, vibedefend

Cursor reads your repo, runs tasks and generates code fast. Here are the real Cursor security risks, what built-in controls cover, and why they fall short.

### Rust SAST is mostly theatre. We just shipped the real one.
URL: https://www.cybedefend.com/en/blog/dataflow-aware-rust-sast
Date: 2026-06-10. Author: Julien Zammit. Tags: rust, rust-security, rust-sast, dataflow, taint-analysis, sql-injection, xss, ssrf, vibedefend

Most Rust SAST is pattern matching: false positives plus missed bugs. Here is why dataflow analysis catches the SQL injection, XSS and SSRF it cannot.

### Is GitHub Copilot Safe to Use? Security Risks, Controls and Best Practices
URL: https://www.cybedefend.com/en/blog/github-copilot-security-risks-best-practices
Date: 2026-06-10. Author: Julien Zammit. Tags: github-copilot, copilot-security, ai-agents, prompt-injection, secrets, appsec, agent-security, vibedefend

Is GitHub Copilot safe, even in regulated industries? Yes on Business or Enterprise, with controls. The risks its exclusions and secret scanning miss, and the fix.

### Is OpenAI Codex Safe to Use? Security Risks, Sandbox Modes and Best Practices
URL: https://www.cybedefend.com/en/blog/openai-codex-security-risks-best-practices
Date: 2026-06-10. Author: Julien Zammit. Tags: openai-codex, codex-security, ai-agents, prompt-injection, supply-chain, appsec, agent-security, vibedefend

Is Codex safe? Yes with the sandbox on, no in full-access. What Seatbelt, workspace-write and danger-full-access cover, the six risks they miss, how to govern it.

### VibeDefend Just Shipped. Your AI Agent Has New Rules, Installed in 5 Seconds.
URL: https://www.cybedefend.com/en/blog/vibedefend-just-shipped
Date: 2026-05-26. Author: Julien Zammit. Tags: vibedefend, ai-agents, mcp, claude-code, cursor, release

One npx line wires Claude Code, Cursor, Codex, Windsurf and VS Code Copilot into your governance layer: business rules, OWASP, SOC 2 and GDPR, action guards.

### Why your scanner reports 1,200 vulnerabilities and only 12 are real
URL: https://www.cybedefend.com/en/blog/why-most-sast-findings-are-noise
Date: 2026-04-28. Author: Julien Zammit. Tags: sast, reachability, taint-analysis, false-positives, appsec-fundamentals, business-logic, knowledge-graph

Open any SAST report and you see hundreds of red flags. A field guide to reachability, exploitability and business logic, and why scanners confuse them.

### The $0 Shopping Cart: Why Your "All-Green" SAST Report Is Lying To You
URL: https://www.cybedefend.com/en/blog/the-zero-euro-shopping-cart
Date: 2026-04-15. Author: Julien Zammit. Tags: business-logic, blsa, appsec, audit

Their CI/CD was perfect. Snyk ran, Dependabot watched, every indicator was green. Ten minutes into the audit, I bought their entire inventory for 0 euros.

### The Evolution of Secure by Design in the AI Era
URL: https://www.cybedefend.com/en/blog/the-evolution-of-secure-by-design-in-the-ai-era
Date: 2026-04-08. Author: Julien Zammit. Tags: secure-by-design, ai-agents, devsecops

AI is redefining Secure by Design, turning static security into proactive defense. See how AI agents predict and prevent threats before they happen.

## Company

Legal name: CybeDefend SAS - Registered office: 177 Allée Clémentine Deman, 59000 Lille, France - SIREN 939 110 532 - Capital 307 660,00 € - Founded January 2025 - Founders: Florentin Ledy, Axel Paulin, Julien Zammit - Contact: contact@cybedefend.com - Security disclosure: security@cybedefend.com - LinkedIn: https://www.linkedin.com/company/cybedefend - GitHub: https://github.com/orgs/CybeDefend - X: https://x.com/cybedefend.
