cd /news/ai-agents/i-built-cybermira-an-ai-powered-cybe… · home › topics › ai-agents › article
[ARTICLE · art-142574] src=dev.to ↗ pub= topic=ai-agents verified=true sentiment=↑ positive

I built CyberMira: An AI-Powered Cybersecurity Assistant Grounded in Sanity

A developer built CyberMira, an AI-powered cybersecurity assistant that retrieves structured security knowledge from a Sanity Knowledge Base via Sanity Context MCP before passing it to Gemini to generate answers. The knowledge base holds 36 structured entries covering vulnerabilities, attack patterns, detection techniques, mitigations, and OWASP categories, with a React/Vite frontend and FastAPI backend. The developer says the design keeps Gemini from being the source of the cybersecurity knowledge, retrieving evidence first and generating the explanation second.

by read3 min views2 publishedSep 30, 2026

This is a submission for the Sanity Challenge, Path One: Ship an Agent That Queries Real Content

Cybersecurity questions often have answers scattered across standards, vulnerability references, attack patterns, and mitigation guidance.

CyberMira is an AI-powered cybersecurity assistant for developers that answers questions using a structured cybersecurity Knowledge Base instead of relying only on a language model's general knowledge.

The Knowledge Base currently contains 36 structured entries covering:

A developer can ask a question such as:

How can I prevent broken object-level authorization in a REST API?

CyberMira identifies the relevant knowledge areas, retrieves the corresponding content through Sanity Context MCP, and gives that evidence to Gemini to generate the final answer.

The goal is simple: retrieve structured security knowledge first, then generate the explanation.

The main architecture is:

The important part is that Gemini is not the source of the cybersecurity knowledge. The application first retrieves evidence from the Sanity Knowledge Base.

Retrieval Flow

Try the deployed application:

cybermira

Or see the live demo here :

The application is publicly accessible and does not require an account.

AI-powered cybersecurity knowledge for developers.

CyberMira is an AI-powered cybersecurity assistant for developers. It combines a structured cybersecurity knowledge base with AI to provide practical, evidence-grounded security guidance.

Unlike a general-purpose chatbot, CyberMira retrieves relevant cybersecurity knowledge from a curated Sanity Knowledge Base before generating an answer. The knowledge base connects vulnerabilities, technologies, attack patterns, detection techniques, mitigations, OWASP categories, and trusted security references.

A typical CyberMira request follows this flow:

Developer question
        |
        v
React / Vite frontend
        |
        v
FastAPI backend
        |
        v
Relevant knowledge paths
        |
        v
Sanity Context MCP
        |
        v
CyberMira Knowledge Base
        |
        v
Structured security evidence
        |
        v
Gemini
        |
        v
Grounded security answer

The backend first identifies the knowledge areas relevant to the developer's question. It then retrieves structured evidence through Sanity Context before passing that evidence to the language model.

This architecture keeps the cybersecurity knowledge separate…

Sanity is the structured knowledge layer behind CyberMira.

I created schemas for cybersecurity concepts instead of storing one large block of text. For example, vulnerabilities, technologies, attack patterns, detection techniques, mitigations, and OWASP categories are modeled as separate content types.

That content is indexed into a Sanity Knowledge Base.

CyberMira then accesses it through Sanity Context MCP.

The backend uses the MCP tools to retrieve the relevant knowledge:

result = await call_mcp_tool( 
 "knowledge_base_read", 
 { 
   "knowledgeBase": KNOWLEDGE_BASE_ID, :
   "paths": paths, 
 }, 
)

The application first selects relevant knowledge paths based on the developer's question:

paths = select_paths(request.message)

evidence = await read_knowledge(paths)

answer = await generate_answer(
    question=request.message,
    evidence=evidence,
)

For example, a question about API authorization can retrieve areas such as:

access_control

attack_patterns

mitigation

The retrieved content is then provided to Gemini as evidence for the answer.

This makes the roles of the components explicit:

Sanity 
  → structured cybersecurity knowledge 
Sanity Context MCP 
  → retrieval interface 
FastAPI 
  → application and retrieval logic 
Gemini 
  → explanation and answer generation 
React 
  → developer-facing interface

Sanity is therefore not just being used as a CMS. Its structured content and Knowledge Base are part of the reasoning pipeline.

No separate agent-session transcript is included in this submission.

The implementation was developed as a hands-on engineering workflow, with the final application, source code, Sanity schemas, Knowledge Base, and retrieval pipeline available for inspection.

The most interesting part of this project was not connecting an LLM to a database.

It was designing the boundary between structured knowledge and generated answers.

Sanity Context MCP provided a clean way to expose a curated Knowledge Base to the application, while the backend remained responsible for deciding what to retrieve and how that evidence should be used.

The result is a cybersecurity assistant where the knowledge layer is structured, inspectable, and separated from the language model.

── more in #ai-agents 4 stories · sorted by recency
── more on @cybermira 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/i-built-cybermira-an…] indexed:0 read:3min 2026-09-30 · —