{"slug": "i-built-cybermira-an-ai-powered-cybersecurity-assistant-grounded-in-sanity", "title": "I built CyberMira: An AI-Powered Cybersecurity Assistant Grounded in Sanity", "summary": "A developer built CyberMira, an AI-powered cybersecurity assistant that retrieves structured security knowledge from a Sanity Knowledge Base via Sanity Context MCP before passing it to Gemini to generate answers. The knowledge base holds 36 structured entries covering vulnerabilities, attack patterns, detection techniques, mitigations, and OWASP categories, with a React/Vite frontend and FastAPI backend. The developer says the design keeps Gemini from being the source of the cybersecurity knowledge, retrieving evidence first and generating the explanation second.", "body_md": "*This is a submission for the [Sanity Challenge, Path One: Ship an Agent That Queries Real Content](https://dev.to/challenges/sanity-2026-09-16)*\n\nCybersecurity questions often have answers scattered across standards, vulnerability references, attack patterns, and mitigation guidance.\n\n**CyberMira** is an AI-powered cybersecurity assistant for developers that answers questions using a structured cybersecurity Knowledge Base instead of relying only on a language model's general knowledge. \n\nThe Knowledge Base currently contains **36 structured entries** covering: \n\nA developer can ask a question such as:\n\nHow can I prevent broken object-level authorization in a REST API?\n\nCyberMira identifies the relevant knowledge areas, retrieves the corresponding content through Sanity Context MCP, and gives that evidence to Gemini to generate the final answer.\n\nThe goal is simple: **retrieve structured security knowledge first, then generate the explanation.**\n\nThe main architecture is:\n\nThe important part is that Gemini is not the source of the cybersecurity knowledge. The application first retrieves evidence from the Sanity Knowledge Base.\n\n**Retrieval Flow**\n\nTry the deployed application:\n\n[cybermira](https://cybermira.onrender.com)\n\nOr see the live demo here :\n\nThe application is publicly accessible and does not require an account.\n\nAI-powered cybersecurity knowledge for developers.\n\nCyberMira is an AI-powered cybersecurity assistant for developers. It combines a structured cybersecurity knowledge base with AI to provide practical, evidence-grounded security guidance.\n\nUnlike a general-purpose chatbot, CyberMira retrieves relevant cybersecurity knowledge from a curated Sanity Knowledge Base before generating an answer. The knowledge base connects vulnerabilities, technologies, attack patterns, detection techniques, mitigations, OWASP categories, and trusted security references.\n\nA typical CyberMira request follows this flow:\n\n```\nDeveloper question\n        |\n        v\nReact / Vite frontend\n        |\n        v\nFastAPI backend\n        |\n        v\nRelevant knowledge paths\n        |\n        v\nSanity Context MCP\n        |\n        v\nCyberMira Knowledge Base\n        |\n        v\nStructured security evidence\n        |\n        v\nGemini\n        |\n        v\nGrounded security answer\n```\n\nThe backend first identifies the knowledge areas relevant to the developer's question. It then retrieves structured evidence through Sanity Context before passing that evidence to the language model.\n\nThis architecture keeps the cybersecurity knowledge separate…\n\nSanity is the structured knowledge layer behind CyberMira.\n\nI created schemas for cybersecurity concepts instead of storing one large block of text. For example, vulnerabilities, technologies, attack patterns, detection techniques, mitigations, and OWASP categories are modeled as separate content types.\n\nThat content is indexed into a **Sanity Knowledge Base.**\n\nCyberMira then accesses it through **Sanity Context MCP**.\n\nThe backend uses the MCP tools to retrieve the relevant knowledge:\n\n```\nresult = await call_mcp_tool( \n \"knowledge_base_read\", \n { \n   \"knowledgeBase\": KNOWLEDGE_BASE_ID, :\n   \"paths\": paths, \n }, \n)\n```\n\nThe application first selects relevant knowledge paths based on the developer's question:\n\n```\npaths = select_paths(request.message)\n\nevidence = await read_knowledge(paths)\n\nanswer = await generate_answer(\n    question=request.message,\n    evidence=evidence,\n)\n```\n\nFor example, a question about API authorization can retrieve areas such as:\n\n`access_control`\n\nattack_patterns\n\nmitigation\n\nThe retrieved content is then provided to Gemini as evidence for the answer.\n\nThis makes the roles of the components explicit:\n\n```\nSanity \n  → structured cybersecurity knowledge \nSanity Context MCP \n  → retrieval interface \nFastAPI \n  → application and retrieval logic \nGemini \n  → explanation and answer generation \nReact \n  → developer-facing interface\n```\n\nSanity is therefore not just being used as a CMS. Its structured content and Knowledge Base are part of the reasoning pipeline.\n\nNo separate agent-session transcript is included in this submission.\n\nThe implementation was developed as a hands-on engineering workflow, with the final application, source code, Sanity schemas, Knowledge Base, and retrieval pipeline available for inspection.\n\nThe most interesting part of this project was not connecting an LLM to a database.\n\nIt was designing the **boundary between structured knowledge and generated answers**.\n\nSanity Context MCP provided a clean way to expose a curated Knowledge Base to the application, while the backend remained responsible for deciding what to retrieve and how that evidence should be used.\n\nThe result is a cybersecurity assistant where the knowledge layer is structured, inspectable, and separated from the language model.", "url": "https://wpnews.pro/news/i-built-cybermira-an-ai-powered-cybersecurity-assistant-grounded-in-sanity", "canonical_source": "https://dev.to/alphonsekazadi/i-built-cybermira-an-ai-powered-cybersecurity-assistant-grounded-in-sanity-25ih", "published_at": "2026-09-30 15:03:22+00:00", "updated_at": "2026-09-30 15:16:54.410340+00:00", "lang": "en", "topics": ["ai-agents", "ai-tools", "agent-protocols", "ai-products", "developer-tools"], "entities": ["CyberMira", "Sanity", "Sanity Context MCP", "Gemini", "FastAPI", "React", "Vite", "OWASP"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/i-built-cybermira-an-ai-powered-cybersecurity-assistant-grounded-in-sanity", "markdown": "https://wpnews.pro/news/i-built-cybermira-an-ai-powered-cybersecurity-assistant-grounded-in-sanity.md", "text": "https://wpnews.pro/news/i-built-cybermira-an-ai-powered-cybersecurity-assistant-grounded-in-sanity.txt", "jsonld": "https://wpnews.pro/news/i-built-cybermira-an-ai-powered-cybersecurity-assistant-grounded-in-sanity.jsonld"}}