# I built CyberMira: An AI-Powered Cybersecurity Assistant Grounded in Sanity

> Source: <https://dev.to/alphonsekazadi/i-built-cybermira-an-ai-powered-cybersecurity-assistant-grounded-in-sanity-25ih>
> Published: 2026-09-30 15:03:22+00:00

*This is a submission for the [Sanity Challenge, Path One: Ship an Agent That Queries Real Content](https://dev.to/challenges/sanity-2026-09-16)*

Cybersecurity questions often have answers scattered across standards, vulnerability references, attack patterns, and mitigation guidance.

**CyberMira** is an AI-powered cybersecurity assistant for developers that answers questions using a structured cybersecurity Knowledge Base instead of relying only on a language model's general knowledge. 

The Knowledge Base currently contains **36 structured entries** covering: 

A developer can ask a question such as:

How can I prevent broken object-level authorization in a REST API?

CyberMira identifies the relevant knowledge areas, retrieves the corresponding content through Sanity Context MCP, and gives that evidence to Gemini to generate the final answer.

The goal is simple: **retrieve structured security knowledge first, then generate the explanation.**

The main architecture is:

The important part is that Gemini is not the source of the cybersecurity knowledge. The application first retrieves evidence from the Sanity Knowledge Base.

**Retrieval Flow**

Try the deployed application:

[cybermira](https://cybermira.onrender.com)

Or see the live demo here :

The application is publicly accessible and does not require an account.

AI-powered cybersecurity knowledge for developers.

CyberMira is an AI-powered cybersecurity assistant for developers. It combines a structured cybersecurity knowledge base with AI to provide practical, evidence-grounded security guidance.

Unlike a general-purpose chatbot, CyberMira retrieves relevant cybersecurity knowledge from a curated Sanity Knowledge Base before generating an answer. The knowledge base connects vulnerabilities, technologies, attack patterns, detection techniques, mitigations, OWASP categories, and trusted security references.

A typical CyberMira request follows this flow:

```
Developer question
        |
        v
React / Vite frontend
        |
        v
FastAPI backend
        |
        v
Relevant knowledge paths
        |
        v
Sanity Context MCP
        |
        v
CyberMira Knowledge Base
        |
        v
Structured security evidence
        |
        v
Gemini
        |
        v
Grounded security answer
```

The backend first identifies the knowledge areas relevant to the developer's question. It then retrieves structured evidence through Sanity Context before passing that evidence to the language model.

This architecture keeps the cybersecurity knowledge separate…

Sanity is the structured knowledge layer behind CyberMira.

I created schemas for cybersecurity concepts instead of storing one large block of text. For example, vulnerabilities, technologies, attack patterns, detection techniques, mitigations, and OWASP categories are modeled as separate content types.

That content is indexed into a **Sanity Knowledge Base.**

CyberMira then accesses it through **Sanity Context MCP**.

The backend uses the MCP tools to retrieve the relevant knowledge:

```
result = await call_mcp_tool( 
 "knowledge_base_read", 
 { 
   "knowledgeBase": KNOWLEDGE_BASE_ID, :
   "paths": paths, 
 }, 
)
```

The application first selects relevant knowledge paths based on the developer's question:

```
paths = select_paths(request.message)

evidence = await read_knowledge(paths)

answer = await generate_answer(
    question=request.message,
    evidence=evidence,
)
```

For example, a question about API authorization can retrieve areas such as:

`access_control`

attack_patterns

mitigation

The retrieved content is then provided to Gemini as evidence for the answer.

This makes the roles of the components explicit:

```
Sanity 
  → structured cybersecurity knowledge 
Sanity Context MCP 
  → retrieval interface 
FastAPI 
  → application and retrieval logic 
Gemini 
  → explanation and answer generation 
React 
  → developer-facing interface
```

Sanity is therefore not just being used as a CMS. Its structured content and Knowledge Base are part of the reasoning pipeline.

No separate agent-session transcript is included in this submission.

The implementation was developed as a hands-on engineering workflow, with the final application, source code, Sanity schemas, Knowledge Base, and retrieval pipeline available for inspection.

The most interesting part of this project was not connecting an LLM to a database.

It was designing the **boundary between structured knowledge and generated answers**.

Sanity Context MCP provided a clean way to expose a curated Knowledge Base to the application, while the backend remained responsible for deciding what to retrieve and how that evidence should be used.

The result is a cybersecurity assistant where the knowledge layer is structured, inspectable, and separated from the language model.
