Legit Security Enhances AI Coding Agent Security with VibeGuard 2.0
Legit Security's VibeGuard 2.0 introduces endpoint security and real-time guardrails for AI coding agents, aiming to improve developer experience while bolstering security.

Legit Security has released VibeGuard 2.0, a significant update to its platform designed to secure AI coding agents and the code they generate. This new version introduces an endpoint security capability that automatically discovers and integrates with various coding agents, applying real-time guardrails directly at the point of code creation. This approach aims to enhance the developer experience by working harmoniously with agents rather than imposing disruptive blocks, while simultaneously tightening security in increasingly AI-centric development environments.
Unlike solutions that rely on easily removable IDE extensions, VibeGuard 2.0 operates directly on the endpoint. This architecture ensures that all coding agents and their plugins are automatically discovered and protected. The system interacts with users in a way that aims to avoid frustrating developers, offering granular policy enforcement that can secure specific agent commands and tools. This comprehensive coverage is crucial as AI agents become more integrated into the software development lifecycle.
Liav Caspi, CTO at Legit, emphasized the importance of securing agentic security at the developer endpoint. "Agentic security needs to happen at the developer endpoint with the goal of enhancing agents rather than blocking," Caspi stated. "When it comes to application security, securing code generation at the point where code is created is the most effective way to move quickly and securely." He added that the new architecture in VibeGuard 2.0 is a "gamechanger for agentic AppSec," enabling risk mitigation at the source of code generation.
Key capabilities in VibeGuard 2.0 include robust endpoint security, providing automated guardrails and policy enforcement for a range of coding agents such as Claude Code, Cursor, and GitHub Copilot. This is built on a new technology designed for complete agent security at the endpoint, ensuring broad compatibility and integration.
The update also brings real-time security guardrails, including skill discovery and protection, blocking of dangerous operations, and granular policy enforcement. This allows organizations to define and enforce policies that govern the actions of AI agents, preventing unintended or malicious activities.
Furthermore, VibeGuard 2.0 offers command monitoring and enforcement, giving security teams visibility into commands executed by AI agents. This enables the blocking of dangerous operations based on custom or built-in policies, which can cover thousands of industry best practices. This feature is critical for mitigating risks such as the unintentional or malicious leakage of sensitive information or the destruction of production data.
Finally, new anti-tampering capabilities have been introduced to prevent agents or threat actors from disabling VibeGuard. These protections also stop users from bypassing essential security measures, ensuring the integrity of the security controls in place.