Using the Cyber Model
Sec-Gemini supports the Gemini 3.8 Flash Cyber model (gemini-3.8-flash-cyber), a specialized variant of Gemini 3.8 Flash post-trained specifically for offensive and defensive cybersecurity tasks—including binary reverse engineering, malware analysis, deobfuscation, vulnerability triage, and forensic artifact analysis.
This guide explains how the cyber model works, environment and quota availability, the automatic air-gapped internet isolation policy enforced whenever it is active, and how to select it across the Web UI, TUI, CLI, Python SDK, and environment variables.
What is Gemini 3.8 Flash Cyber?
Section titled “What is Gemini 3.8 Flash Cyber?”gemini-3.8-flash-cyber is fine-tuned to excel at security workflows:
- Significantly Reduced Refusals: Pre-trained and fine-tuned on dual-use security research tasks (e.g. examining disassemblies, analyzing malicious binaries, generating defensive signatures, inspecting payload mechanics) with minimal false-positive safety refusals.
- Fast Execution: Built on the Gemini 3.8 Flash architecture for high-throughput, low-latency agent iteration and multi-step tool loops.
- Role Fan-Out: When selected, the model can power the main agent loop (
fast_model), reviewer/reflection agents (escalation_model), and refusal retries (refusal_retry_model).
Quota, Allowlisting & Environments
Section titled “Quota, Allowlisting & Environments”The Cyber model is a specialized internal model governed by Vertex AI project allowlisting:
- Internal Environments: Quota is provisioned and available in internal Sec-Gemini environments:
powernine-dev(development)powernine-prod-internal(internal dogfood & production)- Corp Run internal deployments (
internal-ui.secgemini.corp.goog,internal-api.secgemini.corp.goog)
- Public Production: The public production project (
powernine-prod, servingui.secgemini.google) does not have quota and is deliberately excluded from the allowlist. - Fast-Fail Behavior: If a request specifying
gemini-3.8-flash-cyberis sent againstpowernine-prodor an unauthorized GCP project, the system fails fast with a clear error (404 NOT_FOUND ... was not found or your project does not have access to it). There is no silent fallback to default models, ensuring reproducibility during benchmark evaluations and research runs.
Automatic Internet Isolation (Airgap)
Section titled “Automatic Internet Isolation (Airgap)”Whenever any agent role (fast_model, escalation_model, or refusal_retry_model) is configured to use a cyber model (any model name containing "cyber"), Sec-Gemini automatically and non-bypassably enforces complete internet isolation.
This defense-in-depth isolation prevents accidental network callbacks, beaconing, or data leakage while analyzing untrusted samples:
1. Security Policy Enforcement (default-deny-internet-access)
Section titled “1. Security Policy Enforcement (default-deny-internet-access)”- An organizational security policy (
default-deny-internet-access, Priority 700) is automatically activated inenforcemode. - Non-bypassable: It cannot be disabled, downgraded to
audit, or bypassed by client parameters (active_policy_ids). - Blocked Operations:
- Outbound HTTP and TCP connections (
http.host != ""). - Web search tools (
mcp_search). - Headless browser automation (
mcp_chrome). - Live network probing tools in
mcp_network.
- Outbound HTTP and TCP connections (
- Preserved Offline Tools:
- Offline packet capture (PCAP) inspection tools remain fully operational:
sandbox_network_triage_pcap,sandbox_network_extract_pcap_credentials,sandbox_network_filter_pcap_packets, andsandbox_network_extract_pcap_streams. - Local terminal, sandbox file operations, decompilation, disassembly, and local static analysis continue without restriction.
- Offline packet capture (PCAP) inspection tools remain fully operational:
2. Sandbox Kernel Network Namespace Isolation
Section titled “2. Sandbox Kernel Network Namespace Isolation”- Within the sandbox environment (
mcp_sandbox_env), the session policy engine detectsdefault-deny-internet-access. - The execution sandbox enables strict Linux network namespace isolation (
nsjail clone_newnet: true), ensuring that sandbox processes have no network interfaces or route to the internet.
How to Select the Cyber Model
Section titled “How to Select the Cyber Model”1. Web UI
Section titled “1. Web UI”In the Sec-Gemini Web UI (on internal or local instances):
- New Session Menu: Next to the prompt input at the bottom of the new session screen, click the
+(Add files or select mode) button. - Toggle Cyber Model: Click Cyber model (shield icon).
- An active chip
[Cyber model (x)]will appear next to the+button. - To disable before submitting, click the
×on the chip or click Cyber model in the menu again.
- An active chip
- Submit Prompt: Enter your prompt and click Send. The session will be created with
config.model: "gemini-3.8-flash-cyber". - Session View:
- The session header displays a Cyber model shield badge indicating the session is running on the cyber model with air-gapped isolation.
- Follow-up turns in the same session automatically retain the Cyber model and internet isolation policy.
Note: On public production deployments (
ui.secgemini.google), the Cyber model option is automatically hidden from the menu.
2. Terminal UI (TUI)
Section titled “2. Terminal UI (TUI)”You can select the Cyber model either from the command line or from within the TUI interface:
Via CLI Flag
Section titled “Via CLI Flag”Launch the TUI with the --model flag:
sec-gemini --model gemini-3.8-flash-cyberThis pre-selects gemini-3.8-flash-cyber in the New Session model dropdown.
Via the TUI New Session Screen
Section titled “Via the TUI New Session Screen”- On the New Session screen, navigate to the Model dropdown (next to the Harness picker).
- Select
gemini-3.8-flash-cyber. - Create your session.
3. Command-Line Interface (CLI)
Section titled “3. Command-Line Interface (CLI)”The sec-gemini CLI supports --model on all primary commands:
Interactive Chat
Section titled “Interactive Chat”sec-gemini --model gemini-3.8-flash-cyberNon-Interactive Execution (run)
Section titled “Non-Interactive Execution (run)”sec-gemini run --model gemini-3.8-flash-cyber "Analyze the decompiled functions in sample.c for vulnerabilities"Digital Forensics & Incident Response (dfir)
Section titled “Digital Forensics & Incident Response (dfir)”sec-gemini dfir --model gemini-3.8-flash-cyber "Analyze the memory dump for injected DLLs"Granular Per-Role Flags
Section titled “Granular Per-Role Flags”If you want to configure specific agent roles separately:
sec-gemini run \ --fast-model gemini-3.8-flash-cyber \ --escalation-model gemini-3.8-flash-cyber \ "Perform static analysis on payload.bin"4. Python SDK
Section titled “4. Python SDK”When using the sec-gemini Python SDK, pass the model in the session metadata using MODEL_META_KEY:
import asynciofrom sec_gemini import SecGeminifrom sec_gemini.constants import CYBER_MODEL, MODEL_META_KEY
async def main(): async with SecGemini() as client: session = await client.sessions.create()
# Pass the cyber model shortcut in the prompt metadata await session.prompt( "Decompile and analyze suspicious_binary.exe", meta={MODEL_META_KEY: CYBER_MODEL}, ) async for msg in session.messages.stream(): if msg.get("message_type") == "MESSAGE_TYPE_RESPONSE": print(msg.get("content", ""))
asyncio.run(main())You can also specify individual roles in metadata:
meta = { "config.fast_model": "gemini-3.8-flash-cyber", "config.escalation_model": "gemini-3.8-flash-cyber", "config.refusal_retry_model": "gemini-3.8-flash-cyber",}5. Environment Variables (Self-Hosted / Local Stack)
Section titled “5. Environment Variables (Self-Hosted / Local Stack)”For local development or self-hosted worker deployments (e.g. local_services/docker-compose.yml), you can set default models across all sessions via environment variables:
| Environment Variable | Description |
|---|---|
SEC_GEMINI_MODEL |
Shortcut: Sets fast_model, escalation_model, and refusal_retry_model simultaneously |
SEC_GEMINI_FAST_MODEL |
Model for the main agent loop (planner, executor, responder) |
SEC_GEMINI_ESCALATION_MODEL |
Model for reflection, review, and failure escalation |
SEC_GEMINI_REFUSAL_RETRY_MODEL |
Model for refusal recovery re-prompts |
Example:
export SEC_GEMINI_MODEL="gemini-3.8-flash-cyber"sec-geminiConfiguration Precedence
Section titled “Configuration Precedence”When multiple methods specify models, Sec-Gemini resolves them in the following order (highest precedence first):
- Per-role prompt metadata:
config.fast_model,config.escalation_model,config.refusal_retry_model(e.g. CLI flags--fast-model,--escalation-model). - Model shortcut metadata:
config.model(e.g. Web UI toggle, CLI flag--model, TUI dropdown, SDKMODEL_META_KEY). - Constructor arguments:
Config(fast_model=...). - Mode profile pins: e.g.,
dfir.tomldefaults. - Environment variables:
SEC_GEMINI_*_MODELoverridesSEC_GEMINI_MODEL. - Built-in defaults:
DEFAULT_FAST_MODEL(gemini-3.8-flash),DEFAULT_REFUSAL_RETRY_MODEL(gemini-3.1-pro-preview).
Verifying Active Status
Section titled “Verifying Active Status”To confirm that a session is using the Cyber model and that air-gapped isolation is active:
- Web UI: Check the session header bar for the
Cyber modelshield chip. - Session Metrics / API: Inspect the session document
metaorsessionMetricsforconfig.model: "gemini-3.8-flash-cyber"andisCyberModel: true. - Security Policies: Open the Security policies panel in the Web UI or inspect session policies via SDK/CLI. The
default-deny-internet-accesspolicy will be marked as Enforced and active. Attempts by the agent or tools to contact external network addresses will be logged as blocked violations.