announcement aidev SIG 4/5

Cursor Security Review: always-on security agents, beta on Teams/Enterprise

Cursor ships a beta security review product with two always-on agents: a Security Reviewer that comments on every PR, and a scheduled Vulnerability Scanner. Both are customizeable, including plugging in your own scanners via MCP.

PUBLISHED2026-04-30
OBSERVED2026-08-11
AGE3mo
SOURCES1
  • Beta on Teams and Enterprise plans; admins enable it in the dashboard
  • Security Reviewer: checks every PR for vulnerabilities, auth regressions, privacy/data-handling risks, agent tool auto-approvals, and prompt injection; leaves inline severity+remediation comments at the exact diff location
  • Vulnerability Scanner: scheduled codebase scans for known vulnerabilities, outdated dependencies, config issues; can post findings to Slack
  • Customizable: adjust triggers, add instructions, custom tooling, choose output sharing; can wire in existing SAST/SCA/secrets scanners via MCP servers
  • Security agents draw from your existing usage pool

COMMUNITY

No curated reactions recorded for this event. Facts and takes are kept in separate layers — community context is added by hand, never blended into the record above.