Code audits for Cursor-built apps.
Cursor writes plausible code fast, and plausible is not the same as safe. We audit Cursor-built codebases the way a senior engineer reads code before production: every route checked for authorisation, every secret traced, every finding delivered with its fix.
Why it matters
An agent in your editor optimises for the request in front of it. Asked for a feature, it ships the feature; nobody asked it to confirm that the new endpoint checks who is calling, or that the key it needed stayed out of the client bundle. Repeated across hundreds of accepted changes, a codebase accumulates decisions no one reviewed. Most AI-assisted codebases we audit have at least one serious access-control flaw, and the owner is rarely aware of it, because the app works. Working and exposed are not opposites. In our scan data they are the usual combination.
What you get.
Access control review
Every route, action and API endpoint checked for missing or broken authorisation, then verified live with two real accounts. This is the single most common serious hole in AI-written code.
Secrets, tokens and permissions
Keys in client code or committed history, tokens scoped wider than they need to be, and service credentials reachable from the browser. Anything that has shipped to a client is treated as already compromised.
Logic and edge-case audit
We trace the flows that matter, payments, auth, data writes, and find where the happy path the agent tested quietly breaks under a second user or a malformed request.
Deployment configuration
Security headers, CORS, rate limiting, source maps in production, debug endpoints and leftover agent artifacts that ship information an attacker can use.
Prioritised report
Every finding rated by severity with a concrete fix, in the order you should tackle them.
Free re-review
Once you have made the fixes, with Cursor or with us, we check them again at no extra cost.
How it works.
- 01
Access
You give us read access to the repo and a short walkthrough of what the app does and who should see what.
- 02
Review
We read the code and test the live app by hand, with real accounts, not just with automated scanners.
- 03
Report
You get a clear, prioritised write-up within days, plus a call to walk through it. Each finding is written so you can paste it straight back into Cursor as a fix instruction if you prefer.
- 04
Re-review
After the fixes land, we verify they hold and that nothing new opened up.
Common questions.
- Cursor uses strong models. Isn't the code already fine?
- The code is usually correct for what was asked. The flaws live in what was never asked: whether this route needed an auth check, whether one user can read another's records, whether that token needed full scope. Those are questions about your app's intent, and they only surface when someone tests the relationships between accounts.
- Is this just an automated AI code review?
- No. Automated review catches the obvious. The findings that matter, broken access rules and flawed logic, need an engineer reading the code and testing the running app with two accounts. That is what this audit is.
- What does the audit cover?
- Access control on every route verified live, secrets and token scoping, the logic of payment and data flows, and deployment configuration including tokens, permissions and logging. Every finding is rated by severity and comes with a concrete fix.
- Can you fix the issues too?
- Yes. We can make the fixes ourselves, or hand you findings written precisely enough to feed back into Cursor. Either way, the free re-review confirms the result.
- How much does a Cursor code audit cost?
- It is scoped to a fixed quote up front, with no hourly meter, and typically starts around $750 depending on the size of the codebase. You will know the price before we begin.
Related services.
Let's build something real.
Tell us about your app or idea. You'll get a clear plan and a fixed quote back within 24 hours.
