for apps built with Cursor

Building with Cursor?
Scan the code, then let the agent fix it.

With Cursor the code is yours: on your machine, in your repo, deployed wherever you like. So the repo scan does the heavy lifting, the live app scan checks what actually shipped, and on Pro the agent can run both itself.

Free for one app. No card, no install.

what usually goes wrong

Where Cursor apps leak

A .env that got committed

One git add . before the .gitignore was right, and every key in it lives in the repo's history. We show the file and line, with the key redacted, so you know which one to rotate.

repo: committed secrets and .env files

Packages with known holes

Agents install whatever version they remember. We check your lockfile against OSV.dev and tell you which package to bump, and to what.

repo: vulnerable dependencies (OSV.dev)

Database rules that let everyone in

A Supabase migration that creates a table without RLS, a policy that says using (true), or Firebase rules left in test mode. Caught in the code, before it is deployed.

repo: Supabase migrations, Firebase rules files

Patterns agents get wrong

An admin check that only happens in the browser. An API route that changes data without asking who is calling. CORS open to every site. We flag them for you, or the agent, to fix.

repo: risky code patterns

the fix is a prompt

Worded for Cursor

Repo findings point at the file and line, so the prompt can too:

highrepo-code.client-side-role-check

Admin or role check trusts the browser's storage

The admin page decides who is an admin by reading localStorage. Anyone can set that value in their own browser and walk in.

file
src/pages/Admin.tsx
line
18
code
if (localStorage.getItem("role") === "admin")
Paste into Cursor click to select

Security fix: src/pages/Admin.tsx decides whether the user is an admin from localStorage, which anyone can edit.
Check the role on the server instead: read it from the signed-in user's record in the database, and make every admin API route verify it too, returning 403 otherwise.
Keep the UI the same. Show me each route you changed.

then rescan to confirm it is gone

verify your app

Proving it is yours, on Cursor

Cursor is where you build, not where you host, so you verify wherever the app is deployed: Vercel, Netlify, Render, Fly or your own server. The repo scan needs no verification, only the GitHub App.

  • Static file: put it in public/.well-known/ (Vite, Next.js and most frameworks serve that folder as-is).
  • Meta tag: add it to index.html or your root layout's metadata.
  • Own domain: a TXT record at _vibeprotect.<your host> works too.
Paste into Cursor click to select

Add a site verification for VibeProtect. Create the file public/.well-known/vibeprotect.txt containing exactly this single line:
vibeprotect-verify=3kQ9xZr1VbN0aT7mYw2cLp8e
Also add this tag inside <head> in index.html (or the root layout's metadata):
<meta name="vibeprotect-verification" content="vibeprotect-verify=3kQ9xZr1VbN0aT7mYw2cLp8e" />
Do not change anything else.

Your real token is in the app once you add it. The file ends up at /.well-known/vibeprotect.txt.

mcp server · pro

Let Cursor scan and fix on its own

On Pro, connect Cursor to our MCP server and the agent can start a scan, read each finding with its fix prompt, change the code and scan again. You review the diff.

// ~/.cursor/mcp.json
{
  "mcpServers": {
    "vibeprotect": { "url": "https://75c36bbx12.execute-api.us-east-1.amazonaws.com/prod/mcp" }
  }
}
Then ask Cursor click to select

Scan this app with VibeProtect, fix the critical and high findings one by one, and rescan.

questions

Cursor questions

Do I have to deploy before I can scan?

No. Connect GitHub and you can scan the repo straight away. The live app scan needs a public address, and checks what only the shipped app shows: the keys in the built JavaScript, its headers and its HTTPS setup.

Can the agent use the MCP server to scan other people's sites?

No. It can only scan apps your account has verified, the same as you in the dashboard.

Does this work with Windsurf or Claude Code too?

Yes. The repo scan does not care which editor wrote the code, and the MCP server works with any client that supports remote MCP servers.

See what your Cursor app is showing strangers.

One app is free, no card. The hardest part is asking Cursor to add a file.