For Cursor builders
Pre-launch security review for apps built with Cursor
Cursor makes it easy to build a whole product without reading most of the code the model wrote. That is fine until the first stranger signs up. The problems are rarely exotic; they are the ownership check that was never written, the webhook that never verified its signature, the endpoint with no rate limit.
VibeAudit reads the whole repository, not a diff, and for each finding writes a prompt you can paste straight back into Cursor's Composer.
Scan your Cursor project now — free, under a minute, no signup
Paste the GitHub repository URL. Public repos work as-is; sign in with GitHub for private ones.
What Cursor apps usually ship with
From our audits of real repositories. Every item below is something the deep audit reports with file and line, plus a fix prompt.
The model writes `findById(id)` and moves on. Nothing ties the row to the logged-in user.
Stripe, GitHub and Clerk webhooks that accept any POST let anyone mark an order as paid.
Chat and generation routes with no per-user limit turn into someone else's free API.
Hand-rolled auth generated on request tends to skip bcrypt, CSRF and session expiry.
Read before you launch
- API routes and server actions with no auth check · coming soon
- Missing ownership checks (IDOR): reading and editing other users' data · coming soon
- Supabase service-role and secret keys leaking to the browser · coming soon
- Stripe webhooks, idempotency and billing logic bugs →
- Plaintext passwords, weak hashing and forgeable sessions · coming soon
- Unbounded AI endpoints: paying for someone else's prompts · coming soon
FAQ
- How is this different from asking Cursor to review the code?
- Cursor reviews what is in its context window, usually a few files. The deep audit reads up to ~280K tokens of your repository in one pass with Claude Fable 5.1 at high effort and traces flows across files. It also gives you an outside opinion the model that wrote the code will not.
- Can I use the fix prompts in Cursor?
- That is what they are for. Each finding has a prompt that names the file, the change and the reason. Paste it into Composer.