Reviewing AI-written code from Cursor
Cursor writes code inside a real engineering workflow, so the risk is different from app builders: the code is yours, reviewed or not, and the gaps are in what nobody had time to read closely.
Code written with Cursor is as secure as your review of it. The editor produces correct-looking code at a pace no reviewer keeps up with, so missing authorization checks, unsafe queries and secrets in config slip through as diffs nobody read in full. Keep security checks in CI, review authorization and data access by hand, and have the product tested independently before a major launch or a customer security review.
Where the risk sits in a Cursor app
Teams using Cursor usually have version control, pull requests and CI, which is a real advantage. The weakness is volume: a generated change of several hundred lines gets approved on the strength of the tests passing, and the tests were written by the same model with the same blind spots.
| Finding | How to check it yourself |
|---|---|
| Authorization missing in new endpoints | Search new route handlers for an ownership or role check |
| String-built queries | Search for query strings assembled with user input |
| New dependencies nobody chose | Review lockfile changes; check package names are real and maintained |
| Secrets added to config for convenience | Run a secret scanner in CI |
| Tests that assert the bug | Read generated tests: do they check that user A cannot read user B's data? |
| Error handling that swallows failures | Search for empty catch blocks |
Checks to run before launch
0 of 0 done ยท
The full list, tool by tool, is the pre-launch security checklist. For the flows rather than the security, use the launch checklist.
The tool is not the problem
Cursor produces working software quickly and it is a reasonable way to build a first version. Its output is a first draft. Nothing in the tool checks that every record is protected from every user who should not see it, because that depends on rules only you know. Ask it to add the checks, then have someone who did not write the prompts verify them. That is what a security test is.
Getting it tested
A security and QA test of a small Cursor app typically costs $2,000 to $12,000 CAD, depending on roles, payments and any AI features. Testers work from the running app and, if you share it, the exported code. See what to give the testers. TrazTech offers this as vibe-coding QA and security review; get a second quote on the same scope.
Common questions
Are AI-suggested packages safe?
Check each one exists and is the package you expect. Models sometimes suggest names that do not exist, and attackers register look-alike names to catch them.
Can Cursor review its own code for security?
It will find some issues if asked. It shares the blind spots that produced the code, so it is no substitute for an independent review.
When is a formal test worth it?
Before a launch with real customer data, before an enterprise security review, and after large AI-written changes to auth, payments or data access.