VibeCoded

Reviewing AI-written code from Cursor

Cursor writes code inside a real engineering workflow, so the risk is different from app builders: the code is yours, reviewed or not, and the gaps are in what nobody had time to read closely.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

Code written with Cursor is as secure as your review of it. The editor produces correct-looking code at a pace no reviewer keeps up with, so missing authorization checks, unsafe queries and secrets in config slip through as diffs nobody read in full. Keep security checks in CI, review authorization and data access by hand, and have the product tested independently before a major launch or a customer security review.

Where the risk sits in a Cursor app

Teams using Cursor usually have version control, pull requests and CI, which is a real advantage. The weakness is volume: a generated change of several hundred lines gets approved on the strength of the tests passing, and the tests were written by the same model with the same blind spots.

Common findings in apps built with Cursor
FindingHow to check it yourself
Authorization missing in new endpointsSearch new route handlers for an ownership or role check
String-built queriesSearch for query strings assembled with user input
New dependencies nobody choseReview lockfile changes; check package names are real and maintained
Secrets added to config for convenienceRun a secret scanner in CI
Tests that assert the bugRead generated tests: do they check that user A cannot read user B's data?
Error handling that swallows failuresSearch for empty catch blocks

Checks to run before launch

0 of 0 done ยท

The full list, tool by tool, is the pre-launch security checklist. For the flows rather than the security, use the launch checklist.

The tool is not the problem

Cursor produces working software quickly and it is a reasonable way to build a first version. Its output is a first draft. Nothing in the tool checks that every record is protected from every user who should not see it, because that depends on rules only you know. Ask it to add the checks, then have someone who did not write the prompts verify them. That is what a security test is.

Getting it tested

A security and QA test of a small Cursor app typically costs $2,000 to $12,000 CAD, depending on roles, payments and any AI features. Testers work from the running app and, if you share it, the exported code. See what to give the testers. TrazTech offers this as vibe-coding QA and security review; get a second quote on the same scope.

Get your Cursor app tested

Share what it does, who uses it and what it stores.

Get matched

Common questions

Are AI-suggested packages safe?

Check each one exists and is the package you expect. Models sometimes suggest names that do not exist, and attackers register look-alike names to catch them.

Can Cursor review its own code for security?

It will find some issues if asked. It shares the blind spots that produced the code, so it is no substitute for an independent review.

When is a formal test worth it?

Before a launch with real customer data, before an enterprise security review, and after large AI-written changes to auth, payments or data access.