Cursor (Bugbot)

Cursor's PR review layer: Bugbot diff review, Security Agents, PR routing/approval and a PR/merge-queue workspace.

Free tier availableLast verified 2026-08-25

Deployment

Cloud

Languages

Not documented

Pricing model

Per developer seat, Usage-based credits

Free tier

Yes

Workflow coverage

Where in the development lifecycle Cursor (Bugbot) operates.

Real-Time IDE FeedbackPartialPro

Agent Review runs in the Cursor IDE after each commit or via /agent-review; not as-you-type.

AI Agent Guardrail (MCP)YesTeam

Bugbot connects to configured MCP servers for extra review tools; Team and Enterprise plans only.

Local CLI / Pre-CommitYesPro

/review-bugbot reviews branch or uncommitted changes pre-push; patch-ID dedup skips the later PR review.

PR Inline ReviewYesPro

Posts inline PR comments with explanations, fix suggestions, and Fix in Cursor / Fix in Web links.

Merge Gate BlockingYesPro

Status check can fail on unresolved issues to block merges; defaults to neutral otherwise.

Full Repo ScanYesTeam

Security Agents scan codebases for vulnerabilities; source has no dedicated feature page or configuration detail.

Scheduled / Continuous RescanPartialTeam

Vulnerability Scanner runs cron-based recurring scans of the codebase at rest; beta, Team/Enterprise

Runtime / Production MonitoringNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Analysis & detection

Every detection and code-analysis capability tracked for Cursor (Bugbot).

SASTYesTeam

Bugbot flags security issues in diffs; Security Agents scan for vulnerabilities, no engine or rule detail.

Taint / Data-Flow AnalysisNo

Security docs detail specific check types but never mention cross-function taint tracking

Secrets DetectionNo

Docs say teams integrate third-party secrets scanners via MCP; not a native check

Secrets ValidationNo

No native secrets detection, and no mention of testing if a found secret is live

SCA (Dependencies)PartialTeam

Vulnerability Scanner flags known vulnerabilities and outdated dependencies; beta, Team/Enterprise

Reachability AnalysisNo

Anybump marketplace automation template runs reachability analysis on dependency fixes

Malicious Package DetectionNo

No typosquat or compromised-package detection mentioned across security docs

License CompliancePartialPro

Only via a custom BUGBOT.md rule naming specific licenses; no native license policy engine

SBOM GenerationNo

No CycloneDX/SPDX export mentioned anywhere in Bugbot or Security Agents docs

IaC ScanningNo

Security Checks section names no categories; no Terraform/K8s/Dockerfile mention found

Container ScanningNo

Same Security Checks section is silent on container or base-image scanning

Cloud Posture (CSPM)No

No mention of live cloud account configuration scanning in Security Agents docs

DAST / API ScanningNo

Vulnerability Scanner explicitly scans the codebase at rest, static only

Code Smells & MaintainabilityYesPro

Bugbot reports code quality problems alongside bugs and security issues on PR diffs.

Complexity MetricsNo

Full 16-section Bugbot docs page never mentions a complexity metric

Duplication DetectionNo

Same full docs review found no clone or copy-paste detection mentioned

Dead / Unused CodeNo

No dead or unreachable code detection documented

Test Coverage TrackingNo

Only a custom rule requiring tests exist; no coverage percent ingestion documented

Diff / New-Code CoverageNo

No coverage tracking of any kind is documented, so no new-code metric either

Architecture GovernanceYesTeam

ROUTING.md maps products to code boundaries; APPROVAL_POLICY.md sets per-directory review requirements.

Technical Debt QuantificationNo

No conversion of findings into remediation time or cost documented

Behavioral Delivery AnalyticsNo

No git-history analytics such as hotspots, churn, or bus factor documented

AI Logic Bug DetectionYesPro

Bugbot analyzes PR diffs for bugs with Default, High and Custom reasoning-effort levels.

PR Summaries & WalkthroughsPartialGating not documented (beta)

Code Tour walkthroughs and agent diff summaries ship in Cursor Review, currently closed beta.

Custom Rule AuthoringYesPro

Team Rules, .cursor/BUGBOT.md, learned rules and glob-scoped manual rules merged by precedence.

Autofix SuggestionsYesPro

Findings include fix suggestions plus Fix in Cursor, Fix in Web, or ask the in-PR agent.

Autofix via Agentic PRsYesPro

Autofix spawns a Cloud Agent pushing to a new or existing branch; needs on-demand usage billing.

AI Triage / False-Positive FilteringNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Monorepo SupportYesPro

Nested BUGBOT.md discovery upward from changed files, glob-scoped rules, ROUTING.md product boundaries.

AI capabilities

AI Review EngineYesPro

Bugbot, Security Agents, Agent Review and PR Routing are all LLM agents on Cursor's cloud.

BYO Model / BYOKNo

Not offered in vendor documentation reviewed as of 2026-09-05.

MCP ServerPartialTeam

Bugbot consumes configured MCP servers; no MCP server exposing findings. Team and Enterprise only.

AI Usage GovernanceYesEnterprise

Usage analytics, AI code tracking API, repository/model/MCP access controls, OpenTelemetry usage export.

Chat With ReviewerYesPro

In-PR Cursor Agent answers and applies fixes; '@cursor remember' teaches facts inline.

Learns From FeedbackYesTeam

Learned rules auto-generate from team GitHub activity and are auto-enabled or disabled over time.

Code Excluded From TrainingPartialTeam

Team-wide Privacy Mode and Legacy Privacy Mode referenced; no explicit training-exclusion statement in source.

Models used

Composer

Compliance & governance

Audit LogsYesEnterprise

Enterprise audit logs cover Bugbot installs, rules and settings; stream to SIEM, S3 or webhooks.

SSO / SAMLYesTeam

SAML/OIDC SSO listed in Teams Standard plan inclusions.

Role-Based Access ControlYesTeam

Admin versus member roles, per-user Bugbot allow/blocklists, Enterprise repository, model and MCP access controls.

Compliance Reporting ExportsNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Certifications

SOC 2 Type IIGDPRHIPAA (BAA available, Enterprise only)

Integrations

GitHubYes
GitHub Enterprise ServerYes
GitLabYes
GitLab Self-ManagedYes
BitbucketYes
Bitbucket Data CenterYes
Azure DevOpsPartial
REST APIYes
CLIYes
WebhooksPartial

IDEs

Cursor

Issue trackers

LinearJira

Chat & notifications

SlackMicrosoft Teams

Pricing & plans

$16/month billed annually for the Individual (Pro) plan ($20/month if billed monthly), plus $1.00-$1.50 per Bugbot review billed usage-based

Trial: 14-day free trial available for all Bugbot plans

HobbyFreeIndividual evaluation
  • No credit card required
  • Limited Agent requests
  • Access to Composer
  • PR Inbox with up to 3 default repositories
  • No Bugbot or PR-review features
  • Limited Agent requests
Pro$20/monthIndividual developers wanting Bugbot
  • Extended Agent limits
  • Frontier models
  • MCPs, skills and hooks
  • Cloud agents
  • Bugbot with usage-based billing
  • Bugbot reviews bill from included usage, overage from on-demand spend
  • No PR Routing & Approval or Security Agents
  • No Merge Queue
  • No MCP tools for Bugbot
Pro+Not publishedHeavier individual users
  • 3x Pro Agent limits
  • All Pro features
  • Bugbot with usage-based billing
  • Price not published
  • Team-only features still excluded
UltraNot publishedHighest-volume individual users
  • 20x Pro Agent limits
  • Priority access to new features
  • Bugbot with usage-based billing
  • Price not published
  • Team-only features still excluded
Teams Standard$40/user/monthTeams standardising review
  • Agentic code reviews with Bugbot
  • PR Routing & Approval and Security Agents
  • Merge Queue
  • MCP tools for Bugbot
  • Team-wide privacy mode and SAML/OIDC SSO
  • Usage analytics and PR Inbox with 30 default repos
  • Bugbot review cost layers on top as on-demand spend
  • Bugbot Admin API and Public/Analytics API are Enterprise-only
  • No audit logs
Teams Premium$40/user/month plus 5x Agent limitsTeams needing larger agent budgets
  • Everything in Standard
  • Expanded Agent limits
  • Pricing notation for the 5x uplift not itemised in source
EnterpriseCustom (contact sales)Large or regulated organisations
  • Everything in Teams
  • Audit logs and service accounts
  • Bugbot Admin API and Public/Analytics API
  • SCIM seat management and pooled usage
  • HIPAA BAA and Private Connectivity
  • OpenTelemetry export (beta) and AI code tracking API
  • Quote-only pricing
  • OpenTelemetry export still beta

Who it's for

Notable strengths

  • Review, fix and merge live in one product: findings open directly in the Cursor IDE or a Cloud Agent that pushes a fix branch
  • Layered precedence-ordered rules (Team Rules, .cursor/BUGBOT.md, learned rules, manual rules) with verbose-mode audit of which rules applied or were truncated
  • PR Routing & Approval adds risk scoring, git-blame-based reviewer assignment and auto-approval, with self-modifying-policy protection
  • Native status checks across GitHub (incl. GHES), GitLab (incl. self-hosted), Bitbucket (incl. Data Center) and Azure DevOps, plus PrivateLink/Cloudflare Tunnel connectivity to private Git
  • Per-user Bugbot license governance via allowlist/blocklist Admin API for provisioning and offboarding

Notable limitations

  • Cloud-only: no on-premises deployment is offered
  • Merge blocking is not the default - findings publish a neutral check unless 'fail on unresolved issues' is enabled, and that is only available for some orgs
  • Source documents no SCA, secrets, IaC, container, coverage or duplication capability, and names no supported languages
  • Security Agents have no configuration documentation, only cross-references, and require Team or Enterprise
  • Bugbot review cost is metered per review ($1.00-$1.50) on top of seat price, and Autofix additionally requires on-demand usage pricing and non-Legacy privacy mode
  • Bugbot Admin API, Public/Analytics API, audit logs and HIPAA BAAs are Enterprise-only; MCP, Merge Queue and Security Agents need Team or Enterprise

Similar tools

Other PR Review tools in the directory.

FAQ

When should you choose Cursor (Bugbot)?

Cursor (Bugbot) best fits Indie developers, Startups, Mid-market teams, Enterprise. Review, fix and merge live in one product: findings open directly in the Cursor IDE or a Cloud Agent that pushes a fix branch

What languages does Cursor (Bugbot) support?

Language support for Cursor (Bugbot) is not documented in the sources reviewed.

What does Cursor (Bugbot) integrate with?

Cursor (Bugbot) integrates with GitHub, GitHub Enterprise Server, GitLab, GitLab Self-Managed, Bitbucket, Bitbucket Data Center, Azure DevOps (partial) for source control, and IDEs including Cursor.

What tools are similar to Cursor (Bugbot)?

Similar PR Review tools tracked here include CodeAnt AI, CodeRabbit, Greptile, Qodo.

What are Cursor (Bugbot)'s plans and pricing?

Cursor (Bugbot) offers a free tier, with paid plans starting around Free tier available; enterprise pricing is quote-only.