PR Review
Cursor (Bugbot)
Cursor's PR review layer: Bugbot diff review, Security Agents, PR routing/approval and a PR/merge-queue workspace.
Deployment
Cloud
Languages
Not documented
Pricing model
Per developer seat, Usage-based credits
Free tier
Yes
Workflow coverage
Where in the development lifecycle Cursor (Bugbot) operates.
Agent Review runs in the Cursor IDE after each commit or via /agent-review; not as-you-type.
Bugbot connects to configured MCP servers for extra review tools; Team and Enterprise plans only.
/review-bugbot reviews branch or uncommitted changes pre-push; patch-ID dedup skips the later PR review.
Posts inline PR comments with explanations, fix suggestions, and Fix in Cursor / Fix in Web links.
Status check can fail on unresolved issues to block merges; defaults to neutral otherwise.
Security Agents scan codebases for vulnerabilities; source has no dedicated feature page or configuration detail.
Vulnerability Scanner runs cron-based recurring scans of the codebase at rest; beta, Team/Enterprise
Not offered in vendor documentation reviewed as of 2026-09-05.
Analysis & detection
Every detection and code-analysis capability tracked for Cursor (Bugbot).
Bugbot flags security issues in diffs; Security Agents scan for vulnerabilities, no engine or rule detail.
Security docs detail specific check types but never mention cross-function taint tracking
Docs say teams integrate third-party secrets scanners via MCP; not a native check
No native secrets detection, and no mention of testing if a found secret is live
Vulnerability Scanner flags known vulnerabilities and outdated dependencies; beta, Team/Enterprise
Anybump marketplace automation template runs reachability analysis on dependency fixes
No typosquat or compromised-package detection mentioned across security docs
Only via a custom BUGBOT.md rule naming specific licenses; no native license policy engine
No CycloneDX/SPDX export mentioned anywhere in Bugbot or Security Agents docs
Security Checks section names no categories; no Terraform/K8s/Dockerfile mention found
Same Security Checks section is silent on container or base-image scanning
No mention of live cloud account configuration scanning in Security Agents docs
Vulnerability Scanner explicitly scans the codebase at rest, static only
Bugbot reports code quality problems alongside bugs and security issues on PR diffs.
Full 16-section Bugbot docs page never mentions a complexity metric
Same full docs review found no clone or copy-paste detection mentioned
No dead or unreachable code detection documented
Only a custom rule requiring tests exist; no coverage percent ingestion documented
No coverage tracking of any kind is documented, so no new-code metric either
ROUTING.md maps products to code boundaries; APPROVAL_POLICY.md sets per-directory review requirements.
No conversion of findings into remediation time or cost documented
No git-history analytics such as hotspots, churn, or bus factor documented
Bugbot analyzes PR diffs for bugs with Default, High and Custom reasoning-effort levels.
Code Tour walkthroughs and agent diff summaries ship in Cursor Review, currently closed beta.
Team Rules, .cursor/BUGBOT.md, learned rules and glob-scoped manual rules merged by precedence.
Findings include fix suggestions plus Fix in Cursor, Fix in Web, or ask the in-PR agent.
Autofix spawns a Cloud Agent pushing to a new or existing branch; needs on-demand usage billing.
Not offered in vendor documentation reviewed as of 2026-09-05.
Nested BUGBOT.md discovery upward from changed files, glob-scoped rules, ROUTING.md product boundaries.
AI capabilities
Bugbot, Security Agents, Agent Review and PR Routing are all LLM agents on Cursor's cloud.
Not offered in vendor documentation reviewed as of 2026-09-05.
Bugbot consumes configured MCP servers; no MCP server exposing findings. Team and Enterprise only.
Usage analytics, AI code tracking API, repository/model/MCP access controls, OpenTelemetry usage export.
In-PR Cursor Agent answers and applies fixes; '@cursor remember' teaches facts inline.
Learned rules auto-generate from team GitHub activity and are auto-enabled or disabled over time.
Team-wide Privacy Mode and Legacy Privacy Mode referenced; no explicit training-exclusion statement in source.
Models used
Compliance & governance
Enterprise audit logs cover Bugbot installs, rules and settings; stream to SIEM, S3 or webhooks.
SAML/OIDC SSO listed in Teams Standard plan inclusions.
Admin versus member roles, per-user Bugbot allow/blocklists, Enterprise repository, model and MCP access controls.
Not offered in vendor documentation reviewed as of 2026-09-05.
Certifications
Integrations
IDEs
Issue trackers
Chat & notifications
Pricing & plans
$16/month billed annually for the Individual (Pro) plan ($20/month if billed monthly), plus $1.00-$1.50 per Bugbot review billed usage-based
Trial: 14-day free trial available for all Bugbot plans
- No credit card required
- Limited Agent requests
- Access to Composer
- PR Inbox with up to 3 default repositories
- No Bugbot or PR-review features
- Limited Agent requests
- Extended Agent limits
- Frontier models
- MCPs, skills and hooks
- Cloud agents
- Bugbot with usage-based billing
- Bugbot reviews bill from included usage, overage from on-demand spend
- No PR Routing & Approval or Security Agents
- No Merge Queue
- No MCP tools for Bugbot
- 3x Pro Agent limits
- All Pro features
- Bugbot with usage-based billing
- Price not published
- Team-only features still excluded
- 20x Pro Agent limits
- Priority access to new features
- Bugbot with usage-based billing
- Price not published
- Team-only features still excluded
- Agentic code reviews with Bugbot
- PR Routing & Approval and Security Agents
- Merge Queue
- MCP tools for Bugbot
- Team-wide privacy mode and SAML/OIDC SSO
- Usage analytics and PR Inbox with 30 default repos
- Bugbot review cost layers on top as on-demand spend
- Bugbot Admin API and Public/Analytics API are Enterprise-only
- No audit logs
- Everything in Standard
- Expanded Agent limits
- Pricing notation for the 5x uplift not itemised in source
- Everything in Teams
- Audit logs and service accounts
- Bugbot Admin API and Public/Analytics API
- SCIM seat management and pooled usage
- HIPAA BAA and Private Connectivity
- OpenTelemetry export (beta) and AI code tracking API
- Quote-only pricing
- OpenTelemetry export still beta
Who it's for
Notable strengths
- Review, fix and merge live in one product: findings open directly in the Cursor IDE or a Cloud Agent that pushes a fix branch
- Layered precedence-ordered rules (Team Rules, .cursor/BUGBOT.md, learned rules, manual rules) with verbose-mode audit of which rules applied or were truncated
- PR Routing & Approval adds risk scoring, git-blame-based reviewer assignment and auto-approval, with self-modifying-policy protection
- Native status checks across GitHub (incl. GHES), GitLab (incl. self-hosted), Bitbucket (incl. Data Center) and Azure DevOps, plus PrivateLink/Cloudflare Tunnel connectivity to private Git
- Per-user Bugbot license governance via allowlist/blocklist Admin API for provisioning and offboarding
Notable limitations
- Cloud-only: no on-premises deployment is offered
- Merge blocking is not the default - findings publish a neutral check unless 'fail on unresolved issues' is enabled, and that is only available for some orgs
- Source documents no SCA, secrets, IaC, container, coverage or duplication capability, and names no supported languages
- Security Agents have no configuration documentation, only cross-references, and require Team or Enterprise
- Bugbot review cost is metered per review ($1.00-$1.50) on top of seat price, and Autofix additionally requires on-demand usage pricing and non-Legacy privacy mode
- Bugbot Admin API, Public/Analytics API, audit logs and HIPAA BAAs are Enterprise-only; MCP, Merge Queue and Security Agents need Team or Enterprise
Similar tools
Other PR Review tools in the directory.
FAQ
When should you choose Cursor (Bugbot)?
Cursor (Bugbot) best fits Indie developers, Startups, Mid-market teams, Enterprise. Review, fix and merge live in one product: findings open directly in the Cursor IDE or a Cloud Agent that pushes a fix branch
What languages does Cursor (Bugbot) support?
Language support for Cursor (Bugbot) is not documented in the sources reviewed.
What does Cursor (Bugbot) integrate with?
Cursor (Bugbot) integrates with GitHub, GitHub Enterprise Server, GitLab, GitLab Self-Managed, Bitbucket, Bitbucket Data Center, Azure DevOps (partial) for source control, and IDEs including Cursor.
What tools are similar to Cursor (Bugbot)?
Similar PR Review tools tracked here include CodeAnt AI, CodeRabbit, Greptile, Qodo.
What are Cursor (Bugbot)'s plans and pricing?
Cursor (Bugbot) offers a free tier, with paid plans starting around Free tier available; enterprise pricing is quote-only.
Opens cursor.com in a new tab. Review Radar is not affiliated with Cursor.