Cursor 在 Teams 和 Enterprise 计划推出 Security Review 测试版
Cursor Security Review
Cursor 面向 Teams 和 Enterprise 计划推出 Security Review 测试版,提供 Security Reviewer 和 Vulnerability Scanner 两类常驻安全智能体。
Cursor 把安全审查做成常驻智能体,读者可据此判断 PR 审查与定时扫描如何进入现有开发流程。
Cursor Security Review 现已在 Teams 和 Enterprise 计划中进入 beta 阶段。你可以运行两种类型的常驻安全代理:Security Reviewer 和 Vulnerability Scanner。
Security Reviewer
Security Reviewer 会检查每个 PR 是否存在安全漏洞、认证回归、隐私与数据处理风险、代理工具自动批准以及提示注入攻击。它会在确切的 diff 位置留下内联评论,并标注严重程度和修复建议。
<figure><img src="https://ptht05hbb1ssoooe.public.blob.vercel-storage.com/assets/changelog/security-reviewer.png" loading="lazy" alt="Security Reviewer leaving inline comments on a pull request diff." /><figcaption>Security Reviewer 在 pull request diff 上留下内联评论。</figcaption></figure>
Vulnerability Scanner
Vulnerability Scanner 会按计划扫描你的代码库,以检查已知漏洞、过时的依赖项和配置问题。你可以将其配置为在 Slack 中发送其发现的更新。
<figure><img src="https://ptht05hbb1ssoooe.public.blob.vercel-storage.com/assets/changelog/vuln-scanner.png" loading="lazy" alt="Vulnerability Scanner findings and scheduled scans in Cursor." /><figcaption>Vulnerability Scanner 在 Cursor 中的发现和计划扫描。</figcaption></figure>
---
通过调整触发器、添加你自己的指令、为它们提供自定义工具,以及选择如何共享输出,来自定义 Cursor 管理的安全代理。例如,你可以接入 MCP 服务器,以使用你现有的 SAST、SCA 和密钥扫描器,供 Cursor 在审查过程中使用。
我们还在持续改进驱动 Cursor Security Review 的运行时、测试框架和模型,以提供强大的开箱即用体验。
安全代理会从你现有的使用额度池中消耗。管理员可以在 Cursor 仪表板 中启用 Security Review 以开始使用。
来源:Cursor Changelog · cursor.com