Built with Cursor
There is no platform half. All of it is yours.
Cursor writes into a repository you already own. Nothing is hosted for you, nothing is configured for you, and no dashboard flags a problem later.
Cursor’s own documentation, quoted and linked. It is candid about the failure modes, which is more than the average tool manages. The candour only helps if somebody reads it.
Cursor is a trademark of its owner. This page quotes public documentation to explain a scope of work. There is no partnership, endorsement or affiliation in either direction.
What stays yours
An agent is not a platform.
A hosted builder hands back half a job. An agent in your editor hands back all of it, which is easy to miss because the code arrives looking finished.
The review that auto-run skips
Cursor’s own words: “If you have auto-reload enabled, agent changes might execute before you can review them.” The speed that makes it useful moves changes past the one person who would question them.
Being able to undo it
Their advice is one sentence: “Always use version control so you can revert changes.” It reads as obvious until an afternoon of accepted diffs sits between you and the last state you understood.
What you added to the allowlist
You can stop the prompting: “To let trusted calls run without prompting, configure Run Modes.” Every entry is a standing decision, made once when it was annoying and in force every time after.
Deciding what the agent was allowed to read
Cursor is direct about the risk: “AI can behave unexpectedly due to prompt injection, hallucinations, and other issues.” Text the agent reads can carry instructions, and a file, an issue or a web page is text.
Check it tonight
Audit the afternoon you stopped reading.
None of these look at the app. They look at what you agreed to while you were busy agreeing.
Read your own allowlist
Open your Run Modes and read what is permitted without a prompt. You are looking for an entry added in a hurry that is broader than the thing it was added for.
Search the whole history, not the checkout
Deleting a key from a file leaves it in the commit that introduced it. Repositories go public later, and when they do, their past goes with them.
Find the code nobody read
Look for the largest diffs you accepted in one go. Anything you cannot summarise from memory is code running in your name that has never been read by anyone.
Repeat one signed-in request without the session
Take a request your app makes while you are logged in and send it again with the session stripped out. An answer means the guard was drawn in the interface.
A diff you cannot summarise is code running in your name that nobody has read. Hand the reading to your own tool with the free prompt.
What a read adds
You cannot review your own blind spot.
The checks above find what you know to look for. The problem with an agent’s output is that it is fluent, and fluent code reads as reviewed. A second pair of eyes that never saw the conversation is the point.
That is what the audit is for. It runs against a method written down before your app existed.
€350 + VAT · 48 hours
An independent pass over your app.
Your repository and your live app, every finding with the evidence, what it costs you and a prompt you can paste back into Cursor.
€430.50 including VAT.
Start here
Start with the fit check.
Five questions about what you built and how far it has gone. If it is too early for an audit, the reply says what would help instead.