Access
Showcase


Products
Cursor, product by product →Cursor ships more than one product — each judged line competes in its own arena on the same stories as everyone else.
| Line | Arena | Rank | PA Score | Agent-ready |
|---|---|---|---|---|
| Cursor | AI Coding Agents | #11/13 | 27/100 | 29/100 |
| Cursor Bugbotthis page | AI Code Review | #6/6 | 24/100 | 26/100 |
Try itExperimental
See what an agent can do with Cursor Bugbot before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; commands tagged live-capable can re-run against the real endpoint from our edge, right now (▶ run live — the exact same request, live and recorded lines always labeled); sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).
$curl -s https://cursor.com/llms.txt | head -6recorded session — replayed, not liveVerified integrations
No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.
By theme — the product's score on each story themeBy theme
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Autofix agents — stories about autofix agents in this arenaAutofix agentsevidence →
Stories about autofix agents in this arena
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Codebase understanding — how deeply the tool maps your repo — cross-file context, architecture awareness, historyCodebase understandingevidence →
How deeply the tool maps your repo — cross-file context, architecture awareness, history
Interaction — how you steer it — commands, replies, review conversations, configurability in the loopInteractionevidence →
How you steer it — commands, replies, review conversations, configurability in the loop
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Pr integration — stories about pr integration in this arenaPr integrationevidence →
Stories about pr integration in this arena
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Quality gates — stories about quality gates in this arenaQuality gatesevidence →
Stories about quality gates in this arena
Review accuracy — stories about review accuracy in this arenaReview accuracyevidence →
Stories about review accuracy in this arena
Surfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksSurfacesevidence →
Where it meets your workflow — IDE, CLI, web, PR comments, CI checks
Workflow config — stories about workflow config in this arenaWorkflow configevidence →
Stories about workflow config in this arena
Story verdicts — every judged story with its evidenceStory verdicts
What’s free: 3 free · 3 paid · 0 enterprise · 19 not stated in evidence
Follow the green: where the map greys out is where Cursor Bugbot stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
—0/10
Subscribe to events via webhooks
—–
Build against official SDKs
n/an/a
Issue scoped/least-privilege API credentials for an agent
n/an/a
Connect an agent via an official MCP server
n/an/a
Download a machine-readable API spec (OpenAPI or equivalent)
n/an/a
Rely on versioned APIs with a documented deprecation policy
n/an/a
Test against a sandbox environment without touching production data
n/an/a
Explore an interactive API reference with runnable examples
n/an/a
Agentic features
Delegate tasks to a built-in AI assistant inside the product
~5/10
Operate the product with natural-language commands
~6/10
Plug MCP servers into this product so it can use their tools
n/an/a
Get AI-generated insights and suggestions from my data inside the product
✓8/10
Set up automations that run autonomously in the background
✓7/10
Autofix agents — stories about autofix agents in this arenaAutofix agents
Stories about autofix agents in this arena
The reviewer holds the line on AI-generated PRs — it verifies agent-authored code at a volume no human team could review
!6/10
I define custom agentic pre-merge checks in plain language — 'docs updated', 'tests cover new paths' — that run on every PR
~6/10
I turn a review finding into an applied fix — a committed patch or an agent-generated follow-up — without leaving the PR
~6/10
Review findings hand off cleanly to my coding agent — copyable fix prompts or direct integration with Claude Code, Cursor, or Codex
~6/10
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Codebase understanding — how deeply the tool maps your repo — cross-file context, architecture awareness, historyCodebase understanding
How deeply the tool maps your repo — cross-file context, architecture awareness, history
Interaction — how you steer it — commands, replies, review conversations, configurability in the loopInteraction
How you steer it — commands, replies, review conversations, configurability in the loop
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Pr integration — stories about pr integration in this arenaPr integration
Stories about pr integration in this arena
The reviewer installs as a GitHub/GitLab app and posts reviews as native inline comments on my pull requests within minutes
✓8/10
Review comments include committable suggested diffs I can apply with one click
~5/10
Every PR gets an auto-generated summary and change walkthrough so human reviewers orient fast
—0/10
Pushing new commits triggers an incremental re-review that tracks what was fixed instead of repeating old comments
✓7/10
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Quality gates — stories about quality gates in this arenaQuality gates
Stories about quality gates in this arena
Review accuracy — stories about review accuracy in this arenaReview accuracy
Stories about review accuracy in this arena
The reviewer catches real bugs in my PR — logic errors, race conditions, broken edge cases — not just style nits
!6/10
Push back on a bad review comment and the reviewer learns — it stops repeating the same rejected feedback
~4/10
The reviewer keeps noise low — few false positives, deduplicated comments, severity labels — so my team doesn't tune it out
~5/10
Reviews flag security problems in the diff — injection risks, leaked secrets, insecure patterns — alongside functional bugs
✓8/10
Surfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksSurfaces
Where it meets your workflow — IDE, CLI, web, PR comments, CI checks
Workflow config — stories about workflow config in this arenaWorkflow config
Stories about workflow config in this arena
I configure the reviewer with a versioned config file in my repo — path filters, per-path instructions, review profiles
~5/10
I roll out org-level review defaults across hundreds of repos and manage exceptions centrally
~5/10
I encode my team's own review guidelines — natural-language rules, AST patterns, or linked style guides — and the reviewer enforces them
✓7/10
Sorted by importance (agentic first) (high → low) · 53/53 stories · click a row’s chevron for the rationale and evidence
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | partial | 5/10 | Cclaimed | |
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none | 0/10 | ||
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Xcommunity | |
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 7/10 | Cclaimed | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partialpaid | 6/10 | Cclaimed | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Cclaimed | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | n/a | untested | none yet | |
The reviewer installs as a GitHub/GitLab app and posts reviews as native inline comments on my pull requests within minutes C Platforms | developer | Pr integration — stories about pr integration in this arenaPr integration | 3 | full | 8/10 | Xcommunity | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | partial | 6/10 | Cclaimed | |
I turn a review finding into an applied fix — a committed patch or an agent-generated follow-up — without leaving the PR C Fixes | developer | Autofix agents — stories about autofix agents in this arenaAutofix agents | 3 | partial | 6/10 | Xcommunity | |
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | partialfree | 6/10 | Cclaimed | |
The reviewer catches real bugs in my PR — logic errors, race conditions, broken edge cases — not just style nits C Detection | developer | Review accuracy — stories about review accuracy in this arenaReview accuracy | 3 | disputed | 6/10 | Dcontradicted | |
I configure the reviewer with a versioned config file in my repo — path filters, per-path instructions, review profiles C Config | engineering lead | Workflow config — stories about workflow config in this arenaWorkflow config | 3 | partialpaid | 5/10 | Cclaimed | |
Review comments include committable suggested diffs I can apply with one click C Suggestions | developer | Pr integration — stories about pr integration in this arenaPr integration | 3 | partial | 5/10 | Cclaimed | |
The reviewer keeps noise low — few false positives, deduplicated comments, severity labels — so my team doesn't tune it out C Noise | engineering lead | Review accuracy — stories about review accuracy in this arenaReview accuracy | 3 | partial | 5/10 | Xcommunity | |
Review comments reflect the whole repository — call sites, related modules, existing conventions — not just the changed hunks C Context | developer | Codebase understanding — how deeply the tool maps your repo — cross-file context, architecture awareness, historyCodebase understanding | 3 | partial | 4/10 | Cclaimed | |
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | none | 0/10 | ||
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | n/a | untested | none yet | |
Reviews flag security problems in the diff — injection risks, leaked secrets, insecure patterns — alongside functional bugs C Security | security engineer | Review accuracy — stories about review accuracy in this arenaReview accuracy | 2 | full | 8/10 | Tprobed | |
I encode my team's own review guidelines — natural-language rules, AST patterns, or linked style guides — and the reviewer enforces them C Rules | engineering lead | Workflow config — stories about workflow config in this arenaWorkflow config | 2 | full | 7/10 | Cclaimed | |
Pushing new commits triggers an incremental re-review that tracks what was fixed instead of repeating old comments C Updates | developer | Pr integration — stories about pr integration in this arenaPr integration | 2 | full | 7/10 | Tprobed | |
I define custom agentic pre-merge checks in plain language — 'docs updated', 'tests cover new paths' — that run on every PR C Checks | ai-native user | Autofix agents — stories about autofix agents in this arenaAutofix agents | 2 | partial | 6/10 | Cclaimed | |
Review findings hand off cleanly to my coding agent — copyable fix prompts or direct integration with Claude Code, Cursor, or Codex C Handoff | ai-native user | Autofix agents — stories about autofix agents in this arenaAutofix agents | 2 | partial | 6/10 | Cclaimed | |
The reviewer holds the line on AI-generated PRs — it verifies agent-authored code at a volume no human team could review C Ai authored | ai-native user | Autofix agents — stories about autofix agents in this arenaAutofix agents | 2 | disputed | 6/10 | Dcontradicted | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | partialfree | 4/10 | Cclaimed | |
I reply to the reviewer in the PR thread to ask questions, get explanations, or issue commands — and it answers in context C Chat | developer | Interaction — how you steer it — commands, replies, review conversations, configurability in the loopInteraction | 2 | partial | 4/10 | Cclaimed | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | partialfree | 4/10 | Cclaimed | |
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | partial | 4/10 | Cclaimed | |
Push back on a bad review comment and the reviewer learns — it stops repeating the same rejected feedback C Learning | developer | Review accuracy — stories about review accuracy in this arenaReview accuracy | 2 | partial | 4/10 | Xcommunity | |
The reviewer builds a persistent memory of my team's conventions and past review decisions and applies it to future PRs C Memory | ai-native user | Codebase understanding — how deeply the tool maps your repo — cross-file context, architecture awareness, historyCodebase understanding | 2 | partial | 4/10 | Cclaimed | |
Every PR gets an auto-generated summary and change walkthrough so human reviewers orient fast C Summaries | developer | Pr integration — stories about pr integration in this arenaPr integration | 2 | none | 0/10 | ||
I get the same review inside my IDE before I push, catching issues while the code is still in my editor C Ide | developer | Surfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksSurfaces | 2 | none | 0/10 | ||
I run reviews from a CLI against local diffs or in CI scripts, with machine-readable output my tooling can consume C Cli | developer | Surfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksSurfaces | 2 | none | 0/10 | ||
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | none | 0/10 | ||
The reviewer can gate merges — a required status check or blocking review that enforces resolution of critical findings C Gates | engineering lead | Quality gates — stories about quality gates in this arenaQuality gates | 2 | none | 0/10 | ||
The reviewer understands changes that span multiple repositories or a large monorepo and reviews them coherently C Context | engineering lead | Codebase understanding — how deeply the tool maps your repo — cross-file context, architecture awareness, historyCodebase understanding | 2 | none | 0/10 | ||
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | none | untested | none yet | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | none | untested | none yet | |
I control when reviews run — skip drafts, trigger on demand, filter by branch or label — so the bot shows up only when wanted C Control | developer | Interaction — how you steer it — commands, replies, review conversations, configurability in the loopInteraction | 1 | partialpaid | 5/10 | Cclaimed | |
I roll out org-level review defaults across hundreds of repos and manage exceptions centrally C Governance | engineering lead | Workflow config — stories about workflow config in this arenaWorkflow config | 1 | partial | 5/10 | Cclaimed | |
I see dashboards of findings, acceptance rates, and review coverage across my org C Analytics | engineering lead | Quality gates — stories about quality gates in this arenaQuality gates | 1 | partial | 4/10 | Cclaimed | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | n/a | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 33 stories with headroom
What would move Cursor Bugbot’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Agenticness — how well agents can access and operate the productDrive the product through a documented public API
nonemoves agent-readyimpact 45
Evidence shows Bugbot is driven via PR comment triggers (`bugbot run`, `cursor review`) and VCS integrations (GitHub/GitLab/Bitbucket/Azure DevOps), not via any documented public REST/webhook API for programmatic control.
Openness — open source, data portability, and self-hosting storiesExport all of my data in open formats and leave
nonemoves PA Scoreimpact 30
Missing: any export tool, data portability feature, or open-format download of Bugbot's findings/config.
Agenticness — how well agents can access and operate the productSubscribe to events via webhooks
nonemoves agent-readyimpact 30
No evidence anywhere in the pack of webhook subscription capability for Bugbot events; it integrates via PR comments/git provider webhooks internally but exposes no user-facing webhook subscription API.
Agenticness — how well agents can access and operate the productDelegate tasks to a built-in AI assistant inside the product
partialq5/10moves Built-in AIimpact 22.5
Missing: evidence of open-ended task delegation beyond PR review/fix workflows, and a conversational/general-assistant interface within Bugbot itself.
Automation depth — how much of the product can run unattendedSchedule recurring jobs or workflows
nonemoves PA Scoreimpact 20
Bugbot's docs describe event-triggered reviews (automatic on PR update, or manual comment trigger) and org-wide 'Automations' rules, but there is no evidence of true recurring/scheduled job execution (e.g., cron-like or time-based triggers) as opposed to PR-event triggers.
Quality gates — stories about quality gates in this arenaThe reviewer can gate merges — a required status check or blocking review that enforces resolution of critical findings
nonemoves PA Scoreimpact 20
Missing: any mention of CI status check integration, merge-blocking configuration, or required-review enforcement.
Surfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksI run reviews from a CLI against local diffs or in CI scripts, with machine-readable output my tooling can consume
nonemoves PA Scoreimpact 20
Missing: any CLI binary/command, local diff support, structured/machine-readable output format, or CI-script-oriented API.
Codebase understanding — how deeply the tool maps your repo — cross-file context, architecture awareness, historyThe reviewer understands changes that span multiple repositories or a large monorepo and reviews them coherently
nonemoves PA Scoreimpact 20
Missing: any mention of cross-repo dependency awareness, monorepo-scale indexing, or coordinated review across repos in a single PR/change set.
Showing the top 8 of 33 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map6 surfaces · 30 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
Help docs25 stories
- Run the product headlessly / in CI for automation
- Get AI-generated insights and suggestions from my data inside the product
- Set up automations that run autonomously in the background
- Delegate tasks to a built-in AI assistant inside the product
- Operate the product with natural-language commands
- The reviewer holds the line on AI-generated PRs — it verifies agent-authored code at a volume no human team could review
- I define custom agentic pre-merge checks in plain language — 'docs updated', 'tests cover new paths' — that run on every PR
- I turn a review finding into an applied fix — a committed patch or an agent-generated follow-up — without leaving the PR
- Review findings hand off cleanly to my coding agent — copyable fix prompts or direct integration with Claude Code, Cursor, or Codex
- Perform bulk operations across many items at once
- Define rules that trigger actions automatically on events
- Review comments reflect the whole repository — call sites, related modules, existing conventions — not just the changed hunks
- The reviewer builds a persistent memory of my team's conventions and past review decisions and applies it to future PRs
- I reply to the reviewer in the PR thread to ask questions, get explanations, or issue commands — and it answers in context
- I control when reviews run — skip drafts, trigger on demand, filter by branch or label — so the bot shows up only when wanted
- The reviewer installs as a GitHub/GitLab app and posts reviews as native inline comments on my pull requests within minutes
- Review comments include committable suggested diffs I can apply with one click
- I see dashboards of findings, acceptance rates, and review coverage across my org
- The reviewer catches real bugs in my PR — logic errors, race conditions, broken edge cases — not just style nits
- Push back on a bad review comment and the reviewer learns — it stops repeating the same rejected feedback
- The reviewer keeps noise low — few false positives, deduplicated comments, severity labels — so my team doesn't tune it out
- Reviews flag security problems in the diff — injection risks, leaked secrets, insecure patterns — alongside functional bugs
- I configure the reviewer with a versioned config file in my repo — path filters, per-path instructions, review profiles
- I roll out org-level review defaults across hundreds of repos and manage exceptions centrally
- I encode my team's own review guidelines — natural-language rules, AST patterns, or linked style guides — and the reviewer enforces them
docs24 stories
- Point an agent at llms.txt or agent-oriented docs
- Run the product headlessly / in CI for automation
- Get AI-generated insights and suggestions from my data inside the product
- Set up automations that run autonomously in the background
- Delegate tasks to a built-in AI assistant inside the product
- Operate the product with natural-language commands
- The reviewer holds the line on AI-generated PRs — it verifies agent-authored code at a volume no human team could review
- I define custom agentic pre-merge checks in plain language — 'docs updated', 'tests cover new paths' — that run on every PR
- I turn a review finding into an applied fix — a committed patch or an agent-generated follow-up — without leaving the PR
- Review findings hand off cleanly to my coding agent — copyable fix prompts or direct integration with Claude Code, Cursor, or Codex
- Perform bulk operations across many items at once
- Define rules that trigger actions automatically on events
- Review comments reflect the whole repository — call sites, related modules, existing conventions — not just the changed hunks
- The reviewer builds a persistent memory of my team's conventions and past review decisions and applies it to future PRs
- I reply to the reviewer in the PR thread to ask questions, get explanations, or issue commands — and it answers in context
- I control when reviews run — skip drafts, trigger on demand, filter by branch or label — so the bot shows up only when wanted
- The reviewer installs as a GitHub/GitLab app and posts reviews as native inline comments on my pull requests within minutes
- Review comments include committable suggested diffs I can apply with one click
- Pushing new commits triggers an incremental re-review that tracks what was fixed instead of repeating old comments
- Prevent my data from being used to train AI models
- The reviewer catches real bugs in my PR — logic errors, race conditions, broken edge cases — not just style nits
- Push back on a bad review comment and the reviewer learns — it stops repeating the same rejected feedback
- The reviewer keeps noise low — few false positives, deduplicated comments, severity labels — so my team doesn't tune it out
- Reviews flag security problems in the diff — injection risks, leaked secrets, insecure patterns — alongside functional bugs
Hacker News8 stories
- Get AI-generated insights and suggestions from my data inside the product
- The reviewer holds the line on AI-generated PRs — it verifies agent-authored code at a volume no human team could review
- I turn a review finding into an applied fix — a committed patch or an agent-generated follow-up — without leaving the PR
- The reviewer installs as a GitHub/GitLab app and posts reviews as native inline comments on my pull requests within minutes
- The reviewer catches real bugs in my PR — logic errors, race conditions, broken edge cases — not just style nits
- Push back on a bad review comment and the reviewer learns — it stops repeating the same rejected feedback
- The reviewer keeps noise low — few false positives, deduplicated comments, severity labels — so my team doesn't tune it out
- Reviews flag security problems in the diff — injection risks, leaked secrets, insecure patterns — alongside functional bugs
Security docs3 stories
Blog docs2 stories
Probe proofs — replayable recordings from the probe harnessProbe proofs
Replayable recordings from our probe harness — see the Prove-It protocol to submit one.
$curl -s https://cursor.com/llms.txt | head -6reproduced$ curl -s https://cursor.com/llms.txt | head -6 # Cursor Documentation ## Get Started - https://cursor.com/docs.md - https://cursor.com/docs/get-started/quickstart.md
$curl -sL https://cursor.com/docs/bugbot.md | head -6reproduced$ curl -sL https://cursor.com/docs/bugbot.md | head -6 # Bugbot Bugbot reviews pull requests and identifies bugs, security issues, and code quality problems. Configure Bugbot in [Automations](https://cursor.com/automations/from-cursor/bugbot).
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
4 of 12 testable claims verified · 2 contradicted → integrity 0/100
17 distinct capability claims found in Cursor Bugbot’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
4
Verified
6
Unverified
2
Contradicted
18
Undersold
Verified (6)
“Automatically re-reviews a PR whenever new commits are pushed”
Pushing new commits triggers an incremental re-review that tracks what was fixed instead of repeating old commentsfullproof ↗
“Reads existing top-level and inline PR comments to avoid repeating suggestions and build on prior feedback”
The reviewer keeps noise low — few false positives, deduplicated comments, severity labels — so my team doesn't tune it outpartialproof ↗
“Integrates with GitHub, including GitHub Enterprise Server, to review pull requests”
The reviewer installs as a GitHub/GitLab app and posts reviews as native inline comments on my pull requests within minutesfullproof ↗
“Integrates with GitLab, including GitLab Self-Hosted, to review merge requests”
The reviewer installs as a GitHub/GitLab app and posts reviews as native inline comments on my pull requests within minutesfullproof ↗
“Integrates with Bitbucket Cloud and Bitbucket Data Center repositories”
The reviewer installs as a GitHub/GitLab app and posts reviews as native inline comments on my pull requests within minutesfullproof ↗
“Analyzes every PR for bugs, security vulnerabilities, and code quality issues, leaving inline comments with explanations and suggested fixes”
Reviews flag security problems in the diff — injection risks, leaked secrets, insecure patterns — alongside functional bugsfullproof ↗
Unverified (7)
“Can be manually triggered by commenting 'cursor review' or 'bugbot run' on a PR”
I control when reviews run — skip drafts, trigger on demand, filter by branch or label — so the bot shows up only when wantedpartialproof ↗
“Fix in Cursor link opens the flagged issue directly in the Cursor editor”
Review findings hand off cleanly to my coding agent — copyable fix prompts or direct integration with Claude Code, Cursor, or Codexpartialproof ↗
“Fix in Web link opens the flagged issue directly in cursor.com/agents”
Review findings hand off cleanly to my coding agent — copyable fix prompts or direct integration with Claude Code, Cursor, or Codexpartialproof ↗
“Supports a BUGBOT.md file in the repo to give project-specific review guidelines”
I configure the reviewer with a versioned config file in my repo — path filters, per-path instructions, review profilespartialproof ↗
“Supports a BUGBOT.md file in the repo to give project-specific review guidelines”
I encode my team's own review guidelines — natural-language rules, AST patterns, or linked style guides — and the reviewer enforces themfullproof ↗
“Privacy Mode prevents Cursor from training on your data, available to any plan and inheritable by team members”
Prevent my data from being used to train AI modelspartialproof ↗
“Accounts and their data can be deleted at any time from the Settings dashboard”
Contradicted (2)
“Reviews pull requests opened by Cloud Agents, posting findings as PR comments”
The reviewer holds the line on AI-generated PRs — it verifies agent-authored code at a volume no human team could reviewdisputedproof ↗
“Analyzes every PR for bugs, security vulnerabilities, and code quality issues, leaving inline comments with explanations and suggested fixes”
The reviewer catches real bugs in my PR — logic errors, race conditions, broken edge cases — not just style nitsdisputedproof ↗
Undersold (18)
Point an agent at llms.txt or agent-oriented docsfullproof ↗
Run the product headlessly / in CI for automationpartialproof ↗
Get AI-generated insights and suggestions from my data inside the productfullproof ↗
Set up automations that run autonomously in the backgroundfullproof ↗
Delegate tasks to a built-in AI assistant inside the productpartialproof ↗
Operate the product with natural-language commandspartialproof ↗
I define custom agentic pre-merge checks in plain language — 'docs updated', 'tests cover new paths' — that run on every PRpartialproof ↗
I turn a review finding into an applied fix — a committed patch or an agent-generated follow-up — without leaving the PRpartialproof ↗
Perform bulk operations across many items at oncepartialproof ↗
Define rules that trigger actions automatically on eventspartialproof ↗
Review comments reflect the whole repository — call sites, related modules, existing conventions — not just the changed hunkspartialproof ↗
The reviewer builds a persistent memory of my team's conventions and past review decisions and applies it to future PRspartialproof ↗
I reply to the reviewer in the PR thread to ask questions, get explanations, or issue commands — and it answers in contextpartialproof ↗
Review comments include committable suggested diffs I can apply with one clickpartialproof ↗
I see dashboards of findings, acceptance rates, and review coverage across my orgpartialproof ↗
Push back on a bad review comment and the reviewer learns — it stops repeating the same rejected feedbackpartialproof ↗
I roll out org-level review defaults across hundreds of repos and manage exceptions centrallypartialproof ↗
Claims outside our story set (4)
Real capability claims found in Cursor Bugbot’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.
“Verbose trigger mode replies with a table listing which rules were applied in that review”
source ↗“With usage-based billing, users can configure Bugbot's effort level to run deeper, longer reviews”
source ↗“Natural-language instructions can dynamically set Bugbot's review effort level (low/default/high)”
source ↗“Usage-based billing can be enabled to run reviews on all PRs”
source ↗
Business model
Requires a paid Cursor plan (Pro $20/mo, Pro+ $60/mo, Ultra $200/mo); since May 2026 Bugbot bills usage-based at roughly $1.00-$1.50 per review run; Enterprise is custom.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Try Experimental
Run it in the microterminal →Recorded agent sessions — and a live MCP handshake where the vendor ships one.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
Agent surface uptime llms.txt up (tracking since Sep 11 '26)
