VulX Watch for Cursor
MCP serverSecurityGet an independent security review of the apps your AI builds. Once added, your AI can have a GitHub repository watched and checked for security problems. Watch only reviews the code — it never applies patches or makes changes itself.
Available today. Use it from your connected AI after setup.
No other account needed.
After adding Watch, point it at the GitHub repository you want reviewed. It will take care of the security review from there.
Then ask your AI: use VulX Watch for Cursor
What your AI can do with it
- Review a GitHub repository for security problems
- Independently check apps your AI built
- Flag security issues in your code
- Report problems without ever patching the code
From the project's README
As published by ngotomek/vulx-watch-cursor in README.md.
Adds the VulX Watch connector to Cursor: independent security review for AI-built apps. The agent can watch a GitHub repo and ask what the last reading found.
VulX does not write a patch or open a PR.
What you get
- MCP server at
https://mcp.vulx.ai/mcp - A skill so the agent knows when to call Watch
- Commands: watch-repo, security-status
You still need a VulX account. Sign-in happens when Cursor talks to the connector. Free while we build it.
Install
- Install VulX Watch from the Cursor Marketplace, or clone this repo
into
~/.cursor/plugins/localand restart Cursor. - Complete the VulX sign-in prompt.
- Ask:
Watch my repo owner/name with VulX.Then:What did VulX find?
If OAuth does not finish inside Cursor, add the same URL as a custom
connector: https://mcp.vulx.ai/mcp. Human page: https://vulx.ai/connect
What it will not do
- Patch your app or open a merge-ready PR
- Log in to your running site or database
- Give a 0–100 score or a “safe to ship”
- Treat a quiet week as an all-clear
It reads committed source. It writes only its own brief (AGENTS.md and
CLAUDE.md) when brief delivery is on.
License
MIT
Signals
- Last commit
- Sep 2026
Advanced
- Delivery
- watch MCP server → your ahel gateway (mcp.ahel.ai) → every connected AI client.
- Catalog kind
- mcp-server
- Gateway key
ai-vulx-watch- Source
- github.com/ngotomek/vulx-watch-cursor
- Hosted endpoint
https://mcp.vulx.ai/mcp