Skip to content
nerlo.ai

Cursor

This page lists the packages that declare Cursor as their target: Cursor Rules and the MCP servers Cursor connects to. We track Cursor Rules as their own package kind, separate from MCP servers.

We run the same scanner suite on every one: agent and MCP config safety (agentshield), OWASP Agentic and MCP top-10 auditing (agent-audit-kit), known-vulnerable dependencies (osv-scanner, trivy), data-flow SAST (bearer), and detectors we wrote ourselves: nerlo-behavioral, which looks for obfuscated decode-then-exec code, and nerlo-install-instruction, which looks for install docs that direct you to run a bundled or fetched file.

We show every scanner's verdict separately at one flat rank. The composite score is a subordinate summary; it never hides a finding.

We track 9,078 packages that target Cursor, out of 47,540 registry-wide.

No findings does not mean no risk. Nerlo aggregates automated scanner output; automated scanning is one layer of defence, not a substitute for review.

Explore Cursor Packages

Filter by security badge, search packages by keyword or publisher, and inspect side-by-side scanner scorecards for all Cursor packages in the primary registry.

Browse all Cursor packages in Registry →