CHAPTER 13 · Code Review and Security Agents · 1 / 9
Bugbot: an agent wired into the pull request
Bugbot reviews pull requests and leaves comments with explanations and fix suggestions. The mechanics are a clean example of an agent living inside an existing workflow rather than a chat window:
- It runs automatically on every PR update, or on demand when someone comments
cursor review. - It reads existing PR comments as context, so it avoids duplicate suggestions and builds on prior feedback.
- It publishes a CI status (
success,neutral,failure) so it can gate merges through branch protection. - It supports incremental review (only the diff since its last review) to save work, and effort levels that trade reasoning time for thoroughness.
The configuration design is worth noting because it reuses Chapter 9's memory ideas. Bugbot reads .cursor/BUGBOT.md files, including nested ones traversed up from changed files, exactly the "more specific wins" pattern. It also has learned rules: it generates rules from your team's activity, and you can teach it inline by commenting @cursor remember [fact] on a PR, which it saves and applies to future reviews. That is auto-memory (Chapter 9) aimed at a review agent. Rules can be scoped to glob paths, and rule analytics track how often each rule's findings get accepted, so a noisy rule can be spotted and pruned.