CHAPTER 13 · Code Review and Security Agents · 2 / 9
Cursor's security agents and the 15-line prompt
Snyk's analysis of Cursor's four open-sourced security agents contains the most quietly profound lesson in this whole collection. Cursor's security team built agents that review 3,000-plus PRs per week and catch 200-plus real vulnerabilities. The prompt driving the flagship reviewer is fifteen lines: a role ("you are a security reviewer for pull requests"), a goal, a four-step methodology (inspect the diff, trace attacker-controlled input to a real sink, check whether existing controls already block it, report only medium/high/critical findings with a concrete attack path), and a priority list of vulnerability classes.
No elaborate chain-of-thought scaffolding. No pages of examples. No complex output schema. Why does so little work? Because the model already knows what SQL injection and auth bypass look like; it just needs a framework to apply that knowledge systematically. As Snyk puts it, "the prompt is simple because the surrounding infrastructure is not." Underneath those fifteen lines sit a custom MCP server for state and deduplication, a Terraform-managed deployment, webhook orchestration deciding which agent to trigger when, and state that lets agents compare findings across runs. This is Chapter 1's thesis proven in the field: the harness is the product, the prompt is the tip of the iceberg.
The four agents map to four jobs:
| Agent | Job |
|---|---|
| Agentic Security Review | Reviews every PR against the team's threat model; posts to Slack, comments on the PR, can block CI |
| Vuln Hunter | Scans the existing codebase (not just new diffs), segment by segment |
| Anybump | Automated dependency patching: reachability analysis, test, open a PR only when confidence is high |
| Invariant Sentinel | Daily drift detection against security and compliance properties, using memory to compare across runs |