All posts

June 5, 2026 · 4 min read

Cursor Just Shipped a Dedicated Security Review Command. Here's Where That Puts It on the Spectrum I've Been Tracking All Year.

Cursor 3.7 shipped today with a dedicated Security Review mode, reachable through a /review command. I wrote three months ago about Cursor's Bugbot gaining Autofix, the ability to spin up its own agent to test and patch findings. This is a further, more explicit step in the same direction: security-specific review, now a named, deliberate feature rather than a side effect of general code review.

Where this lands on the spectrum I've been tracking all year

I compared the major platforms just a couple days ago on exactly this axis: does the check run automatically, or does it require the builder to already know to reach for it. A /review command is, by its nature, opt-in. It's the same category as Claude Code's /security-review, genuinely capable, requiring someone to specifically invoke it. That's not a criticism of the feature itself, which sounds like real, substantive progress. It's a note on which half of the builder population it's actually positioned to help.

Why I keep coming back to this specific distinction

Every single incident I've written about this year happened to someone who never had a check run before launch. Not because the checks didn't exist somewhere in some tool. Because whatever check existed required the person to already know it was worth asking for, and they didn't. A command this capable is a genuine gift to the builder who's already internalized "I should check this," a group I wrote about in April as slowly, visibly growing. It does nothing extra for the builder who hasn't gotten there yet, which is still, by every account I have, most of the people this blog is actually trying to reach.

What would actually change my read on this

If Cursor eventually runs some version of this automatically at a meaningful moment, before a deploy, before sharing a public link, the way Lovable and Bolt do at publish time, that would shift it into the category I've consistently said moves the needle most. Until then, it's a genuinely strong tool for the builder who already knows to look for it, and exactly as invisible as every other opt-in feature to the builder who doesn't.

What's actually worth doing with it right now

If you use Cursor, build the habit of running /review before anything meaningful ships, the same advice I gave for Claude Code's command back in March. Don't wait for it to become automatic. The tool is real and it's free to use today. The only thing standing between it and your next deploy is remembering to type the command, which is exactly the gap this whole blog keeps trying to close.

Related reading

Harbova is a security service for apps built with AI tools. Start with a free scan, and if it finds something serious, we can fix it and prove it is closed.