The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the VulX Watch listing page.
Adds the VulX Watch connector to Cursor: independent security review for AI-built apps. The agent can watch a GitHub repo and ask what the last reading found.
VulX does not write a patch or open a PR.
https://mcp.vulx.ai/mcpYou still need a VulX account. Sign-in happens when Cursor talks to the connector. Free while we build it.
~/.cursor/plugins/local and restart Cursor.Watch my repo owner/name with VulX. Then: What did VulX find?If OAuth does not finish inside Cursor, add the same URL as a custom
connector: https://mcp.vulx.ai/mcp. Human page: https://vulx.ai/connect
It reads committed source. It writes only its own brief (AGENTS.md and
CLAUDE.md) when brief delivery is on.
MIT