plugin-cursor — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited plugin-cursor (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Every AI action receipted. Capability-gated. Rollback-ready.
AI Governance-as-a-Service via MCP. Every write, shell command, and state-changing operation your agent makes is validated before it runs and cryptographically receipted after it completes — giving you a tamper-evident audit trail you can query, export, or roll back at any time.
Works with Claude Code, Codex, Cursor, Windsurf, and any MCP-compatible agent.
npm install dingdawg-governance# Authenticate (free — no credit card)
npx dingdawg-governance auth login
# Start the governance MCP server
DINGDAWG_API_KEY=your_key npx dingdawg-governanceAdd to your MCP client config:
{
"mcpServers": {
"dingdawg-governance": {
"command": "npx",
"args": ["dingdawg-governance"],
"env": {
"DINGDAWG_API_KEY": "your_key_here"
}
}
}
}Get your free API key at app.dingdawg.com/settings/api.
| Tool | What it does |
|---|---|
validate_action | Pre-execution check. Returns APPROVED, FLAGGED, or BLOCKED with reason code and risk score. |
generate_receipt | Post-execution cryptographic receipt with tamper-evident output hash. |
capture_rollback_state | Snapshot current state before destructive or high-risk operations. |
rollback_action | Restore prior state from a receipt ID. |
query_receipts | Search receipts by date, agent, action type, or status. Export-ready. |
check_status | Current tier, daily usage, quota, and active governance alerts. |
generate_audit_report | On-demand compliance report — SOC 2, ISO 27001, or custom policy framework. |
| Plan | Governed actions/day | Rollback window | Audit reports |
|---|---|---|---|
| Free | 200 | — | — |
| Pro — $29/mo | 10,000 | 30 days | Unlimited |
| Business — $149/mo | Unlimited | 90 days | Compliance PDF |
No credit card to start. Full pricing: dingdawg.com/governance#pricing
Full docs at [dingdawg.com/governance/docs](https://dingdawg.com/governance/docs)
Issues and pull requests welcome. See CONTRIBUTING.md.
github.com/dingdawg/governance-mcp
Built by DingDawg — Trust layer for the agentic internet.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.