Cursor Mcp Bridge — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Cursor Mcp Bridge (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server that lets any agent or MCP host delegate to the Cursor CLI agent (agent -p) running headless. Cursor is the cheap/fast worker in the fleet — use it for routine work and to map unfamiliar projects without burning your own context.
Mirrors the ergonomics of agy-bridge: every tool takes an optional model and effort, returns a session_id, and supports follow_up. Default model is `auto` (Cursor picks the cheapest adequate model).
| Tool | Purpose |
|---|---|
delegate | Run a task on the Cursor agent with full tool access in cwd. |
explore | Read-only exploration. No files → general project map; with files → answer about those files. The cheap counterpart to Claude's Explore. |
web_lookup | Web/docs lookup via the Cursor agent's web access. |
follow_up | Continue a prior session by session_id. |
Every tool accepts: cwd, model (default auto), effort (applied only to parameterized models; auto ignores it).
agent and authenticated (agent login).git clone https://github.com/JaimeJunr/cursor-mcp-bridge.git
cd cursor-mcp-bridge
npm install
npm run buildClaude Code:
claude mcp add cursor-bridge -s user -- node /abs/path/to/cursor-mcp-bridge/dist/index.jsAny host — add to its mcp.json:
{
"mcpServers": {
"cursor-bridge": {
"command": "node",
"args": ["/abs/path/to/cursor-mcp-bridge/dist/index.js"]
}
}
}| Var | Default | Meaning |
|---|---|---|
CURSOR_BIN | agent | Path to the Cursor CLI binary. |
CURSOR_BRIDGE_MODEL | auto | Default model when a call omits model. |
CURSOR_BRIDGE_FORCE | _(off)_ | If 1/true, pass --force so commands run without prompts. |
CURSOR_BRIDGE_TIMEOUT_MS | 600000 | Per-call timeout. |
Security:delegatecan edit files and (withCURSOR_BRIDGE_FORCE) run shell autonomously.discoveryandanalyze_filesrun in read-only modes (plan/ask).
npm test # vitest — unit tests for model resolution / arg building
npm run dev # run from source via tsxMIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.