Findings by source

Cursor

Code · GitHub (demo) Anysphere · Coding · config: Cursor rules

Policy · none set
Policy changes re-score this app on the next sync, which starts right away.
Finding · Open
Risk score
31
Medium
People
0
Committers are not collected
Repositories
1
0 public · 0 packages
Keys in code
0
None found in the files read
source-codefixturecoding-assistantcorroborated
Next steps

Recommended actions

  1. 01Cursor trains on data unless a business tier or opt-out is used. Verify which tier these users are on.
  2. 02Cursor is configured for this codebase. Set a policy on AI coding tools: which are approved, whether repository context may leave the company, and whether generated code needs review flags.
GitHub (demo) · fixture

Where it lives in code

Assistant config · 1
Repositories
RepositorySignalsPushed
contoso/customer-portalAssistant config27 h ago
Configuration
Cursor rules1 repo
Same app, other lanes

Related findings

  • Medium48CursorEndpoint2 people
  • Medium31CursorVendor account6 people
Who

People

Identifiers come from device telemetry and proxy logs, so they may be account names rather than full directory entries.

No people are linked to this app.

Why

Evidence

  1. source_code · Sep 13, 2026
    Cursor in 1 repository via GitHub (demo): Cursor rules
    Detail
    {
      "repos": [
        "contoso/customer-portal"
      ],
      "configs": [
        {
          "path": "Cursor rules",
          "repos": 1
        }
      ],
      "packages": [],
      "endpoints": []
    }
  2. corroboration
    Also found by another lane (mde:cursor)
    Detail
    {
      "findingKey": "mde:cursor"
    }