Skip to main content
Use Cursor Cloud agents to investigate vulnerabilities and prepare pull requests. Your service receives an Antigen webhook, retrieves the vulnerability, and starts an agent through the Cursor API. The agent runs in Cursor’s environment. Your service controls when it starts and updates the vulnerability’s status and assignment as work progresses.

Before you start

You need:
  • Cursor Cloud agent access and an API key.
  • A repository connected to Cursor, with an environment configured for the agent’s work.
  • An Antigen API key for reading vulnerabilities and updating them.
  • A service that can receive Antigen webhooks.
Keep both API keys in your service’s secret storage. See Cursor’s Cloud Agent API for API access and authentication.

Set up the workflow

1. Choose when to start work

Register a webhook pointing to your service. Choose the event that should start your workflow, such as a vulnerability entering Open or being assigned to your agent. Your handler checks the event before starting work. For assignment events, check that the new assignee is the agent your service handles. If you are replacing a default triage or remediation workflow, disable the corresponding default hook in the platform or via the API. See Assigning to your own agents for the available triggers.

2. Launch a Cursor Cloud agent

Use the Antigen API to retrieve the vulnerability and its evidence. Select the affected repository and include the relevant context in the agent’s instructions. For example, ask the agent to reproduce the reported behavior, inspect the affected code, and prepare a pull request with a fix and tests. Start the agent through the Cursor API. Save the returned agent identifier alongside the vulnerability ID so your service can follow its progress and associate the result with the right vulnerability.

3. Update the vulnerability

Your service follows the agent’s progress through the Cursor API. Create a human task through the Antigen API to request your team’s review, including the pull request or proposed infrastructure change. When the fix has been deployed, move the vulnerability to Remediated to start verification if the default verification hook is enabled.

Ask your team for help

The agent or your service can create human tasks through the Antigen API to request access, a review, or an infrastructure change. Those requests use the same connected messaging and issue tracking tools as tasks from the pre-built agents.

Troubleshooting

The agent cannot access the repository

Check the repository access granted to Cursor and its Cloud agent environment. The agent needs the dependencies and credentials required to inspect and test the code.

A result appears on the wrong vulnerability

Check the association your service stores between the Antigen vulnerability ID and the Cursor agent identifier. Use that association when processing later updates.