From a recorded Cursor build

Cursor missed 22 issues in its own plan. Here’s how you catch them in yours.

No code to write. Works inside the Cursor chat you already use.

Try it free on your project

Free account. Your first review is free, no card needed.

What the independent reviewers caught

Cursor reads findings like these and decides what to fix. The small line on each card is the finding exactly as it was recorded.

  • CriticalSecurity

    A repo's own git config could run code on your machine during normal commands.

    As recorded: Git config runs arbitrary code during normal commands

    Caught by: judge only

  • CriticalOperational

    A force-push could create duplicate PRs or endless retries.

    As recorded: Force-push breaks state tracking: duplicate PRs or retry loops

    Caught by: multi-engine consensus

  • CriticalSecurity

    A huge repo could crash the tool by running git with no limits.

    As recorded: Git commands with no timeout or output limit. Huge repo = out of memory…

    Caught by: DeepSeek only

  • HighSecurity

    Another program on your computer could hijack the GitHub login.

    As recorded: The plan uses a fixed port (8765) for the OAuth callback. Any other program on the same machine can bind that port first…

    Caught by: judge only

From a recorded build. Cursor’s own security review found 23 issues; independent reviewers found 45. Full comparison here.

Watch the same review process, recorded · 1:09 · no sound

A sped-up screen recording of the Claude Code build from the same comparison. There is no published recording of the Cursor run; its findings are in the full comparison linked above. The clip runs 1 minute 9 seconds with no sound; the build itself took a lot longer.

Three steps, about two minutes

1

Create a free account

Sign up free. No card needed, and your first review is on us.

2

Connect it to your coding tool

One command, pasted into the terminal on the computer where you use Cursor. This step needs that computer, not your phone.

Paste into your terminal
npx megalens-mcp setup

It finds Cursor, asks for your connection token, which you copy from your MegaLens settings, and writes the config file for you. Then restart Cursor and type run megalens_status in the chat. A reply means you are connected. Prefer to paste the config into .cursor/mcp.json yourself? The Cursor guide has the exact snippet.

Using Claude Code or Codex? Same thing, here’s how: Claude Code · Codex

3

Ask for a review in plain English

Type either of these into your chat. Your coding tool takes it from there.

Review this plan with MegaLens before we build

Run a MegaLens security audit on what we just built

Example of what comes back in your chat

> Review this plan with MegaLens before we build

megalens_debate · done

Independent reviewers returned findings, including:

[Critical] Git config runs arbitrary code during normal commands

[Critical] Force-push breaks state tracking: duplicate PRs or retry loops

I checked these against the plan. Both hold up. Updating the plan before we build.

Shown as text, not a screenshot. The two findings are real, from the recorded build.

What happens next

  • The findings come back into your chat.
  • Cursor reads them and decides what to fix.
  • You stay in the same conversation.

You never leave your IDE. You never read a report.

Findings like these, on your own project, in the chat you already use.

Try it free on your project

First review free. Then $5 credit for $0.50, or bring your own key.

Questions

Do I need to know how to code?
No. You run one setup command, then ask for reviews in plain English inside the chat you already use. Your coding tool reads the findings and handles the fixes.
What is an MCP?
A small add-on that lets your coding tool talk to an outside service. The setup command in step 2 installs it for you, and after that you just type normal English.
How can I try it?
Create a free account and run your first review with no card and no API key. It covers up to 35,000 tokens of input, which is a plan or a few files. After that, verify a card for $0.50 and get $5 in credit, or connect your own OpenRouter key and review with no MegaLens charges at all.
Will it send my code somewhere?
Yes. The code you ask about is sent to the AI models that review it. Your review history is kept for 30 days on the free plan and 90 days on paid plans, then deleted automatically. Details are in the privacy policy.
Does it replace Cursor?
No. It adds independent reviewers to it. Cursor still writes the code and still decides which findings to act on.
What does it cost after the free review?

Two ways to pay, no subscription needed for either.

Pay as you go: you keep a balance with MegaLens and each review is charged from it. In a recorded Claude Code build, the plan review cost $1.25, the mid-build code review $1.23, and the final security review $0.84, so $3.32 for the whole build. Your free review comes first, and $5 in credit covers a build like that.

Bring your own key: connect your OpenRouter key and pay the AI providers directly, roughly $1.50 to $2 for the same three reviews, with two reviewers plus a judge instead of three. MegaLens charges nothing on this path.

Pro at $15 a month adds a deeper review with five models per run, live-data specialists like Perplexity and Grok, automatic fix routing in Claude Code and Codex, and no daily limit on reviews. Full details on the pricing page.

Want to check the numbers for yourself? The full comparison lists every major finding from both builds, which reviewer caught each one, and what each IDE missed on its own. Read the full comparison