Trustabl for Cursor

Trustabl for Cursor

MCP server that brings Trustabl static reliability scanning into Cursor, letting agents inventory agents/tools, flag risky patterns, score production readiness, and write SARIF reports.

Category
访问服务器

README

Trustabl for Cursor

Bring Trustabl — the static reliability & safety scanner for AI-agent codebases — into Cursor.

The plugin adds an MCP server whose tools the Cursor agent can call. Ask it to "scan this repo with Trustabl" and it inventories your agents, tools, and MCP servers, flags risky patterns with severities, scores production readiness, and writes a SARIF 2.1.0 report into your workspace so the findings render in a SARIF viewer as well as in chat.

Detects Claude Agent SDK, OpenAI Agents SDK, Google ADK, LangChain, CrewAI, Pydantic AI, Vercel AI, AutoGen, MCP servers, and Claude subagents & skills.

How it works

flowchart TD
    U["You <br/><i>&quot;scan this repo with Trustabl&quot;</i>"] --> A["Cursor Agent"]
    A -->|"MCP tool call<br/>trustabl_scan"| S["Trustabl MCP server<br/><code>dist/index.js</code> · stdio"]

    S --> B{"trustabl binary<br/>available?"}
    B -->|"on PATH"| SCAN
    B -->|"no"| D["Download release asset<br/>+ verify sha256<br/>cache in ~/.trustabl-cursor"]
    D --> SCAN["<b>trustabl scan</b><br/>single pass · --sarif-out · --json-out"]

    SCAN --> R["Report table · readiness score<br/>severity breakdown · findings"]
    R -->|"returned in the tool result"| A
    R -->|"written to disk"| F["trustabl.sarif<br/>trustabl.json<br/>trustabl-report.txt"]
    F --> V["SARIF viewer /<br/>Problems panel"]
    A --> U

    classDef plugin fill:#1f6feb,stroke:#1f6feb,color:#fff
    classDef output fill:#238636,stroke:#238636,color:#fff
    class S,SCAN plugin
    class F,V,R output

A failed download or a checksum mismatch aborts the scan — the plugin never runs an unverified binary.

Install

Three ways, same result. Pick one.

Best for
1. Plugin directory Most people — one click, updates handled by Cursor.
2. Local plugin folder Trying it before it's published, or running a fork.
3. Plain MCP server Skipping the plugin system, or using a client other than Cursor.

1. From the Cursor plugin directory

  1. In Cursor, open Customize (Settings → the "Plugins, MCPs, Skills and Rules have moved to Customize" banner links there too).
  2. Browse Marketplace → search Trustabl → Install.

2. From this repo, as a local plugin

Clone it into Cursor's local plugin folder and restart Cursor:

git clone https://github.com/trustabl/trustabl-cursor.git
# macOS / Linux
cp -r trustabl-cursor ~/.cursor/plugins/local/
# Windows (PowerShell)
Copy-Item -Recurse trustabl-cursor "$HOME\.cursor\plugins\local\"

Cursor auto-detects .cursor-plugin/plugin.json and mcp.json. No build step and no npm install — the server ships pre-bundled.

3. As a plain MCP server

Registers the server directly, bypassing the plugin system entirely. Clone the repo anywhere, then add it to ~/.cursor/mcp.json (global) or <your-project>/.cursor/mcp.json (that project only), using the absolute path to the clone:

{
  "mcpServers": {
    "trustabl": {
      "command": "node",
      "args": ["/absolute/path/to/trustabl-cursor/dist/index.js"]
    }
  }
}

On Windows use forward slashes: C:/Users/you/trustabl-cursor/dist/index.js. Restart Cursor.

The same block works in any MCP client — Claude Code, Windsurf, VS Code — since it is a standard stdio MCP server. Set TRUSTABL_VERSION / GITHUB_TOKEN under an "env" key here rather than in Cursor's plugin settings.

Check it's working

Customize → Plugins → Trustabl Cursor. Under MCPs you should see:

trustabl  ● 2 tools enabled

A green dot means the server started. If it's red, open Configure → Show Output for the error (see Troubleshooting). With method 3 the server appears under Customize → MCPs instead of under a plugin.

Nothing else to set up: the trustabl binary is downloaded and sha256-verified on first scan, then cached in ~/.trustabl-cursor/.

Using it in chat

Open the repo you want to check, start a chat (Ctrl/Cmd + L), and ask for a scan in plain language:

Scan this repository with Trustabl and summarise the high-severity findings.

The agent calls trustabl_scan and replies with the severity table, the readiness score, and the findings. The first scan on a machine also downloads the scanner (~14 MB); later scans skip straight to scanning — around 20 seconds for a large repo.

Other prompts that work well:

Scan ./services/agent with Trustabl.

Scan this repo with Trustabl, then fix the highest-severity finding.

Scan with Trustabl using only the mcp and claude_sdk detectors.

Show me the findings from the last Trustabl scan. ← no re-scan

Because findings come back as structured data with file paths and line numbers, the agent can jump straight to the code and propose fixes — ask it to fix what it found and it will.

After a scan, three files land in the scanned directory:

File Use
trustabl.sarif Open with a SARIF viewer extension to see findings inline on your code.
trustabl.json Full machine-readable results — every finding, not just the ones shown in chat.
trustabl-report.txt The complete console report, ready to paste into a ticket.

Tools

Tool What it does
trustabl_scan Scan a directory. Returns a severity table, the readiness score, the scan report, and findings (worst first); writes trustabl.sarif, trustabl.json, and trustabl-report.txt into the scanned directory.
trustabl_last_findings Return the SARIF from the previous scan without re-running it.

trustabl_scan parameters — all optional:

Name Default Description
path current workspace Directory to scan.
detectors (all) Comma-separated SDK subset, e.g. claude_sdk,openai_sdk,mcp.
strict false Report any finding, however minor.

Large scans return the worst 50 findings inline, and the scan report is excerpted, to keep the agent's context usable — the complete set is always in trustabl.json / trustabl.sarif / trustabl-report.txt.

Example of what comes back:

## Trustabl scan — /path/to/repo

**Readiness 91/100** · risk 9 · 454 findings · max severity `high` · **gated**

| severity | count | share
|----------|-------|------
| critical |     0 |
| high     |    97 | ████
| medium   |    24 | █
| low      |   317 | ██████████████
| info     |    16 | █
| **total**|   454 |

Configuration

Both optional, set in Cursor's plugin settings:

Variable Default Description
TRUSTABL_VERSION latest Release tag to run, e.g. v0.1.6. Pin it for reproducible results.
GITHUB_TOKEN (none) Only used to download the release binary; avoids GitHub's 60-requests/hour anonymous limit.

TRUSTABL_BIN (env) forces a specific binary — useful if you already have trustabl installed somewhere non-standard.

Development

cd server
npm install
npm run build     # bundles to ../dist/index.js (commit the result)

dist/index.js is committed because Cursor runs the server directly from the installed plugin — it does not install npm dependencies. The bundle has no runtime dependencies. Rebuild and commit dist/ after changing anything in server/.

Test the server without Cursor:

npx @modelcontextprotocol/inspector node dist/index.js

Troubleshooting

The tools don't appear in Cursor. Open Customize → Trustabl Cursor → Configure → Show Output to see why the server exited. If the error is Cannot find module '...${PLUGIN_ROOT}...', your Cursor build doesn't expand that variable — replace cwd in mcp.json with an absolute path to the plugin folder.

Changed something and the fix didn't take. MCP servers don't hot-reload: Configure → Reload (or restart Cursor) after editing the plugin.

"Could not resolve the latest trustabl release." GitHub rate-limited the anonymous API call — set GITHUB_TOKEN, or pin TRUSTABL_VERSION to a tag.

Windows. Supported (amd64). The release .zip is unpacked with PowerShell's Expand-Archive; macOS and Linux use tar.

License

Proprietary — see LICENSE. The Trustabl scanner itself is Apache-2.0.

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选