DRIFTSEAL/ 01
TECHNICAL NOTES / V0.1

Cursor MCP security

Track changes to the components behind your editor's agent tools.

Record the approved surface

Scan public server packages or paste explicit tool metadata. Retain source/artifact fingerprints, descriptions, schemas and capability indicators so a later change can be compared with an actual approval.

Use evidence in code review

The local CLI and GitHub Action can compare approved configuration manifests in CI. Private repository files need not leave the workstation. DriftSeal does not change Cursor settings or claim affiliation with its vendor.

What a clean result means

DriftSeal provides automated technical analysis and monitoring. It does not guarantee that software is secure. A clean DriftSeal result means only that no material issue or drift was detected by the active ruleset and coverage available during that scan.

Establish your baseline.

Inspect a public component or use the local CLI for private source.

Scan a component — free ↗
YOUR TRUST LEDGER

Keep watch.

Sign in with a one-time email link. No password to remember.