Cursor MCP
The Aikido MCP Plugin connects Aikido’s security engine to AI coding tools. It automatically scans AI generated code for vulnerabilities and hardcoded secrets as soon as it is created.
AI assistants can review their own output, but that review is not perfect. Aikido adds a reliable and consistent security layer that checks every generated snippet with proven scanning rules.
Why use Aikido MCP
Deterministic, independent security checks on every AI generated snippet before it is committed
Immediate detection and remediation of vulnerabilities and hardcoded secrets in AI assisted workflows
Real time feedback, making AI driven development safer by default
aikido_full_scan: Scans local code files for vulnerabilities (SAST) and hardcoded secrets.
aikido_issues_list: Fetches security issues from your Aikido feed.
Filter by one scope: repo_name, cloud_name, vm_name, domain_name, or container_name
Pick one or more issue types: sast, leaked_secret, iac, open_source, cloud, cloud_instance, docker_container, malware, eol, mobile, surface_monitoring, scm_security, license, ai_pentest
Returns each issue with title, type, severity, and remediation steps
Installation
Via Aikido IDE Expansion Packs (recommended)
The easiest way to add the Aikido MCP to Cursor is through the Aikido IDE plugin's Expansion Packs. This handles configuration automatically without any manual setup.
Cursor IDEOnce the plugin is installed, open the Aikido sidebar and go to Aikido Cursor Plugin to enable the Aikido MCP server.
Learn more about Expansion Packs
Via Cursor Marketplace
You can also install Aikido MCP directly from the Cursor Marketplace.
Create an Aikido MCP token
In Aikido, go to Settings → Integrations → IDE → MCP and create a Personal Access Token.
Add via Cursor Marketplace
Open Aikido on the Cursor Marketplace and click Add to Cursor.
When prompted, add your token as the AIKIDO_API_KEY environment variable.
Add custom instructions
Add an instruction to your .cursorrules file or Cursor custom instructions to ensure the agent uses the MCP server.
Scanning code
"Use Aikido to scan this file for security issues"
"Run an Aikido scan on my staged changes to check for secrets before I commit"
"Scan the files I just edited with Aikido and link them to the
payments-apirepo"
Reviewing issues by repo
"Show me all critical Aikido issues in
payments-api""List any leaked secrets in
frontend-webfrom Aikido""What open source vulnerabilities does Aikido see in
api-gateway?""Show SAST and IaC issues in
infra-corefrom Aikido"
Reviewing issues by cloud, VM, or container
"List all Aikido cloud issues in
prod-aws""Show malware findings on
web-server-01from Aikido""What end-of-life software is running in the
nginx-proxycontainer per Aikido?""Show me surface monitoring issues for
example.comin Aikido"
Combined workflows
"Use Aikido to scan my current changes, then show existing critical issues in the same repo"
"Check this PR with Aikido and compare against open SAST issues in the repo"
Manual installation
For any custom setup, refer to the npm package page for detailed manual installation instructions.
Last updated
Was this helpful?