How it works

Three steps from local audit evidence to a quarterly governance roadmap and radar.

Step 1

Run the Cursor audit locally

Paste CURSOR_REVIEW_PROMPT.md into Cursor against your repo. Collect evidence-backed JSON (file:line). Mark CVE/coverage/flaky fields needs scan until tools have run.

Step 2

Paste findings and score four axes

Drop scores for code, architecture, test, and documentation (0–100, higher = healthier). Optional targets draw a second radar polygon. Free path stays fully deterministic.

Step 3

Ship a quarterly plan with rollback

Review actions with effort, benefit, risk, and rollback. Pro adds a model-assisted narrative labelled as such — never a silent mock. Architects still own final design.

Honesty: decision-support only — no guarantee of remediation outcomes or 100% debt coverage. See Security for fail-closed AI behaviour.

Was this result helpful?Detailed feedback