Track lessons
Configure .cursor/BUGBOT.md for Pull Request Reviews
Generic PR review advice misses the risks unique to your repository. BUGBOT.md gives Cursor Bugbot review-specific instructions without mixing them with editor rules used while writing code.
When to use
- Flag repository-specific authorization or tenancy mistakes.
- Ignore formatting already enforced by automation.
- Apply stricter review checks inside a sensitive folder.
Example
A multi-tenant API asks Bugbot to flag tenant IDs taken from request bodies and SQL built through string concatenation, while ignoring style noise.
TL;DR
Bugbot reads .cursor/BUGBOT.md, not your editor rules. Put review rules there.
mkdir -p .cursor && $EDITOR .cursor/BUGBOT.mdSteps
- 1
Write review rules
State observable conditions Bugbot should flag or ignore. Prefer repository risks over general style preferences.
.cursor/BUGBOT.md# Review rules - Flag any endpoint that reads tenant_id from the request body. - Flag SQL built with string concatenation. - Flag new dependencies without a lockfile change. - Ignore formatting; the linter handles it. - Every bug fix must include a regression test. - 2
Add folder-specific rules
Nested BUGBOT.md files apply when files in that folder change.
pathsrc/billing/.cursor/BUGBOT.md - 3
Trigger a review on a PR
Post the supported trigger in the pull request when you need Bugbot to run again after new commits or updated rules.
PR commentcursor review
Gotchas
- .cursor/rules/*.mdc do not configure Bugbot; BUGBOT.md does.
- Write rules as things to flag, not general style advice.
- Bugbot must be enabled for the repository in Cursor's dashboard first.
Cheat sheet
| .cursor/BUGBOT.md | Repo-wide review rules |
| <dir>/.cursor/BUGBOT.md | Folder rules |
| cursor review / bugbot run | Manual trigger comment |
Related
Sources
Reviewing agent output? CodeCrab reviews pull requests locally with your own AI tools.
