GOVENANT
Free · read-only · Coding tool

Audit your Cursor agents.

Audit your Cursor agents for free by adding the GOVENANT Audit to your MCP config. Have Cursor’s agent run a read-only, aggregate-only governance sweep and tell you whether your AI system is actually shipping work — or just looking busy (performed autonomy).

Step 1

Add the audit to Cursor

Paste one URL — no API key. Cursor connects itself.

Step 2

Sign in

Automatic browser sign-in on first connect. That’s the whole ask.

Step 3

Ask for the audit

Say “Run a GOVENANT trust sweep.” Get a shareable report back.

Add the GOVENANT Audit to Cursor

The MCP server URL:

https://mcp.govenantstandard.org/mcp

Add to ~/.cursor/mcp.json:

{
  "mcpServers": {
    "govenant": { "url": "https://mcp.govenantstandard.org/mcp" }
  }
}
  1. Add the GOVENANT server to ~/.cursor/mcp.json (snippet above).
  2. Toggle the server on in Settings → MCP & Integrations.
  3. Cursor opens the sign-in automatically on first connect (GitHub or Google).
  4. Ask Cursor: “Run a GOVENANT trust sweep.”

Authentication: Automatic browser sign-in on first connect.

What the Cursor audit tells you

Anomalies first

The bad news up top: motion without delivery, missed work, approvals expiring unapproved, decisions never graded — the signs of performed autonomy.

Your grade

Where your Cursor agents land on the GOVENANT ladder — Logged → Gated → Delivered → Earned — and the delivery numbers behind it.

Delivery, not activity

Verified outcomes vs. total actions, work delivered vs. missed — measured against the record, never self-reported.

A shareable page

Every run has its own URL, with an optional one-click “share for a free expert review.”

Cursor audit — FAQ

Where does the Cursor MCP config live?
Global servers go in ~/.cursor/mcp.json; you can also scope one to a project in .cursor/mcp.json. Use the "url" key for a remote HTTP server like GOVENANT.
Do I need an API key?
No. You paste one URL; Cursor connects and opens the OAuth sign-in itself. The audit is free.
Is the GOVENANT Audit really free?
Yes. You sign in with GitHub or Google so we know who ran it — that’s the whole ask. No API key, no credit card, no paywall on the audit.
What does it read, and what does it never see?
It reads aggregate numbers from your agents’ own records: how many ran, how many finished, whether checks passed, which models you use. It never reads your prompts, your agents’ messages, your customers’ data, or any secrets.
What is “performed autonomy”?
Agents that look busy — fluent plans, satisfied logs — but don’t verifiably ship. Motion is not delivery. The audit measures verified outcomes against the record, never the logs’ self-report.

Using a different tool?

Prove your agents actually deliver.

Free under the covenant — the method is free forever. Read-only and aggregate-only: your prompts, data, and secrets never leave your machine.