Skip to main content
Integrate CodeAnt AI into Cursor to resolve PR review comments, review local changes, and generate custom review rules - driven by Cursor’s AI agent.

What You Get

Four Cursor Skills that teach the AI agent how to use the CodeAnt CLI:
These skills run the CodeAnt CLI. To also give Cursor’s agent structured tools for scans, the Hotlist, cloud and pentest findings, and pull requests, add the CodeAnt MCP server to .cursor/mcp.json. The skills and the MCP server work together.

Prerequisites

  1. Cursor 2.4 or later - the new Skills system requires this minimum version (download)
  2. CodeAnt CLI installed and authenticated - follow the CLI setup guide

Installation

Run these commands from your project root:
Commit to share with your team:

Option 2: Create Manually

Create the skill files under .cursor/skills/ - see the full skill content in the skills repository. Each skill is a SKILL.md file inside its own directory:
If you previously installed the .mdc rule file to .cursor/rules/codeant.mdc, you can migrate to the new Skills format:
  1. Install the new skills using the instructions above
  2. Delete the old rule file: rm .cursor/rules/codeant.mdc
  3. Restart Cursor
The new Skills format provides slash command invocation, better discoverability, and feature parity with the Claude Code integration.

Usage

/codeant-resolve-pr-comments - Resolve PR Review Comments

Fetch all unresolved CodeAnt AI review comments on a pull request and fix them. With a PR number:
Auto-detect from current branch:
Or use natural language:
The fix flow:
  1. Find the PR - detects from current branch or uses the provided PR number
  2. Fetch comments - runs codeant pr comments --pr-number <N> --codeant-generated true and filters to unresolved comments
  3. Categorize - separates inline code comments (actionable) from general PR-level comments (informational, skipped)
  4. Analyze and assign verdicts - for each comment:
    • Reads the file with 30 lines of surrounding context
    • Checks the code still matches what the comment describes
    • Extracts code suggestions from the comment body
    • Validates syntax, variable scope, imports, and that existing logic is not broken
    • Assigns a verdict: ACCEPT, LIKELY ACCEPT, DO NOT ACCEPT, or STALE
  5. Present summary - shows all comments grouped by verdict with before/after code diffs
  6. Apply safe fixes - applies ACCEPT fixes, asks about LIKELY ACCEPT, skips DO NOT ACCEPT and STALE
  7. Resolve threads - marks applied comments as resolved on the PR via codeant pr resolve
  8. Offer to commit - lists changed files and offers to commit and push
Changes are not committed automatically - you review the diffs and decide.

/codeant-resolve-quality-gates - Fix CI/CD Quality Gate Failures

Locate the CodeAnt Quality Gate comment posted by CI on the current branch’s PR and fix the listed findings. With a PR number:
Auto-detect from current branch:
Or use natural language:
The fix flow:
  1. Find the PR - detects from current branch or uses the provided PR number
  2. Locate the comment - fetches CodeAnt comments and picks the most recent one whose body starts with CodeAnt Quality Gate Results
  3. Parse failures - extracts the list of failed gates from the summary table and the per-finding rows from the View Failure Result block (SAST, Secrets, Duplicate Code)
  4. Analyze and assign verdicts - for each finding:
    • Reads the file at the indicated line with 30 lines of context
    • Drafts a minimal fix (the comment contains no inline suggestion - the skill designs the fix from the rule / type / window)
    • Validates syntax, scope, error handling, and that existing behavior is preserved
    • Assigns a verdict: ACCEPT, LIKELY ACCEPT, DO NOT ACCEPT, or STALE
  5. Present summary - groups findings by verdict and gate type, shows before/after diffs
  6. Apply safe fixes - ACCEPT automatically, LIKELY ACCEPT with confirmation, skip the rest
  7. Offer to commit - pushing the fix commit re-triggers CI, which updates the quality gate comment
Coverage by gate: Changes are not committed automatically - you review the diffs and decide.

/codeant-review - Review and Fix Local Changes

Run a CodeAnt AI code review on your local changes and fix all issues found.
You can specify the review scope:
The skill selects the right flag based on your request: The fix flow:
  1. Run review - executes codeant review <scope-flag>
  2. Present findings - shows issues grouped by file with category labels (Security, Code Quality, Performance, Maintainability)
  3. Analyze and assign verdicts - classifies each issue as ACCEPT, LIKELY ACCEPT, DO NOT ACCEPT, or STALE
  4. Present summary with verdicts - shows before/after code diffs, highlights Security issues first
  5. Apply safe fixes - minimal changes only, skips anything that could break existing logic
  6. Verify - re-runs the review to confirm fixes are clean
  7. Report - initial findings, fixes applied, fixes skipped (and why), and verification results
Changes are not committed automatically - you review the diffs and commit when ready.

/codeant-implement-repo-learnings - Generate Custom Review Rules

Analyze your team’s PR review history to generate custom CodeAnt review rules.
The workflow:
  1. Fetch PR history - retrieves the last 100 merged PRs
  2. Extract human feedback - fetches review comments, filters out bots and non-actionable replies
  3. Analyze bug-fix commits - mines git history for recurring fix patterns
  4. Read project guidelines - extracts conventions from .cursorrules, CLAUDE.md, CONTRIBUTING.md, etc.
  5. Cluster patterns - groups feedback into rule candidates with confidence levels (HIGH/MEDIUM)
  6. Interactive confirmation - presents each rule with evidence for your approval
  7. Write rules - generates .codeant/review.json with your approved rules
Rules are merged with any existing .codeant/review.json - nothing is overwritten without confirmation.

Verdict System

All fix workflows use a verdict system to classify each suggestion before applying:

Example Workflows

Resolve PR Comments

Review → Fix → Ship

How It Works

Each skill is a SKILL.md file inside .cursor/skills/ - part of Cursor’s Agent Skills system. Skills teach the Cursor agent specialized workflows through detailed step-by-step instructions. Skills are automatically discovered by Cursor and can be invoked via /skill-name slash commands or triggered automatically when the agent determines they’re relevant. You can also reference them naturally in conversation (e.g., “review my changes with CodeAnt”).

Troubleshooting

“codeant: command not found” Ensure the CLI is installed globally and accessible from Cursor’s terminal:
If using nvm, ensure the correct Node version is active in Cursor’s integrated terminal. “Not authenticated” or “Could not detect remote”
Skills not appearing
  • Verify .cursor/skills/codeant-review/SKILL.md exists (and similar for other skills)
  • Restart Cursor after adding skills
  • Check Settings → Rules to see if skills appear under “Agent Decides”
  • Be explicit: “Use CodeAnt to review my changes” or use /codeant-review