
Key Takeaways
- Zenity is now listed on the Cursor Marketplace. All Cursor users have visibility into every Model Context Protocol (MCP) server their agents connect to.
- Model Context Protocol is the foundation for tool-using enterprise agents. MCP adoption has skyrocketed to millions of downloads per month
- Unified visibility, assembled natively in the Cursor desktop. Using webhooks and OpenTelemetry (OTEL) based events, Zenity builds a live inventory record mapping each Cursor agent to its MCP endpoints.
Cursor has become one of the primary AI coding environments for development teams, and its agents increasingly reach into the outside world through MCP servers: databases, ticketing systems, cloud consoles, and internal APIs. Every connection extends what an agent can do. It also extends what could go wrong if that access goes unmonitored or unchecked. Zenity's plugin on the Cursor Marketplace addresses that gap, extending the agent-centric observability and governance Zenity already applies across the enterprise down to the Cursor desktop itself.
The Blind Spot on the Developer Endpoint
Cursor agents don't work in isolation. A single agent might be wired into a customer database, an internal deployment pipeline, and sensitive local files. Security teams may already inventory how their agents were configured at build time, but the specific MCP servers those agents reach on the endpoint have largely been invisible: configured locally, added ad hoc, or inherited autonomously.
That blind spot matters because MCP access is functionally equivalent to giving an agent a new set of hands. A rogue or misconfigured connection can let an agent read data, call APIs, or take actions well outside its intended scope, often without anyone realizing the connection exists. Before teams can govern that access, they need to answer a basic set of questions:
- Which MCP server is each Cursor agent actually connected to right now?
- What data, systems, or credentials can those servers reach on the agent's behalf?
- Does that access match what the developer, or the organization, intended when the agent was first configured?
- Would anyone notice if an agent escalated privilege and picked up a new, ungoverned connection tomorrow?
Without a reliable, continuously updated answer to those questions, MCP governance is a policy on paper rather than a control that holds up at runtime.
Zenity for Cursor: Visibility from the Agent to the Endpoint
The Zenity plugin installs directly in Cursor desktop, so developers don't have to change how they work to get covered. Using webhooks and OTEL-based events, the plugin compiles data into an inventory record that maps every Cursor agent to the MCP endpoints it uses.
This isn't a new category of monitoring, governance, or enforcement for Zenity. Cursor agents are already visible inside the Zenity platform today. What the Marketplace listing adds is democratization: all MCP servers, usage data, and connecting agents are instantly visible to all users, narrowing the gap between what a Cursor agent is configured to achieve, and how it accomplishes its goals.
Inside the Integration: Layers of MCP Scanning and Governance
Complete and continuous agent-to-MCP inventory
The plugin builds and maintains a live map between every Cursor agent on the endpoint and the MCP servers it's connected to, so security teams get a single, current record instead of a point-in-time survey.
- Agent-level mapping of every active MCP connection
- Real-time visibility into new or changed connections
- A consistent inventory that stays current as developer workflows evolve
Enabling governance where agents act
Visibility is the foundation, but Zenity also gives teams a path to enforcement. Webhooks support prevention rules and inline controls on MCP servers, so organizations can move from watching usage to setting hard boundaries around it by:
- Standardizing Cursor agent tool and API calls
- Enforcement of custom boundaries on MCP use and enhanced security posture without slowing down deployment
Why This Matters Now
For organizations running Cursor at scale, the Marketplace listing delivers democratized visibility into what every Cursor agent can touch, for every user, at no extra cost. Minimizing over-exposed connections in real time is critical to reducing the blast radius if an agent takes rogue action or acts out of scope. For development teams required to deliver at agent-speed, lethargic point-in-time reporting is not an option.
The Road Ahead: Governing Agents Wherever They Build
Developers will keep connecting Cursor agents to more MCP servers because that's what makes those agents useful. The organizations that get ahead of the risk won't be the ones that slow that down. They'll be the ones that can see it, govern it, and correct it in real time, without asking developers to work differently.
Zenity's listing on the Cursor Marketplace is a step in that direction: inventory and mapping of MCP servers for Cursor agents, delivered inside the tool developers already use, with a clear path to enforcement when access needs to be reined in.
Because in the era of agentic AI, the agent is the new endpoint, and endpoints only stay secure when someone can see, and act on, everything they touch.
All ArticlesRelated blog posts

Zenity Now Integrates with Microsoft Agent 365
AI agents have moved from pilots into broad enterprise use. They read email, query systems of record, take actions,...

Why AI Security Has to Live at the Decision Point
For the past couple of years, most of the industry’s attention has gone toward agents that respond to a single...

AgentForger Showed Why Securing AI Agents Takes More Than a Patch
Securing AI agents changed again when Zenity Labs disclosed AgentForger, a vulnerability in OpenAI's ChatGPT Workspace...
Secure Your Agents
We’d love to chat with you about how your team can secure and govern AI Agents everywhere.
Get a Demo