Risk assessment for AI coding prompts - Automatically analyze your coding requests for security and safety risks before execution.
Click this link to automatically install in Cursor:
cursor://anysphere.cursor-deeplink/mcp/install?name=orcho&config=eyJuYW1lIjoib3JjaG8iLCJ0eXBlIjoic3RkaW8iLCJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsIkBvcmNob19yaXNrL21jcC1zZXJ2ZXIiXSwiZW52Ijp7Ik9SQ0hPX0FQSV9LRVkiOiJ0ZXN0X2tleV9vcmNob18xMjM0NSJ9fQ==
How to use:
- Copy the link above
- Paste it into your browser's address bar and press Enter
- Cursor will open and automatically configure the MCP server
- Replace the test API key with your real key (see API Configuration)
- Restart Cursor to activate
- Replace the test API key with your real key (see API Configuration)
- Restart Cursor to activate the MCP server
Orcho analyzes your coding prompts in real-time to identify potential security risks, dangerous operations, and safety concerns before code is generated or executed.
- 🔍 Real-time Risk Assessment - Analyze prompts using Orcho's risk analysis API
- 📁 Context-Aware - Automatically includes file context for accurate blast radius and complexity analysis
- 🛡️ Security First - Identifies high-risk prompts before execution
- 🔌 Seamless Integration - Works natively with Cursor's Model Context Protocol
Copy and paste this link into your browser:
cursor://anysphere.cursor-deeplink/mcp/install?name=orcho&config=eyJuYW1lIjoib3JjaG8iLCJ0eXBlIjoic3RkaW8iLCJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsIkBvcmNob19yaXNrL21jcC1zZXJ2ZXIiXSwiZW52Ijp7Ik9SQ0hPX0FQSV9LRVkiOiJ0ZXN0X2tleV9vcmNob18xMjM0NSJ9fQ==
This automatically:
- ✅ Configures the MCP server in Cursor
- ✅ Sets up auto-installation via npx
⚠️ Next step: Replace the test API key with your real key (see below)⚠️ Then: Restart Cursor
-
Install the package:
npm install -g @orcho_risk/mcp-server
-
Configure Cursor:
Create or edit
~/.cursor/mcp.json(Windows:C:\Users\<YourUsername>\.cursor\mcp.json):{ "mcpServers": { "orcho": { "command": "npx", "args": ["-y", "@orcho_risk/mcp-server"], "env": { "ORCHO_API_KEY": "your-api-key-here" } } } } -
Restart Cursor completely (quit and reopen)
- Sign up at app.orcho.ai
- Navigate to API Settings (Dashboard → API Keys)
- Create or copy your API key
- Update your
mcp.jsonfile:- Location:
~/.cursor/mcp.json(orC:\Users\<YourUsername>\.cursor\mcp.jsonon Windows) - Replace
test_key_orcho_12345with your actual API key
- Location:
For initial testing, you can use:
test_key_orcho_12345
Note: The test key has limited functionality and rate limits. Get your own API key from app.orcho.ai for production use.
- ✅ Store API keys only in
~/.cursor/mcp.json(not in your project) - ✅ Never commit API keys to version control
- ✅ Rotate keys immediately if accidentally exposed
In Cursor chat, type:
@orcho assess_risk: Your prompt here
Enable automatic risk assessment for all prompts by adding a Cursor rule to your project.
Copy the rule file to your project:
# Create .cursor/rules directory
mkdir -p .cursor/rules
# Copy the rule file
cp node_modules/@orcho_risk/mcp-server/.cursor/rules/orcho-risk-assessment.mdc .cursor/rules/Or manually copy from:
node_modules/@orcho_risk/mcp-server/.cursor/rules/orcho-risk-assessment.mdc
Copy the example rules file:
cp node_modules/@orcho_risk/mcp-server/.cursorrules.example .cursorrulesNote: Project Rules (Option 1) are the modern approach and support more features.
Orcho automatically gathers context when available:
- Current File: Detects the file open in your editor
- Other Files: Analyzes which files will be modified by the prompt
- Dependency Graph: Optional project dependency information
- Blast Radius: Calculates impact scope of changes
User: "Delete all user data from the database"
→ Cursor calls: @orcho assess_risk with context
→ Risk: HIGH (score: 95)
→ Cursor warns: "⚠️ HIGH RISK: This could cause data loss. Proceed?"
task(required): The prompt to assesscurrent_file(recommended): Path to currently open fileother_files(recommended): Array of files that will be modifieddependency_graph(optional): Project dependency graphweights(optional): Custom risk calculation weightsaiignore_file(optional): Path to .aiignore file
-
Check
mcp.jsonlocation:- Mac/Linux:
~/.cursor/mcp.json - Windows:
C:\Users\<YourUsername>\.cursor\mcp.json
- Mac/Linux:
-
Verify Node.js is installed:
node --version # Requires v18+ -
Check Cursor Developer Tools:
- Help → Toggle Developer Tools
- Look for MCP-related errors in Console
- Invalid API Key: Verify the key is correct in
mcp.json - Rate Limits: Check your account quota at app.orcho.ai
- No API Key: The server will use the test key by default (limited functionality)
- Check that Cursor is fully restarted (quit and reopen)
- Verify your API key is valid at app.orcho.ai
- Ensure you have internet connectivity
MIT
For issues and questions:
- GitHub Issues: [Your Repo URL]
- Orcho Support: [Support URL]