Cursor Agent Permissions Explained: What Runs Without Asking, and How to Tighten It A developer's guide details Cursor's default agent permissions, showing that the agent reads files, searches code and edits workspace files without approval, while terminal commands, configuration edits and MCP tool calls require approval unless allowlisted. It recommends tightening defaults with .cursorignore for secrets, named read-only MCP tool allowlists, enabling VS Code-style workspace trust (off by default), and hooks for rules pattern allowlists cannot express, noting Cursor calls these "best-effort guardrails rather than a hard security boundary. Cursor's agent can read your codebase, edit files, run terminal commands and call MCP tools. How much of that happens without asking you is controlled by a handful of settings that are easy to skim past. This guide explains Cursor agent permissions as they work by default, what each control actually governs, and the gaps worth closing for real projects. Everything below about Cursor's defaults comes from Cursor's Agent Security documentation https://cursor.com/docs/agent/security ; check it again after major releases, because defaults do change. | Action | Default behaviour | |---|---| | Reading files, searching code | Runs without approval | | Editing files in the workspace | Runs without approval written to disk immediately , except configuration files | | Editing configuration files e.g. workspace settings | Requires approval | | Terminal commands | Require approval, unless allowed by a Run Mode | | Connecting an MCP server | Requires approval | | Each MCP tool call | Requires approval, unless the tool is on an MCP allowlist | | Network requests from Cursor's own tools | Limited to GitHub, direct link retrieval and web search providers | Two consequences follow immediately: .cursorignore for files the agent should never see Because reading needs no approval, the main lever for sensitive files is .cursorignore , which blocks agent access to matching paths. A reasonable starting point: secrets and credentials .env .env. .env.example .pem .key secrets/ config/credentials .yml infrastructure state that often contains secrets .tfstate .tfstate.backup Two caveats. First, .cursorignore governs Cursor's own file access; a terminal command the agent runs cat .env is a separate route, governed by your command approvals. Second, ignoring a file is not the same as the secret not being on disk. The strongest version of this control is not having production secrets in the working tree at all. By default every terminal command asks. That is safe and quickly exhausting, which is how people end up approving everything. Run Modes let trusted commands run without prompting, ranging from a simple allowlist up to an Auto-review classifier. Cursor describes these as "best-effort guardrails rather than a hard security boundary" , and that framing is correct. Practical advice: npm test , npm run lint , git status , git diff . python , node , curl , bash . A prefix like python -c "