Cursor
What Cursor’s own help pages, docs and terms said on 1 October 2026, by the same six questions we ask of every agent. We didn’t test it for this page. “Not documented” means we didn’t find it on the vendor’s pages; it doesn’t mean the feature is missing.
Coding agent
- Can you limit it?
- Run modes, allowlist
- Does it ask first?
- Three run modes, from Auto-review to Run Everything
- Can you stop it?
- Not documented
- Is there a record someone outside can check?
- Not documented
- What about sub-agents?
- Inherit all tools
- Can you test it yourself?
- Headless, MCP
What the vendor’s pages say
Cursor has three run modes: Auto-review, Allowlist and Run Everything (run modes), and says "Auto-review is not a security boundary". Cursor also says "the allowlist is best-effort, not a security boundary" (safety and controls). Cloud agents auto-run all terminal commands, and the same page names the risk that attackers could use prompt injection to trick the agent into uploading code (secrets and network). "Subagents inherit all tools from the parent" (subagents). Enterprise audit logs cover sign-ins, roles, keys and settings, and exclude prompts, agent output and code (compliance).
Every statement above was checked on the vendor’s own page on 1 October 2026; each links to its source.
Run this test on yours
Delegus Check gives your agent a permission and a one-hour test server, then shows every action it tries and what was refused. It works today with agents that accept a custom MCP server, including Claude on any plan.
Corrections
Vendors and readers: if anything here is out of date, write to hello@delegus.ai and we’ll fix it. Each change is listed here with its date.
- 1 October 2026: first published. All vendor statements checked that day.