Coding agent

Cursor CLI

Cursor's familiar agent loop in the terminal and in automation.

Status
Active
License
Proprietary
Evidence
Documented + independently measured configuration, 16 sources
Product record checked
2026-08-01

At a glance

A proprietary terminal surface for Cursor Agent with interactive and print modes, subscription model selection, MCP, Agent Skills, project rules, structured output, and allow or deny policies for shell commands and file access.

Good choice if

  • Existing Cursor subscribers who want the same agent from a terminal
  • Scripted analysis and code changes using print mode and structured output
  • Teams that want repository-scoped allow and deny rules without a larger platform

Check before choosing

  • The closed binary has no public immutable release tag or source revision; capability verification depends on dated product documentation and the installed version
  • Model access normally routes through Cursor; the documented Bedrock path does not make the CLI a general local-model harness
  • Sandboxing and worktrees are separate opt-in controls: worktrees isolate files only, while Run Everything/--yolo can bypass interactive approvals
See 3 more considerations
  • Global MCP servers are auto-approved whereas project servers require trust; every extension expands the effective tool boundary
  • Rewind restores file and conversation state but cannot undo network or other external side effects
  • No public product evaluation suite or complete harness benchmark record is available

Capability support

Documented first-class product support, checked against the sources below.

External tools (MCP)
DocumentedProduct-supported MCP integrationSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Reusable skills
DocumentedProduct-supported reusable skill packagesSource · checked 2026-08-01Support does not establish portability, package quality, safety, or adoption.
Local models
Not documentedNo first-class support established by the current recordAbsence of current documentation is not proof that the capability is impossible.
Agent parallelism
DocumentedDelegated or parallel agent workflowSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Runs without an open UI
DocumentedNon-interactive or automation surfaceSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Browser control
Not documentedNo first-class support established by the current recordAbsence of current documentation is not proof that the capability is impossible.
Isolated execution
OptionalOptional sandbox policy for command executionSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Undo file changes
DocumentedProduct-supported file or session rollbackSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.

Getting started

Install `cursor-agent`, sign in to Cursor, and define project permissions before combining print mode with `--force` in automation.

Open official documentation

Classification and operating model

Category fit and technical mechanisms are evidence records, not product-quality scores.

Category fit
Qualifies, 4/4 criteria
Operating model
7/7 layers documented
Inspect category criteria and operating mechanismsFirst-party records

Why it qualifies as a coding harness

This confirms category fit, not product quality. Every required criterion links back to first-party evidence.

Qualifies4 of 4 required criteria evidenced
  • Adaptive agent loop

    Documented

    The system repeatedly observes results and chooses the next action instead of following a fixed one-pass graph.

  • Repository tool execution

    Documented

    The system can use tools to inspect and change a repository or its execution environment.

  • Task-aware context management

    Documented

    The runtime assembles, updates, compacts, retrieves, or persists task-relevant context while work proceeds.

  • Model-independent runtime control

    Documented

    Permissions, budgets, interruption, policy, or stop controls operate outside the model's own text generation.

Membership establishes category fit only. It does not score quality, safety, autonomy, model capability, or benchmark performance. · Read the membership rule.

How it works under the hood

Seven mechanisms mapped from first-party records. These labels describe what the harness provides, not how intelligent its model is.

7/7layers documented
  • Execution & isolationSandbox availableDocumented mechanism, not a performance score.
  • Tooling & integrationsExtensible toolsDocumented mechanism, not a performance score.
  • Context & stateManaged contextDocumented mechanism, not a performance score.
  • Lifecycle & recoveryCheckpoint/rewindDocumented mechanism, not a performance score.
  • ObservabilityLogs/transcriptsDocumented mechanism, not a performance score.
  • VerificationTool-assistedDocumented mechanism, not a performance score.
  • Governance & permissionsPolicy controlsDocumented mechanism, not a performance score.

Measured and public context

Configuration-specific measurements and source-native activity stay separate from general product capability.

Inspect code audit, measured configurations, and ecosystem signalsContext, not a product score

Public code audit

Unrankedsupport-only repository
Security policy
Present at inspected commit
CI workflow
Not found
Automated tests
Not found
Evaluation assets
Not found
Contributor documentation
Not found

The pinned public tree contains only five paths: a README, SECURITY.md, and an issue-template directory. It exposes no Cursor CLI implementation, release tag, engineering test, CI workflow, contributor guide, or product evaluation suite, so it cannot establish code-verifiable harness capability.

Inspect commit 654b1b4775ca67aef473bd31a14c8c04a1abde2d, checked 2026-07-27
Context, not quality

Public ecosystem signals

Source-native observations for exact mapped artifacts and reviewed stable release trains. Different units and populations stay separate, and missing coverage is never treated as zero.

View this harness in Usage
  • OpenRouter 30d tokens972.94B#12 coding app; 2026-08-09 to 2026-09-07Open app page
  • Homebrew 30d events1.51KCask: cursor-cliOpen artifact
  • GitHub stars33.22KSupport repository; 2.29K forksOpen artifact

Routing, package retrievals, release downloads, editor installs, and repository interest observe different populations. They are never added together and never affect capability evidence, classification, or measured results.

Interpretation rulesSignals checked

First-party evidence

Each capability claim links to the first-party record that supports it.

16 first-party sourcesProduct record checked

Product and interfaces

4 sources
View 3 more sources

Execution and control

3 sources
View 2 more sources

Agents, state and recovery

1 source

Automation and extensions

5 sources
View 4 more sources

Enterprise and operations

1 source

Releases and public code audit

2 sources
View 1 more source