Anysphere · IDE assistant
Cursor
An AI-native editor with deep agentic capability, where behaviour is shaped by repository rules files that almost nobody reviews.
What you are actually governing
Cursor is a full editor built around agentic editing, which means the agent is not a panel beside the work — it is the primary way the work happens. Multi-file edits, terminal commands and codebase-wide reasoning are the default interaction, so the volume of agent-initiated action per engineer is high and the friction per action is deliberately low.
Behaviour is shaped by rules. Project rules live in the repository, user rules live with the individual, and Cursor also reads the cross-tool `AGENTS.md` convention. Rules are the highest-leverage governance artifact on this surface and the least-governed in practice: a rules file is prose, it arrives through an ordinary pull request, and a reviewer skims it. An instruction that quietly relaxes a safeguard reads exactly like an instruction that improves code style.
MCP support is first-class, and per-project server configuration means connectors are added at the pace of individual convenience. The same servers appear across the company's other AI surfaces, governed separately in each. Team and enterprise plans provide admin controls and a privacy mode governing code retention, and configuring those is the baseline — but they address data handling rather than artifact trust.
The structural point for a security team is that Cursor concentrates a lot of agent capability inside a tool engineers experience as their editor. Anything that feels like editor configuration — a rules file, an MCP entry, an extension — is in fact agent policy, and it is edited with the ceremony of a preferences pane.
Artifact classes this surface loads
Each of these changes what the agent does, and each arrives through a channel with no dependency review. This is the inventory a governance programme has to cover — not a feature list.
- Project rules
- User rules
- AGENTS.md
- MCP servers
- Extensions
What Anysphere genuinely controls
Documented controls worth configuring fully before buying anything. Every one is cited to Anysphere's own documentation below.
- Team and enterprise admin controls
Central membership management and organisation-level configuration on paid team plans.
- Privacy mode
Governs whether code is retained by the vendor, enforceable as an organisation-wide setting.
- SSO
Identity through the organisation's provider rather than individual accounts.
- Repository-scoped project rules
Rules committed to the repository inherit branch protection and pull request review.
What is still open once those are configured
Not criticism of the product — the honest boundary of a per-machine configuration model. These are fleet questions, and local settings were never designed to answer them.
- Rules files are unreviewed policy
Prose instructions that steer every session, passing through a review process that is not looking for security implications.
- User rules are invisible to the organisation
Individual rules apply across a person's projects and are not visible or governable centrally.
- Per-project MCP configuration
Connectors are added per repository at individual convenience, with no central inventory of what is connected where.
- No artifact vetting or pinning
Nothing establishes that a rules file or MCP server was reviewed, or that the reviewed version is the one in use.
Frequently asked
- Are Cursor rules files a security risk?
- They are unreviewed policy. A rules file shapes every agent session in the repository, is authored in prose, and passes through a review process optimised for code. That combination is the risk, not any specific file.
- Does privacy mode address our AI governance requirements?
- It addresses code retention, which is one requirement. It says nothing about which artifacts steer the agent, which connectors it can reach, or what happened in a given session.
Sources
Compiled from Anysphere's own documentation on 2026-07-25. Products in this category change quickly — verify against the source before a decision depends on a specific mechanism.