Anysphere · IDE assistant

Cursor

An AI-native editor with deep agentic capability, where behaviour is shaped by repository rules files that almost nobody reviews.

What you are actually governing

Cursor is a full editor built around agentic editing, which means the agent is not a panel beside the work — it is the primary way the work happens. Multi-file edits, terminal commands and codebase-wide reasoning are the default interaction, so the volume of agent-initiated action per engineer is high and the friction per action is deliberately low.

Behaviour is shaped by rules. Project rules live in the repository, user rules live with the individual, and Cursor also reads the cross-tool `AGENTS.md` convention. Rules are the highest-leverage governance artifact on this surface and the least-governed in practice: a rules file is prose, it arrives through an ordinary pull request, and a reviewer skims it. An instruction that quietly relaxes a safeguard reads exactly like an instruction that improves code style.

MCP support is first-class, and per-project server configuration means connectors are added at the pace of individual convenience. The same servers appear across the company's other AI surfaces, governed separately in each. Team and enterprise plans provide admin controls and a privacy mode governing code retention, and configuring those is the baseline — but they address data handling rather than artifact trust.

The structural point for a security team is that Cursor concentrates a lot of agent capability inside a tool engineers experience as their editor. Anything that feels like editor configuration — a rules file, an MCP entry, an extension — is in fact agent policy, and it is edited with the ceremony of a preferences pane.

Artifact classes this surface loads

Each of these changes what the agent does, and each arrives through a channel with no dependency review. This is the inventory a governance programme has to cover — not a feature list.

  • Project rules
  • User rules
  • AGENTS.md
  • MCP servers
  • Extensions

What Anysphere genuinely controls

Documented controls worth configuring fully before buying anything. Every one is cited to Anysphere's own documentation below.

  • Team and enterprise admin controls

    Central membership management and organisation-level configuration on paid team plans.

  • Privacy mode

    Governs whether code is retained by the vendor, enforceable as an organisation-wide setting.

  • SSO

    Identity through the organisation's provider rather than individual accounts.

  • Repository-scoped project rules

    Rules committed to the repository inherit branch protection and pull request review.

What is still open once those are configured

Not criticism of the product — the honest boundary of a per-machine configuration model. These are fleet questions, and local settings were never designed to answer them.

  • Rules files are unreviewed policy

    Prose instructions that steer every session, passing through a review process that is not looking for security implications.

  • User rules are invisible to the organisation

    Individual rules apply across a person's projects and are not visible or governable centrally.

  • Per-project MCP configuration

    Connectors are added per repository at individual convenience, with no central inventory of what is connected where.

  • No artifact vetting or pinning

    Nothing establishes that a rules file or MCP server was reviewed, or that the reviewed version is the one in use.

Frequently asked

Are Cursor rules files a security risk?
They are unreviewed policy. A rules file shapes every agent session in the repository, is authored in prose, and passes through a review process optimised for code. That combination is the risk, not any specific file.
Does privacy mode address our AI governance requirements?
It addresses code retention, which is one requirement. It says nothing about which artifacts steer the agent, which connectors it can reach, or what happened in a given session.

Sources

Compiled from Anysphere's own documentation on 2026-07-25. Products in this category change quickly — verify against the source before a decision depends on a specific mechanism.

Other surfaces

Concepts on this page

Govern Cursor the same way you govern everything else

Vincosha Registry distributes reviewed, version-pinned artifacts to Cursor and every other surface your company runs, from one source. Vincosha Assay scans them before they land, and Vincosha Ledger shows which versions were active in which session.