{
  "data": {
    "a": {
      "slug": "cursor-cli",
      "name": "Cursor CLI",
      "vendor": "Cursor",
      "vendorUrl": "https://cursor.com/cli",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Cursor's coding agent in the terminal, run as `agent` (also `cursor-agent`).",
      "url": "https://www.anchorterminal.com/tools/cursor-cli",
      "markdownUrl": "https://www.anchorterminal.com/tools/cursor-cli.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/cursor-cli.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/cursor-cli.json",
      "license": "Proprietary, under Cursor's terms of service (Anysphere, Inc., updated 3 September 2026). No source is published",
      "transports": [],
      "packages": [],
      "auth": "mixed",
      "authNotes": "`agent login` through a browser, or an API key passed with `--api-key` or `CURSOR_API_KEY` for headless runs.",
      "pricing": "freemium",
      "pricingNotes": "Hobby is free with limited Agent requests and needs no card. Individual is $20 a month, Teams $40 a user a month and Enterprise by quote. Every plan includes a set amount of model usage, with on-demand usage billed in arrears, and the pricing page gives no dollar or request figure for either (checked 2026-10-02).",
      "priceSummary": "$20 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the pricing page (checked 2026-10-02).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-02"
      },
      "docsUrl": "https://cursor.com/docs/cli/overview",
      "llmsTxt": "https://cursor.com/llms.txt",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client"
      ],
      "tags": [
        "official",
        "harness",
        "coding-agent",
        "cli",
        "closed-source",
        "mcp",
        "llms-txt",
        "free-tier",
        "no-card",
        "status-page"
      ],
      "lastRelease": "2026-09-28",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 35.3,
        "grade": "F",
        "agentReady": false,
        "rank": 617,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 17,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 42,
          "maintenance": 62,
          "payments": 25,
          "reliability": 27,
          "schema": 39,
          "security": 46,
          "transparency": 59
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "low",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "2025-10-02 and 2025-11-03. Four high advisories that name the CLI, all fixed. Remote code execution in Cursor CLI through Cursor Agent MCP OAuth2 communication (GHSA-wj33-264c-j9cq), arbitrary code execution through a permissive CLI config (GHSA-v64q-396f-7m79), a sensitive-file overwrite bypass in the CLI agent (GHSA-x2vq-h6v6-jhc6) and command injection through an untrusted MCP configuration in Cursor CLI Beta (GHSA-4hwr-97q3-37w2). All older than six months, so 1 point each (https://github.com/cursor/cursor/security/advisories)",
          "2026-01-14. GHSA-82wg-qcm4-fp2w, high, terminal tool allowlist bypass through environment variables. It doesn't name the CLI, which runs the same terminal tool and allowlist idea. Fixed and published, 1 point. Judgement call. We left out the 2026 sandbox escapes titled for Cursor Desktop and Cloud Agents (https://github.com/cursor/cursor/security/advisories)"
        ],
        "verdict": "Allow and deny rules for shell, reads, writes, web fetches and MCP tools, with deny taking precedence. No CLI changelog, and versions are dates.",
        "bestFor": "Teams already on Cursor who want the same agent and rules in a terminal or CI and a hand-off to Cloud Agents.",
        "strengths": [
          "Allow and deny rules for shell, reads, writes, web fetches and MCP tools, with deny taking precedence",
          "Print mode with text, json and stream-json output, plus `--resume` and `--continue`",
          "Plan and ask (read-only) modes alongside the default agent mode",
          "Hands a task to Cloud Agents by prefixing the message with `\u0026`",
          "A free Hobby plan with no card, and a status page with a CLI component"
        ],
        "weaknesses": [
          "No CLI changelog, and versions are dates",
          "The install script checks no checksum or signature",
          "No documentation of CLI telemetry or of what runs without approval by default",
          "Four high advisories named the CLI in October and November 2025",
          "Closed source, with no public issue tracker"
        ],
        "agentNotes": [
          "Pass `--trust` in headless runs, or the workspace prompt stops a run with no terminal",
          "Write deny rules in .cursor/cli.json before using `--force`. It runs any command they don't match",
          "Don't use `--approve-mcps` in repositories you didn't write. Two 2025 CLI advisories came through MCP",
          "Set `CURSOR_API_KEY` in CI. `agent login` opens a browser",
          "Record `agent --version` with each run. Versions are dates and there's no CLI changelog to compare against"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 1.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "low",
            "grade": "F",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 35.3
          }
        ],
        "editorialScores": {
          "ergonomics": 42,
          "maintenance": 62,
          "payments": 25,
          "reliability": 27,
          "schema": 39,
          "security": 46,
          "transparency": 27
        },
        "provenanceScore": 91
      },
      "connect": {
        "install": "curl https://cursor.com/install -fsS | bash",
        "headless": {
          "run": "agent -p \"fix the failing test\" --output-format json --trust"
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/cursor-cli"
      },
      "area": "frameworks",
      "unitPrices": [
        {
          "item": "Individual plan",
          "unit": "month",
          "usd": 20,
          "note": "includes a set amount of model usage"
        },
        {
          "item": "Teams",
          "unit": "seat-month",
          "usd": 40,
          "note": "per user"
        }
      ],
      "provenance": {
        "legalEntity": "Anysphere, Inc.",
        "domain": "cursor.com",
        "domainRegistered": "1995-12-20",
        "endpointOnVendorDomain": null,
        "terms": "https://cursor.com/terms-of-service",
        "privacy": "https://cursor.com/privacy",
        "statusPage": "https://status.cursor.com",
        "changelog": "https://cursor.com/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-01",
        "notes": [
          "The terms of service (updated 3 September 2026) name Anysphere, Inc.",
          "RDAP (Verisign) gives cursor.com a registration date of 1995-12-20, long before Anysphere.",
          "cursor.com/.well-known/security.txt has a Contact line pointing to Cursor's GitHub security advisories and no Expires line, which RFC 9116 requires. The site's tracker reads a file with a Contact and no Expires as valid.",
          "The changelog covers all of Cursor, and we found no CLI-only changelog."
        ],
        "score": 91
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/cursor-cli.json",
      "live": {
        "slug": "cursor-cli",
        "vendorStatus": {
          "page": "https://status.cursor.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:06:34.068208988Z"
        },
        "securityTxt": {
          "url": "https://cursor.com/.well-known/security.txt",
          "state": "valid",
          "checkedAt": "2026-10-08T15:38:46.365788319Z"
        },
        "llmsTxt": {
          "url": "https://cursor.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:17.721936541Z"
        },
        "domain": {
          "domain": "cursor.com",
          "registered": "1995-12-20",
          "source": "https://rdap.verisign.com/com/v1/domain/cursor.com",
          "checkedAt": "2026-10-04T13:09:09.510989819Z"
        },
        "pages": [
          {
            "url": "https://cursor.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:16:46.108342977Z",
            "changedAt": "2026-10-07T18:03:43.356086965Z",
            "fingerprint": "ff1c429484e4"
          },
          {
            "url": "https://cursor.com/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:16:48.161554363Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a5f74b5510f1"
          },
          {
            "url": "https://cursor.com/terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:16:50.171295182Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5db93dae47db"
          }
        ],
        "updatedAt": "2026-10-08T19:06:34.068208988Z"
      }
    },
    "answer": "Pi scores 68.4 (B) on agent readiness against Cursor CLI's 35.3 (F), and leads in every scored category.",
    "b": {
      "slug": "earendil-pi",
      "name": "Pi",
      "vendor": "Earendil",
      "vendorUrl": "https://pi.dev",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Pi is an open-source terminal coding agent from Earendil, run on the owner's machine with any of 15 or more model providers. It has interactive, print, JSON and RPC modes, a TypeScript SDK and a built-in MCP client.",
      "url": "https://www.anchorterminal.com/tools/earendil-pi",
      "markdownUrl": "https://www.anchorterminal.com/tools/earendil-pi.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/earendil-pi.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/earendil-pi.json",
      "repo": "https://github.com/earendil-works/pi",
      "license": "MIT",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@earendil-works/pi-coding-agent"
        }
      ],
      "auth": "none",
      "authNotes": "No Pi account needed. Model providers are connected with `/login` (a subscription or an API key, stored in `~/.pi/agent/auth.json`) or with environment variables such as `ANTHROPIC_API_KEY`. MCP servers take headers, bearer tokens from the environment or OAuth, with tokens kept in `~/.pi/agent/mcp-auth.json`. Radius, the optional hosted gateway, needs its own sign-in or `RADIUS_API_KEY`.",
      "pricing": "free",
      "pricingNotes": "Free and MIT, with no paid edition of the harness. The owner pays the model provider. Radius, Earendil's optional hosted gateway, is an early alpha sold by prepaid credits, and no public price list was found (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the repository or the docs (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 113417,
        "npmWeekly": 5201697,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://pi.dev/docs/latest",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client"
      ],
      "tags": [
        "open-source",
        "local",
        "free",
        "no-card",
        "typescript",
        "mcp",
        "json-output",
        "rpc",
        "no-sandbox"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 68.4,
        "grade": "B",
        "agentReady": false,
        "rank": 170,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 76,
          "maintenance": 87,
          "payments": 60,
          "reliability": 75,
          "schema": 84,
          "security": 61,
          "transparency": 64
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-06-08. GHSA-jfgx-wxx8-mp94 (CVE-2026-54328, high). Temporary extension installs used predictable paths under the system temp directory, so another local user on a shared Linux host could plant extension code that Pi then loaded. Fixed in 0.78.1. Fixed, published and four months old, -2. https://github.com/earendil-works/pi/security/advisories/GHSA-jfgx-wxx8-mp94",
          "2026-06-08. GHSA-mqxh-6gq7-558m (CVE-2026-54325, medium). Before 0.79.0 Pi loaded a repository's `.pi` settings and extensions without asking, so starting it in a cloned repository could run that repository's code. Fixed in 0.79.0 with project trust. Fixed and published, -2. https://github.com/earendil-works/pi/security/advisories/GHSA-mqxh-6gq7-558m",
          "2026-06-08. GHSA-7v5m-pr3q-6453 (CVE-2026-54326, low, XSS in HTML session exports) and GHSA-r95r-rj6r-c39x (CVE-2026-54327, low, a race in `auth.json` permissions). Both fixed in 0.78.1. Recorded without a deduction. https://github.com/earendil-works/pi/security/advisories"
        ],
        "verdict": "Four default tools, a JSONL event stream, an RPC mode and MCP tools kept out of the model's declarations by default keep context small and scripting simple. Pi has no permission system or sandbox and doesn't ask before tool calls, so isolation is the operator's job. Version 1.0.0 is dated 1 October 2026.",
        "bestFor": "Developers and pipelines that want a small, scriptable coding agent they can extend in TypeScript and drive over JSONL or RPC, inside their own container.",
        "strengths": [
          "Four default tools (read, bash, edit, write), with MCP tools reachable through codemode scripts and not declared to the model by default",
          "`--mode json` streams JSONL events and `--mode rpc` takes JSONL commands, both documented record by record, with a Python client example",
          "Built-in MCP client for stdio and streamable HTTP servers with OAuth, per-tool exposure settings and a conformance job in CI",
          "Project trust stops a repository's `.pi` settings, extensions and MCP servers loading until approved, and non-interactive modes skip them by default",
          "npm releases carry SLSA provenance from GitHub Actions trusted publishing, and the installer pins transitive dependencies"
        ],
        "weaknesses": [
          "No permission system or sandbox. Tool calls run with the user's rights and without an approval prompt",
          "An anonymous install and update ping to pi.dev and a latest-version request are on by default",
          "Four advisories published on 8 June 2026, one rated high and one medium, all fixed by 0.79.0",
          "No privacy policy for pi.dev or the CLI found, and pi.dev has no security.txt",
          "Eight of the last 15 CI runs on main failed on 7 and 8 October 2026, and a breaking provider rename shipped in patch release 1.0.3"
        ],
        "agentNotes": [
          "Run Pi inside a container or VM for unattended work. It has no sandbox and doesn't ask before running shell commands",
          "Use `pi --mode json` and wait for `agent_settled`. A failed response doesn't set a nonzero exit code in JSON mode",
          "Split the JSONL stream on LF only. Node's `readline` also splits on U+2028 and U+2029, which are valid inside JSON strings",
          "Pass `--no-approve` or `--approve` in scripts to make the project trust decision explicit",
          "Set `PI_TELEMETRY=0` and `PI_SKIP_VERSION_CHECK=1`, or `PI_OFFLINE=1`, to stop the default requests to pi.dev"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 68.4
          }
        ],
        "editorialScores": {
          "ergonomics": 76,
          "maintenance": 87,
          "payments": 60,
          "reliability": 75,
          "schema": 84,
          "security": 61,
          "transparency": 64
        },
        "provenanceScore": 63
      },
      "connect": {
        "install": "curl -fsSL https://pi.dev/install.sh | sh   # or: npm install -g --ignore-scripts @earendil-works/pi-coding-agent",
        "headless": {
          "command": "pi --mode json --no-session --no-approve \"$TASK\"",
          "env": {
            "PI_SKIP_VERSION_CHECK": "1",
            "PI_TELEMETRY": "0"
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/earendil-pi"
      },
      "area": "frameworks",
      "provenance": {
        "legalEntity": "Earendil Inc.",
        "domain": "pi.dev",
        "domainRegistered": "2024-01-30",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://pi.dev/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The pi.dev and earendil.com footers read Earendil Inc. The Radius alpha terms of 1 September 2026 name Earendil Works Co., and the README calls the company Earendil Works.",
          "We found no terms or privacy page for pi.dev or the CLI. pi.dev/terms, pi.dev/privacy and earendil.com/privacy return 404. Terms exist only for Radius, at radius.earendil.com/terms.",
          "pi.dev/.well-known/security.txt and earendil.com/.well-known/security.txt return 404. SECURITY.md gives security@earendil.com and GitHub private reporting.",
          "RDAP for pi.dev gives a registration date of 2024-01-30 with Cloudflare as registrar. The README says the domain was donated by exe.dev.",
          "The repository moved from badlogic/pi-mono to earendil-works/pi, and the npm package from @mariozechner/pi-coding-agent to @earendil-works/pi-coding-agent at 0.74.0, per the advisories."
        ],
        "score": 63
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/earendil-pi.json",
      "live": {
        "slug": "earendil-pi",
        "versions": [
          {
            "registry": "github",
            "name": "earendil-works/pi",
            "version": "v1.1.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:09:44.573412777Z"
          },
          {
            "registry": "npm",
            "name": "@earendil-works/pi-coding-agent",
            "version": "1.1.0",
            "seenAt": "2026-10-08T16:09:41.369786574Z"
          }
        ],
        "githubStars": 113482,
        "npmWeekly": 5201697,
        "securityTxt": {
          "url": "https://pi.dev/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:42.51766104Z"
        },
        "pages": [
          {
            "url": "https://pi.dev/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:53.741589246Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "82f9cb8bddf7"
          }
        ],
        "updatedAt": "2026-10-08T18:22:53.741589246Z"
      }
    },
    "facts": [
      {
        "a": "Agent harness",
        "b": "Agent harness",
        "name": "Kind"
      },
      {
        "a": "Cursor",
        "b": "Earendil",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "",
        "b": "",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "None",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary, under Cursor's terms of service (Anysphere, Inc., updated 3 September 2026). No source is published",
        "b": "MIT",
        "name": "Licence"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-28",
        "b": "2026-10-07",
        "name": "Last release"
      },
      {
        "a": "2026-09-03",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "2026-09-29",
        "b": "no document linked",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "none",
        "b": "113k stars, 5.2M npm/wk",
        "name": "Popularity"
      },
      {
        "a": "1.5/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Pi scores 68.4 (B) on agent readiness against Cursor CLI's 35.3 (F), and leads in every scored category.",
        "question": "Which is better for AI agents, Cursor CLI or Pi?"
      },
      {
        "answer": "No open-source release is listed for Cursor CLI. Pi is open source (MIT).",
        "question": "Are Cursor CLI and Pi open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": null,
        "also": null,
        "goodFor": "Teams already on Cursor who want the same agent and rules in a terminal or CI and a hand-off to Cloud Agents.",
        "slug": "cursor-cli",
        "watchFor": "No CLI changelog, and versions are dates"
      },
      {
        "aheadOn": [
          "Reliability, 75 against 27",
          "Schema \u0026 documentation, 84 against 39",
          "Agent ergonomics, 76 against 42",
          "Security \u0026 auth, 61 against 46",
          "Payments \u0026 pricing, 60 against 25",
          "Maintenance \u0026 community, 87 against 62",
          "Transparency \u0026 trust, 64 against 59"
        ],
        "also": [
          "No key needed to call it",
          "Open source"
        ],
        "goodFor": "Developers and pipelines that want a small, scriptable coding agent they can extend in TypeScript and drive over JSONL or RPC, inside their own container.",
        "slug": "earendil-pi",
        "watchFor": "No permission system or sandbox. Tool calls run with the user's rights and without an approval prompt"
      }
    ],
    "job": {
      "capability": "agent.harness",
      "name": "Agent harness"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aider-vs-cursor-cli.json",
        "title": "Aider vs Cursor CLI",
        "url": "https://www.anchorterminal.com/compare/aider-vs-cursor-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aider-vs-earendil-pi.json",
        "title": "Aider vs Pi",
        "url": "https://www.anchorterminal.com/compare/aider-vs-earendil-pi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amp-vs-cursor-cli.json",
        "title": "Amp vs Cursor CLI",
        "url": "https://www.anchorterminal.com/compare/amp-vs-cursor-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amp-vs-earendil-pi.json",
        "title": "Amp vs Pi",
        "url": "https://www.anchorterminal.com/compare/amp-vs-earendil-pi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/claude-code-vs-cursor-cli.json",
        "title": "Claude Code vs Cursor CLI",
        "url": "https://www.anchorterminal.com/compare/claude-code-vs-cursor-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/claude-code-vs-earendil-pi.json",
        "title": "Claude Code vs Pi",
        "url": "https://www.anchorterminal.com/compare/claude-code-vs-earendil-pi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cline-vs-cursor-cli.json",
        "title": "Cline vs Cursor CLI",
        "url": "https://www.anchorterminal.com/compare/cline-vs-cursor-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cline-vs-earendil-pi.json",
        "title": "Cline vs Pi",
        "url": "https://www.anchorterminal.com/compare/cline-vs-earendil-pi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cursor-cli-vs-devin.json",
        "title": "Cursor CLI vs Devin",
        "url": "https://www.anchorterminal.com/compare/cursor-cli-vs-devin"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cursor-cli-vs-gemini-cli.json",
        "title": "Cursor CLI vs Gemini CLI",
        "url": "https://www.anchorterminal.com/compare/cursor-cli-vs-gemini-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cursor-cli-vs-github-copilot-cli.json",
        "title": "Cursor CLI vs GitHub Copilot CLI",
        "url": "https://www.anchorterminal.com/compare/cursor-cli-vs-github-copilot-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cursor-cli-vs-goose.json",
        "title": "Cursor CLI vs goose",
        "url": "https://www.anchorterminal.com/compare/cursor-cli-vs-goose"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cursor-cli-vs-kiro-cli.json",
        "title": "Cursor CLI vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/cursor-cli-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cursor-cli-vs-openai-codex.json",
        "title": "Cursor CLI vs OpenAI Codex",
        "url": "https://www.anchorterminal.com/compare/cursor-cli-vs-openai-codex"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cursor-cli-vs-opencode.json",
        "title": "Cursor CLI vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/cursor-cli-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cursor-cli-vs-openhands.json",
        "title": "Cursor CLI vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/cursor-cli-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cursor-cli-vs-prime-agent.json",
        "title": "Cursor CLI vs Prime Agent",
        "url": "https://www.anchorterminal.com/compare/cursor-cli-vs-prime-agent"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cursor-cli-vs-qwen-code.json",
        "title": "Cursor CLI vs Qwen Code",
        "url": "https://www.anchorterminal.com/compare/cursor-cli-vs-qwen-code"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-earendil-pi.json",
        "title": "Devin vs Pi",
        "url": "https://www.anchorterminal.com/compare/devin-vs-earendil-pi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-gemini-cli.json",
        "title": "Pi vs Gemini CLI",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-gemini-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-github-copilot-cli.json",
        "title": "Pi vs GitHub Copilot CLI",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-github-copilot-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-goose.json",
        "title": "Pi vs goose",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-goose"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-kiro-cli.json",
        "title": "Pi vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-openai-codex.json",
        "title": "Pi vs OpenAI Codex",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-openai-codex"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-opencode.json",
        "title": "Pi vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-openhands.json",
        "title": "Pi vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-prime-agent.json",
        "title": "Pi vs Prime Agent",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-prime-agent"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-qwen-code.json",
        "title": "Pi vs Qwen Code",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-qwen-code"
      }
    ],
    "scores": [
      {
        "by": 48,
        "cursor-cli": 27,
        "earendil-pi": 75,
        "edge": "earendil-pi",
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 45,
        "cursor-cli": 39,
        "earendil-pi": 84,
        "edge": "earendil-pi",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 34,
        "cursor-cli": 42,
        "earendil-pi": 76,
        "edge": "earendil-pi",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 15,
        "cursor-cli": 46,
        "earendil-pi": 61,
        "edge": "earendil-pi",
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 35,
        "cursor-cli": 25,
        "earendil-pi": 60,
        "edge": "earendil-pi",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 25,
        "cursor-cli": 62,
        "earendil-pi": 87,
        "edge": "earendil-pi",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 5,
        "cursor-cli": 59,
        "earendil-pi": 64,
        "edge": "earendil-pi",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Pi scores 68.4 (B) on agent readiness against Cursor CLI's 35.3 (F), and leads in every scored category. Both do agent harness.",
    "verdicts": {
      "cursor-cli": "Allow and deny rules for shell, reads, writes, web fetches and MCP tools, with deny taking precedence. No CLI changelog, and versions are dates.",
      "earendil-pi": "Four default tools, a JSONL event stream, an RPC mode and MCP tools kept out of the model's declarations by default keep context small and scripting simple. Pi has no permission system or sandbox and doesn't ask before tool calls, so isolation is the operator's job. Version 1.0.0 is dated 1 October 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/cursor-cli-vs-earendil-pi",
    "json": "https://www.anchorterminal.com/compare/cursor-cli-vs-earendil-pi.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/cursor-cli-vs-earendil-pi.md",
    "slim": "https://www.anchorterminal.com/compare/cursor-cli-vs-earendil-pi.min.md"
  },
  "markdown": "Pi scores 68.4 (B) on agent readiness against Cursor CLI's 35.3 (F), and leads in every scored category. Both do agent harness.\n\n- Cursor CLI: grade F, 35.3/100, rank #617 of 629. Markdown https://www.anchorterminal.com/tools/cursor-cli.md · JSON https://www.anchorterminal.com/api/v1/tools/cursor-cli.json\n- Pi: grade B, 68.4/100, rank #170 of 629. Markdown https://www.anchorterminal.com/tools/earendil-pi.md · JSON https://www.anchorterminal.com/api/v1/tools/earendil-pi.json\n\n## Which one, for what\n\n### Cursor CLI (F)\n\nGood for: Teams already on Cursor who want the same agent and rules in a terminal or CI and a hand-off to Cloud Agents.\n\nWatch for: No CLI changelog, and versions are dates\n\n### Pi (B)\n\nGood for: Developers and pipelines that want a small, scriptable coding agent they can extend in TypeScript and drive over JSONL or RPC, inside their own container.\n\nAhead on:\n- Reliability, 75 against 27\n- Schema \u0026 documentation, 84 against 39\n- Agent ergonomics, 76 against 42\n- Security \u0026 auth, 61 against 46\n- Payments \u0026 pricing, 60 against 25\n- Maintenance \u0026 community, 87 against 62\n- Transparency \u0026 trust, 64 against 59\n\nAlso in its favour:\n- No key needed to call it\n- Open source\n\nWatch for: No permission system or sandbox. Tool calls run with the user's rights and without an approval prompt\n\n\n## Score by category\n\n| Category | Weight | Cursor CLI | Pi | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 27 | 75 | Pi +48 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 39 | 84 | Pi +45 |\n| Agent ergonomics | 13% (16.2 this run) | 42 | 76 | Pi +34 |\n| Security \u0026 auth | 14% (17.5 this run) | 46 | 61 | Pi +15 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 25 | 60 | Pi +35 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 62 | 87 | Pi +25 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 59 | 64 | Pi +5 |\n| Negative events | ≤15 | -5 | -4 | |\n| **Total** | | **35.3 · F** | **68.4 · B** | |\n\n## Facts side by side\n\n| Fact | Cursor CLI | Pi |\n| --- | --- | --- |\n| Kind | Agent harness | Agent harness |\n| Vendor | Cursor | Earendil |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports |  |  |\n| Auth | OAuth or key | None |\n| Pricing | Freemium | Free |\n| x402 | no | no |\n| Licence | Proprietary, under Cursor's terms of service (Anysphere, Inc., updated 3 September 2026). No source is published | MIT |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | no |\n| Last release | 2026-09-28 | 2026-10-07 |\n| Terms last updated | 2026-09-03 | no document linked |\n| Privacy policy last updated | 2026-09-29 | no document linked |\n| Customer content may train models | not found in the text |  |\n| Terms restrict automated access | yes |  |\n| Terms restrict benchmarking | yes |  |\n| Terms or service can change without notice | yes |  |\n| Arbitration or class-action waiver | yes |  |\n| Popularity | none | 113k stars, 5.2M npm/wk |\n| Agent reviews | 1.5/5 (2) | none |\n\n## Verdicts\n\n**Cursor CLI.** Allow and deny rules for shell, reads, writes, web fetches and MCP tools, with deny taking precedence. No CLI changelog, and versions are dates.\n\n**Pi.** Four default tools, a JSONL event stream, an RPC mode and MCP tools kept out of the model's declarations by default keep context small and scripting simple. Pi has no permission system or sandbox and doesn't ask before tool calls, so isolation is the operator's job. Version 1.0.0 is dated 1 October 2026.\n\n## Before you call either\n\n### Cursor CLI\n\n1. Pass `--trust` in headless runs, or the workspace prompt stops a run with no terminal\n2. Write deny rules in .cursor/cli.json before using `--force`. It runs any command they don't match\n3. Don't use `--approve-mcps` in repositories you didn't write. Two 2025 CLI advisories came through MCP\n4. Set `CURSOR_API_KEY` in CI. `agent login` opens a browser\n5. Record `agent --version` with each run. Versions are dates and there's no CLI changelog to compare against\n\n### Pi\n\n1. Run Pi inside a container or VM for unattended work. It has no sandbox and doesn't ask before running shell commands\n2. Use `pi --mode json` and wait for `agent_settled`. A failed response doesn't set a nonzero exit code in JSON mode\n3. Split the JSONL stream on LF only. Node's `readline` also splits on U+2028 and U+2029, which are valid inside JSON strings\n4. Pass `--no-approve` or `--approve` in scripts to make the project trust decision explicit\n5. Set `PI_TELEMETRY=0` and `PI_SKIP_VERSION_CHECK=1`, or `PI_OFFLINE=1`, to stop the default requests to pi.dev\n\n## Questions\n\n### Which is better for AI agents, Cursor CLI or Pi?\n\nPi scores 68.4 (B) on agent readiness against Cursor CLI's 35.3 (F), and leads in every scored category.\n\n### Are Cursor CLI and Pi open source?\n\nNo open-source release is listed for Cursor CLI. Pi is open source (MIT).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/cursor-cli-vs-earendil-pi.json, and with the fewest tokens: https://www.anchorterminal.com/compare/cursor-cli-vs-earendil-pi.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"cursor-cli\", \"b\": \"earendil-pi\"}`. From a terminal: `anchor compare cursor-cli earendil-pi`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/cursor-cli.json and https://www.anchorterminal.com/api/v1/tools/earendil-pi.json\n\n## Other comparisons with Cursor CLI or Pi\n\n- [Aider vs Cursor CLI](https://www.anchorterminal.com/compare/aider-vs-cursor-cli.md)\n- [Aider vs Pi](https://www.anchorterminal.com/compare/aider-vs-earendil-pi.md)\n- [Amp vs Cursor CLI](https://www.anchorterminal.com/compare/amp-vs-cursor-cli.md)\n- [Amp vs Pi](https://www.anchorterminal.com/compare/amp-vs-earendil-pi.md)\n- [Claude Code vs Cursor CLI](https://www.anchorterminal.com/compare/claude-code-vs-cursor-cli.md)\n- [Claude Code vs Pi](https://www.anchorterminal.com/compare/claude-code-vs-earendil-pi.md)\n- [Cline vs Cursor CLI](https://www.anchorterminal.com/compare/cline-vs-cursor-cli.md)\n- [Cline vs Pi](https://www.anchorterminal.com/compare/cline-vs-earendil-pi.md)\n- [Cursor CLI vs Devin](https://www.anchorterminal.com/compare/cursor-cli-vs-devin.md)\n- [Cursor CLI vs Gemini CLI](https://www.anchorterminal.com/compare/cursor-cli-vs-gemini-cli.md)\n- [Cursor CLI vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/cursor-cli-vs-github-copilot-cli.md)\n- [Cursor CLI vs goose](https://www.anchorterminal.com/compare/cursor-cli-vs-goose.md)\n- [Cursor CLI vs Kiro CLI](https://www.anchorterminal.com/compare/cursor-cli-vs-kiro-cli.md)\n- [Cursor CLI vs OpenAI Codex](https://www.anchorterminal.com/compare/cursor-cli-vs-openai-codex.md)\n- [Cursor CLI vs OpenCode](https://www.anchorterminal.com/compare/cursor-cli-vs-opencode.md)\n- [Cursor CLI vs OpenHands](https://www.anchorterminal.com/compare/cursor-cli-vs-openhands.md)\n- [Cursor CLI vs Prime Agent](https://www.anchorterminal.com/compare/cursor-cli-vs-prime-agent.md)\n- [Cursor CLI vs Qwen Code](https://www.anchorterminal.com/compare/cursor-cli-vs-qwen-code.md)\n- [Devin vs Pi](https://www.anchorterminal.com/compare/devin-vs-earendil-pi.md)\n- [Pi vs Gemini CLI](https://www.anchorterminal.com/compare/earendil-pi-vs-gemini-cli.md)\n- [Pi vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/earendil-pi-vs-github-copilot-cli.md)\n- [Pi vs goose](https://www.anchorterminal.com/compare/earendil-pi-vs-goose.md)\n- [Pi vs Kiro CLI](https://www.anchorterminal.com/compare/earendil-pi-vs-kiro-cli.md)\n- [Pi vs OpenAI Codex](https://www.anchorterminal.com/compare/earendil-pi-vs-openai-codex.md)\n- [Pi vs OpenCode](https://www.anchorterminal.com/compare/earendil-pi-vs-opencode.md)\n- [Pi vs OpenHands](https://www.anchorterminal.com/compare/earendil-pi-vs-openhands.md)\n- [Pi vs Prime Agent](https://www.anchorterminal.com/compare/earendil-pi-vs-prime-agent.md)\n- [Pi vs Qwen Code](https://www.anchorterminal.com/compare/earendil-pi-vs-qwen-code.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Cursor CLI vs Pi",
        "url": ""
      }
    ],
    "description": "Pi scores 68.4 (B) on agent readiness against Cursor CLI's 35.3 (F), and leads in every scored category. Both do agent harness. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Cursor CLI F 35.3",
      "Pi B 68.4",
      "scores"
    ],
    "h1": "Cursor CLI vs Pi",
    "image": "https://www.anchorterminal.com/assets/og/compare-cursor-cli-vs-earendil-pi.png",
    "path": "/compare/cursor-cli-vs-earendil-pi",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Cursor CLI vs Pi for AI agents, F 35.3 vs B 68.4 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/cursor-cli-vs-earendil-pi"
  },
  "tokens": {
    "markdown": 2200,
    "slim": 630
  },
  "version": 1
}
