{
  "data": {
    "a": {
      "slug": "cursor-cli",
      "name": "Cursor CLI",
      "vendor": "Cursor",
      "vendorUrl": "https://cursor.com/cli",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Cursor's coding agent in the terminal, run as `agent` (also `cursor-agent`).",
      "url": "https://www.anchorterminal.com/tools/cursor-cli",
      "markdownUrl": "https://www.anchorterminal.com/tools/cursor-cli.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/cursor-cli.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/cursor-cli.json",
      "license": "Proprietary, under Cursor's terms of service (Anysphere, Inc., updated 3 September 2026). No source is published",
      "transports": [],
      "packages": [],
      "auth": "mixed",
      "authNotes": "`agent login` through a browser, or an API key passed with `--api-key` or `CURSOR_API_KEY` for headless runs.",
      "pricing": "freemium",
      "pricingNotes": "Hobby is free with limited Agent requests and needs no card. Individual is $20 a month, Teams $40 a user a month and Enterprise by quote. Every plan includes a set amount of model usage, with on-demand usage billed in arrears, and the pricing page gives no dollar or request figure for either (checked 2026-10-02).",
      "priceSummary": "$20 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the pricing page (checked 2026-10-02).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-02"
      },
      "docsUrl": "https://cursor.com/docs/cli/overview",
      "llmsTxt": "https://cursor.com/llms.txt",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client"
      ],
      "tags": [
        "official",
        "harness",
        "coding-agent",
        "cli",
        "closed-source",
        "mcp",
        "llms-txt",
        "free-tier",
        "no-card",
        "status-page"
      ],
      "lastRelease": "2026-09-28",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 35.8,
        "grade": "F",
        "agentReady": false,
        "rank": 441,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 10,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 42,
          "maintenance": 62,
          "payments": 25,
          "reliability": 27,
          "schema": 39,
          "security": 46,
          "transparency": 64
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "low",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "2025-10-02 and 2025-11-03. Four high advisories that name the CLI, all fixed. Remote code execution in Cursor CLI through Cursor Agent MCP OAuth2 communication (GHSA-wj33-264c-j9cq), arbitrary code execution through a permissive CLI config (GHSA-v64q-396f-7m79), a sensitive-file overwrite bypass in the CLI agent (GHSA-x2vq-h6v6-jhc6) and command injection through an untrusted MCP configuration in Cursor CLI Beta (GHSA-4hwr-97q3-37w2). All older than six months, so 1 point each (https://github.com/cursor/cursor/security/advisories)",
          "2026-01-14. GHSA-82wg-qcm4-fp2w, high, terminal tool allowlist bypass through environment variables. It doesn't name the CLI, which runs the same terminal tool and allowlist idea. Fixed and published, 1 point. Judgement call. We left out the 2026 sandbox escapes titled for Cursor Desktop and Cloud Agents (https://github.com/cursor/cursor/security/advisories)"
        ],
        "verdict": "Allow and deny rules for shell, reads, writes, web fetches and MCP tools, with deny taking precedence. No CLI changelog, and versions are dates.",
        "strengths": [
          "Allow and deny rules for shell, reads, writes, web fetches and MCP tools, with deny taking precedence",
          "Print mode with text, json and stream-json output, plus `--resume` and `--continue`",
          "Plan and ask (read-only) modes alongside the default agent mode",
          "Hands a task to Cloud Agents by prefixing the message with `\u0026`",
          "A free Hobby plan with no card, and a status page with a CLI component"
        ],
        "weaknesses": [
          "No CLI changelog, and versions are dates",
          "The install script checks no checksum or signature",
          "No documentation of CLI telemetry or of what runs without approval by default",
          "Four high advisories named the CLI in October and November 2025",
          "Closed source, with no public issue tracker"
        ],
        "agentNotes": [
          "Pass `--trust` in headless runs, or the workspace prompt stops a run with no terminal",
          "Write deny rules in .cursor/cli.json before using `--force`. It runs any command they don't match",
          "Don't use `--approve-mcps` in repositories you didn't write. Two 2025 CLI advisories came through MCP",
          "Set `CURSOR_API_KEY` in CI. `agent login` opens a browser",
          "Record `agent --version` with each run. Versions are dates and there's no CLI changelog to compare against"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 1.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "low",
            "grade": "F",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 35.8
          }
        ],
        "editorialScores": {
          "ergonomics": 42,
          "maintenance": 62,
          "payments": 25,
          "reliability": 27,
          "schema": 39,
          "security": 46,
          "transparency": 27
        },
        "provenanceScore": 100
      },
      "connect": {
        "install": "curl https://cursor.com/install -fsS | bash",
        "headless": {
          "run": "agent -p \"fix the failing test\" --output-format json --trust"
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/cursor-cli"
      },
      "area": "frameworks",
      "unitPrices": [
        {
          "item": "Individual plan",
          "unit": "month",
          "usd": 20,
          "note": "includes a set amount of model usage"
        },
        {
          "item": "Teams",
          "unit": "seat-month",
          "usd": 40,
          "note": "per user"
        }
      ],
      "provenance": {
        "legalEntity": "Anysphere, Inc.",
        "domain": "cursor.com",
        "domainRegistered": "1995-12-20",
        "endpointOnVendorDomain": null,
        "terms": "https://cursor.com/terms-of-service",
        "privacy": "https://cursor.com/privacy",
        "statusPage": "https://status.cursor.com",
        "changelog": "https://cursor.com/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-01",
        "notes": [
          "The terms of service (updated 3 September 2026) name Anysphere, Inc.",
          "RDAP (Verisign) gives cursor.com a registration date of 1995-12-20, long before Anysphere.",
          "cursor.com/.well-known/security.txt has a Contact line pointing to Cursor's GitHub security advisories and no Expires line, which RFC 9116 requires. The site's tracker reads a file with a Contact and no Expires as valid.",
          "The changelog covers all of Cursor, and we found no CLI-only changelog."
        ],
        "score": 100
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/cursor-cli.json",
      "live": {
        "slug": "cursor-cli",
        "vendorStatus": {
          "page": "https://status.cursor.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-04T21:39:55.87045525Z"
        },
        "securityTxt": {
          "url": "https://cursor.com/.well-known/security.txt",
          "state": "valid",
          "checkedAt": "2026-10-04T15:15:59.179317189Z"
        },
        "llmsTxt": {
          "url": "https://cursor.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:29.345712262Z"
        },
        "domain": {
          "domain": "cursor.com",
          "registered": "1995-12-20",
          "source": "https://rdap.verisign.com/com/v1/domain/cursor.com",
          "checkedAt": "2026-10-04T13:09:09.510989819Z"
        },
        "pages": [
          {
            "url": "https://cursor.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:42:16.526843692Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0533f35b59a7"
          },
          {
            "url": "https://cursor.com/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:42:18.612925478Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a5f74b5510f1"
          },
          {
            "url": "https://cursor.com/terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:42:20.641585682Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5db93dae47db"
          }
        ],
        "updatedAt": "2026-10-04T21:39:55.87045525Z"
      }
    },
    "b": {
      "slug": "github-copilot-cli",
      "name": "GitHub Copilot CLI",
      "vendor": "GitHub",
      "vendorUrl": "https://github.com/features/copilot/cli",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "GitHub's coding agent for the terminal, built on the same agent harness as Copilot cloud agent (formerly Copilot coding agent), which works in GitHub Actions and opens pull requests.",
      "url": "https://www.anchorterminal.com/tools/github-copilot-cli",
      "markdownUrl": "https://www.anchorterminal.com/tools/github-copilot-cli.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/github-copilot-cli.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/github-copilot-cli.json",
      "repo": "https://github.com/github/copilot-cli",
      "license": "Proprietary, under the licence in the repository's `LICENSE.md`. Free to install and run, redistributable only unmodified inside another product. The repository holds the README, changelog and install script, not the source",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@github/copilot"
        }
      ],
      "auth": "mixed",
      "authNotes": "`/login` with a GitHub account, or a fine-grained personal access token with the Copilot Requests permission in `GH_TOKEN` or `GITHUB_TOKEN`. Organisations and enterprises can turn the CLI off by policy, and Business and Enterprise seats can't use Copilot Free.",
      "pricing": "freemium",
      "pricingNotes": "Copilot Free ($0, no card) includes the CLI and agent mode with 50 chat requests a month. Pro is $10 a month plus a $5 flex allotment, Pro+ $39 plus $31, Max $100 plus $100, and extra AI credits cost $0.01 each. Business and Enterprise prices aren't on the plans page. Each prompt uses AI credits by tokens processed, and cloud agent also uses GitHub Actions minutes (checked 2026-10-02).",
      "priceSummary": "$0.01 / credit",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the plans page or the changelog (checked 2026-10-02).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 11000,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-02"
      },
      "docsUrl": "https://docs.github.com/en/copilot/concepts/agents/about-copilot-cli",
      "llmsTxt": "https://docs.github.com/llms.txt",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client",
        "agent.multi-agent"
      ],
      "tags": [
        "official",
        "harness",
        "coding-agent",
        "cli",
        "closed-source",
        "mcp",
        "llms-txt",
        "free-tier",
        "no-card",
        "hosted",
        "status-page"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 57.9,
        "grade": "C",
        "agentReady": false,
        "rank": 286,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 8,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 77,
          "payments": 40,
          "reliability": 55,
          "schema": 72,
          "security": 60,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "2026-09-22. 1.0.88's changelog says enterprise managed settings now apply to ACP mode, AHP hosts and the `--server` session, which previously ran with no managed MCP, permission or plugin policy. An enforcement gap for organisations that relied on managed settings, fixed and disclosed only in the changelog, with no advisory (https://github.com/github/copilot-cli/blob/main/changelog.md). -2",
          "2026-05-11. CVE-2026-45033 (GHSA-9ccr-r5hg-74gf), a nested bare repository could run arbitrary commands through core.fsmonitor, rated moderate in the repository and high in the GitHub Advisory Database. Fixed and published, inside six months (https://github.com/advisories/GHSA-9ccr-r5hg-74gf). -2",
          "2026-03-06. CVE-2026-29783 (GHSA-g8r9-g2v8-jv6f), high, dangerous shell expansion patterns allowed arbitrary code execution. Fixed and published, older than six months (https://github.com/advisories/GHSA-g8r9-g2v8-jv6f). -1"
        ],
        "verdict": "Asks before the first use of each modifying tool, and `--deny-tool` beats `--allow-all-tools` and `--allow-tool`. Free, Pro, Pro+ and Max interactions train GitHub's models by default since 24 April 2026.",
        "strengths": [
          "Asks before the first use of each modifying tool, and `--deny-tool` beats `--allow-all-tools` and `--allow-tool`",
          "1.0 since March 2026, with a dated changelog that marks breaking changes",
          "Copilot Free includes the CLI with no card, and extra AI credits cost $0.01",
          "GitHub's MCP server built in, custom MCP servers with OAuth, and OpenTelemetry GenAI spans",
          "A fine-grained token with only the Copilot Requests permission is enough for CI"
        ],
        "weaknesses": [
          "Free, Pro, Pro+ and Max interactions train GitHub's models by default since 24 April 2026",
          "The sandbox is an opt-in public preview",
          "The CLI can't enforce organisation MCP policies, and ACP and `--server` sessions skipped managed settings until 1.0.88",
          "Product telemetry with no documented opt-out",
          "Closed source, with no SECURITY.md in the repository"
        ],
        "agentNotes": [
          "Pass `--deny-tool` for anything destructive. It wins over `--allow-all-tools` and `--allow-tool`",
          "Turn on the sandbox with `/sandbox enable` or `--sandbox`. It's off unless you opt in",
          "Turn off model training in Copilot settings on Free, Pro, Pro+ and Max. It's on by default since 24 April 2026",
          "Run 1.0.88 or later where enterprise policy matters. Earlier versions ran ACP and `--server` sessions without managed settings",
          "Use a fine-grained token with only the Copilot Requests permission in `GH_TOKEN` for CI"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 57.9
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 77,
          "payments": 40,
          "reliability": 55,
          "schema": 72,
          "security": 60,
          "transparency": 49
        },
        "provenanceScore": 94
      },
      "connect": {
        "install": "npm i -g @github/copilot   # or: brew install copilot-cli",
        "headless": {
          "run": "copilot -p \"fix the failing test\" --allow-tool 'write' --deny-tool 'shell(git push)'"
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/github-copilot-cli"
      },
      "sameCompany": [
        "github-mcp-server"
      ],
      "area": "frameworks",
      "unitPrices": [
        {
          "item": "AI credit",
          "unit": "credit",
          "usd": 0.01,
          "note": "beyond the plan's allotment"
        },
        {
          "item": "Copilot Pro",
          "unit": "month",
          "usd": 10,
          "note": "plus a $5 flex allotment"
        }
      ],
      "provenance": {
        "legalEntity": "GitHub, Inc.",
        "domain": "github.com",
        "domainRegistered": "2007-10-09",
        "domainNote": "github.com publishes a security.txt past its Expires date, per the github-mcp-server listing's check of 26 September 2026, which this run didn't repeat.",
        "endpointOnVendorDomain": null,
        "terms": "https://docs.github.com/en/site-policy/github-terms/github-terms-of-service",
        "privacy": "https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement",
        "statusPage": "https://www.githubstatus.com",
        "changelog": "https://github.com/github/copilot-cli/blob/main/changelog.md",
        "securityTxt": "expired",
        "checked": "2026-10-01",
        "score": 94
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/github-copilot-cli.json",
      "live": {
        "slug": "github-copilot-cli",
        "vendorStatus": {
          "page": "https://www.githubstatus.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-04T21:40:04.838066047Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "github/copilot-cli",
            "version": "v1.0.91",
            "released": "2026-10-01",
            "seenAt": "2026-10-04T16:28:00.810427203Z"
          },
          {
            "registry": "npm",
            "name": "@github/copilot",
            "version": "1.0.91",
            "seenAt": "2026-10-04T16:27:59.993331647Z"
          }
        ],
        "githubStars": 11235,
        "npmWeekly": 1712758,
        "securityTxt": {
          "url": "https://github.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2026-11-03T15:16:02z",
          "checkedAt": "2026-10-04T15:16:02.867444993Z"
        },
        "llmsTxt": {
          "url": "https://docs.github.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:48.31339366Z"
        },
        "domain": {
          "domain": "github.com",
          "registered": "2007-10-09",
          "source": "https://rdap.verisign.com/com/v1/domain/github.com",
          "checkedAt": "2026-10-04T13:05:18.320609382Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/github/copilot-cli/main/changelog.md",
            "kind": "deprecations",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:33.259981925Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f5debd759b4a"
          },
          {
            "url": "https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:43:41.923557881Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "b2c773d01d82"
          },
          {
            "url": "https://docs.github.com/en/site-policy/github-terms/github-terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:43:39.466219844Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c1da594b43f5"
          }
        ],
        "updatedAt": "2026-10-04T21:40:04.838066047Z"
      }
    },
    "summary": "GitHub Copilot CLI has a score of 57.9 (C) against Cursor CLI's 35.8 (F). Both do agent harness. The largest gap is schema \u0026 documentation, 33 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/cursor-cli-vs-github-copilot-cli",
    "json": "https://www.anchorterminal.com/compare/cursor-cli-vs-github-copilot-cli.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/cursor-cli-vs-github-copilot-cli.md",
    "slim": "https://www.anchorterminal.com/compare/cursor-cli-vs-github-copilot-cli.min.md"
  },
  "markdown": "GitHub Copilot CLI has a score of 57.9 (C) against Cursor CLI's 35.8 (F). Both do agent harness. The largest gap is schema \u0026 documentation, 33 points.\n\n- Cursor CLI: grade F, 35.8/100, rank #441 of 452. Markdown https://www.anchorterminal.com/tools/cursor-cli.md · JSON https://www.anchorterminal.com/api/v1/tools/cursor-cli.json\n- GitHub Copilot CLI: grade C, 57.9/100, rank #286 of 452. Markdown https://www.anchorterminal.com/tools/github-copilot-cli.md · JSON https://www.anchorterminal.com/api/v1/tools/github-copilot-cli.json\n\n## Which one, for what\n\nPick Cursor CLI for nothing in particular (no category where it leads by five points or more).\n\nPick GitHub Copilot CLI for reliability (+28), schema \u0026 documentation (+33), agent ergonomics (+30), security \u0026 auth (+14), payments \u0026 pricing (+15), maintenance \u0026 community (+15), transparency \u0026 trust (+8).\n\n## Score by category\n\n| Category | Weight | Cursor CLI | GitHub Copilot CLI | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 27 | 55 | GitHub Copilot CLI +28 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 39 | 72 | GitHub Copilot CLI +33 |\n| Agent ergonomics | 13% (16.2 this run) | 42 | 72 | GitHub Copilot CLI +30 |\n| Security \u0026 auth | 14% (17.5 this run) | 46 | 60 | GitHub Copilot CLI +14 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 25 | 40 | GitHub Copilot CLI +15 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 62 | 77 | GitHub Copilot CLI +15 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 64 | 72 | GitHub Copilot CLI +8 |\n| Negative events | ≤15 | -5 | -5 | |\n| **Total** | | **35.8 · F** | **57.9 · C** | |\n\n## Facts side by side\n\n| Fact | Cursor CLI | GitHub Copilot CLI |\n| --- | --- | --- |\n| Kind | Agent harness | Agent harness |\n| Vendor | Cursor | GitHub |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports |  |  |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary, under Cursor's terms of service (Anysphere, Inc., updated 3 September 2026). No source is published | Proprietary, under the licence in the repository's `LICENSE.md`. Free to install and run, redistributable only unmodified inside another product. The repository holds the README, changelog and install script, not the source |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-09-28 | 2026-10-01 |\n| Popularity | none | 11k stars |\n| Agent reviews | 1.5/5 (2) | 2.5/5 (2) |\n\n## Verdicts\n\n**Cursor CLI.** Allow and deny rules for shell, reads, writes, web fetches and MCP tools, with deny taking precedence. No CLI changelog, and versions are dates.\n\n**GitHub Copilot CLI.** Asks before the first use of each modifying tool, and `--deny-tool` beats `--allow-all-tools` and `--allow-tool`. Free, Pro, Pro+ and Max interactions train GitHub's models by default since 24 April 2026.\n\n## Before you call either\n\n### Cursor CLI\n\n1. Pass `--trust` in headless runs, or the workspace prompt stops a run with no terminal\n2. Write deny rules in .cursor/cli.json before using `--force`. It runs any command they don't match\n3. Don't use `--approve-mcps` in repositories you didn't write. Two 2025 CLI advisories came through MCP\n4. Set `CURSOR_API_KEY` in CI. `agent login` opens a browser\n5. Record `agent --version` with each run. Versions are dates and there's no CLI changelog to compare against\n\n### GitHub Copilot CLI\n\n1. Pass `--deny-tool` for anything destructive. It wins over `--allow-all-tools` and `--allow-tool`\n2. Turn on the sandbox with `/sandbox enable` or `--sandbox`. It's off unless you opt in\n3. Turn off model training in Copilot settings on Free, Pro, Pro+ and Max. It's on by default since 24 April 2026\n4. Run 1.0.88 or later where enterprise policy matters. Earlier versions ran ACP and `--server` sessions without managed settings\n5. Use a fine-grained token with only the Copilot Requests permission in `GH_TOKEN` for CI\n\n## Other comparisons with Cursor CLI or GitHub Copilot CLI\n\n- [Aider vs Cursor CLI](https://www.anchorterminal.com/compare/aider-vs-cursor-cli.md)\n- [Aider vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/aider-vs-github-copilot-cli.md)\n- [Claude Code vs Cursor CLI](https://www.anchorterminal.com/compare/claude-code-vs-cursor-cli.md)\n- [Claude Code vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/claude-code-vs-github-copilot-cli.md)\n- [Cline vs Cursor CLI](https://www.anchorterminal.com/compare/cline-vs-cursor-cli.md)\n- [Cline vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/cline-vs-github-copilot-cli.md)\n- [Cursor CLI vs Gemini CLI](https://www.anchorterminal.com/compare/cursor-cli-vs-gemini-cli.md)\n- [Cursor CLI vs goose](https://www.anchorterminal.com/compare/cursor-cli-vs-goose.md)\n- [Cursor CLI vs OpenAI Codex](https://www.anchorterminal.com/compare/cursor-cli-vs-openai-codex.md)\n- [Cursor CLI vs OpenCode](https://www.anchorterminal.com/compare/cursor-cli-vs-opencode.md)\n- [Cursor CLI vs OpenHands](https://www.anchorterminal.com/compare/cursor-cli-vs-openhands.md)\n- [Gemini CLI vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/gemini-cli-vs-github-copilot-cli.md)\n- [GitHub Copilot CLI vs goose](https://www.anchorterminal.com/compare/github-copilot-cli-vs-goose.md)\n- [GitHub Copilot CLI vs OpenAI Codex](https://www.anchorterminal.com/compare/github-copilot-cli-vs-openai-codex.md)\n- [GitHub Copilot CLI vs OpenCode](https://www.anchorterminal.com/compare/github-copilot-cli-vs-opencode.md)\n- [GitHub Copilot CLI vs OpenHands](https://www.anchorterminal.com/compare/github-copilot-cli-vs-openhands.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Cursor CLI vs GitHub Copilot CLI",
        "url": ""
      }
    ],
    "description": "GitHub Copilot CLI has a score of 57.9 (C) against Cursor CLI's 35.8 (F). Both do agent harness. The largest gap is schema \u0026 documentation, 33 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Cursor CLI F 35.8",
      "GitHub Copilot CLI C 57.9",
      "scores"
    ],
    "h1": "Cursor CLI vs GitHub Copilot CLI",
    "image": "https://www.anchorterminal.com/assets/og/compare-cursor-cli-vs-github-copilot-cli.png",
    "path": "/compare/cursor-cli-vs-github-copilot-cli",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Cursor CLI vs GitHub Copilot CLI for AI agents, F 35.8 vs C 57.9",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/cursor-cli-vs-github-copilot-cli"
  },
  "tokens": {
    "markdown": 1700,
    "slim": 380
  },
  "version": 1
}
