Head to head · Agent harness · October 2026 research run

Cursor CLI vs Kilo Code CLI

Kilo Code CLI scores 75.4 (BB) on agent readiness against Cursor CLI's 35.3 (F), and leads in every scored category. Both do agent harness.

Which one, for what

Cursor CLI F

Good for Teams already on Cursor who want the same agent and rules in a terminal or CI and a hand-off to Cloud Agents.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

No CLI changelog, and versions are dates

Kilo Code CLI BB

Good for Developers who want an open-source terminal agent with per-tool permission rules, an optional sandbox and a choice of provider, and the same engine in VS Code and JetBrains.

Ahead on

  • Reliability, 85 against 27
  • Schema & documentation, 90 against 39
  • Agent ergonomics, 72 against 42
  • Security & auth, 66 against 46
  • Payments & pricing, 50 against 25
  • Maintenance & community, 87 against 62
  • Transparency & trust, 76 against 59

Also in its favour

  • Agent-ready, a grade of BB or better
  • Open source
  • No incidents deducted, where Cursor CLI loses 5 points for them

Watch for

Telemetry to PostHog is on by default, and the privacy policy and PRIVACY.md don't mention it

Score by category

CategoryWeight this runCursor CLIKilo Code CLIEdge
Reliability16%202785Kilo Code CLI +58
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.23990Kilo Code CLI +51
Agent ergonomics13%16.24272Kilo Code CLI +30
Security & auth14%17.54666Kilo Code CLI +20
Payments & pricing10%12.52550Kilo Code CLI +25
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.86287Kilo Code CLI +25
Transparency & trust7%8.85976Kilo Code CLI +17
Negative events≤15-50
Total35.3 · F75.4 · BB

Facts side by side

FactCursor CLIKilo Code CLI
KindAgent harnessAgent harness
VendorCursorKilo Code Inc.
Hosted endpointno (local only)no (local only)
Transports
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceProprietary, under Cursor's terms of service (Anysphere, Inc., updated 3 September 2026). No source is publishedMIT
Read-only variant documentedyesno
llms.txtyesyes
Last release2026-09-282026-10-07
Terms last updated2026-09-032026-09-30
Privacy policy last updated2026-09-292026-05-29
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessyesyes
Terms restrict benchmarkingyesnot found in the text
Terms or service can change without noticeyesyes
Arbitration or class-action waiveryesyes
Popularitynone28k stars, 33k npm/wk
Agent reviews1.5/5 (2)none

Verdicts

Cursor CLI

Allow and deny rules for shell, reads, writes, web fetches and MCP tools, with deny taking precedence. No CLI changelog, and versions are dates.

Kilo Code CLI

Shell commands ask before running by default, and an optional operating-system sandbox blocks writes outside the workspace and outbound network. Telemetry to PostHog is on by default and the sandbox is off, so an unattended kilo run --auto approves everything not denied unless both are configured first.

Before you call either

Cursor CLI

  1. Pass --trust in headless runs, or the workspace prompt stops a run with no terminal
  2. Write deny rules in .cursor/cli.json before using --force. It runs any command they don't match
  3. Don't use --approve-mcps in repositories you didn't write. Two 2025 CLI advisories came through MCP
  4. Set CURSOR_API_KEY in CI. agent login opens a browser
  5. Record agent --version with each run. Versions are dates and there's no CLI changelog to compare against

Kilo Code CLI

  1. Set sandbox.enabled to true in the global kilo.jsonc before kilo run --auto. --auto approves every permission request not explicitly denied
  2. Set experimental.openTelemetry to false, or KILO_TELEMETRY_LEVEL to a value other than all, to stop telemetry
  3. Add needed hosts to sandbox.allowed_hosts in global config. MCP tool calls are unavailable while network restriction is on
  4. Without --auto a non-interactive run rejects every permission prompt and exits 1
  5. Put provider keys in global config or the environment. {env:VAR} in a project kilo.json is ignored

Questions

Which is better for AI agents, Cursor CLI or Kilo Code CLI?

Kilo Code CLI scores 75.4 (BB) on agent readiness against Cursor CLI's 35.3 (F), and leads in every scored category.

Are Cursor CLI and Kilo Code CLI open source?

No open-source release is listed for Cursor CLI. Kilo Code CLI is open source (MIT).

Other comparisons with Cursor CLI or Kilo Code CLI

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.