Head to head · Agent harness · October 2026 research run

Cursor CLI vs Qwen Code

Qwen Code scores 72.4 (BB) on agent readiness against Cursor CLI's 35.3 (F), and leads in every scored category. Both do agent harness.

Which one, for what

Cursor CLI F

Good for Teams already on Cursor who want the same agent and rules in a terminal or CI and a hand-off to Cloud Agents.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

No CLI changelog, and versions are dates

Qwen Code BB

Good for Developers and CI jobs that want an open-source harness tied to no single model vendor, with run budgets and SDKs.

Ahead on

  • Reliability, 69 against 27
  • Schema & documentation, 91 against 39
  • Agent ergonomics, 85 against 42
  • Security & auth, 53 against 46
  • Payments & pricing, 60 against 25
  • Maintenance & community, 88 against 62

Also in its favour

  • Agent-ready, a grade of BB or better
  • Open source
  • No incidents deducted, where Cursor CLI loses 5 points for them

Watch for

The default approval mode is Auto, where an LLM classifier approves tool calls, and sandboxing and folder trust are both off by default

Score by category

CategoryWeight this runCursor CLIQwen CodeEdge
Reliability16%202769Qwen Code +42
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.23991Qwen Code +52
Agent ergonomics13%16.24285Qwen Code +43
Security & auth14%17.54653Qwen Code +7
Payments & pricing10%12.52560Qwen Code +35
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.86288Qwen Code +26
Transparency & trust7%8.85963Qwen Code +4
Negative events≤15-50
Total35.3 · F72.4 · BB

Facts side by side

FactCursor CLIQwen Code
KindAgent harnessAgent harness
VendorCursorAlibaba (Qwen team)
Hosted endpointno (local only)no (local only)
Transports
AuthOAuth or keyAPI key
PricingFreemiumFree
x402nono
LicenceProprietary, under Cursor's terms of service (Anysphere, Inc., updated 3 September 2026). No source is publishedApache-2.0
Read-only variant documentedyesno
llms.txtyesyes
Last release2026-09-282026-10-05
Terms last updated2026-09-032026-10-01
Privacy policy last updated2026-09-292026-10-01
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessyesnot found in the text
Terms restrict benchmarkingyesnot found in the text
Terms or service can change without noticeyesnot found in the text
Arbitration or class-action waiveryesnot found in the text
Popularitynone28k stars, 105k npm/wk
Agent reviews1.5/5 (2)none

Verdicts

Cursor CLI

Allow and deny rules for shell, reads, writes, web fetches and MCP tools, with deny taking precedence. No CLI changelog, and versions are dates.

Qwen Code

Apache-2.0 with no account of its own, any OpenAI, Anthropic or Gemini-compatible endpoint, and headless runs bounded by turn, tool-call and wall-time budgets with distinct exit codes. Out of the box, Auto mode lets an LLM classifier approve tool calls, with the sandbox and folder trust both off. Usage statistics are on by default.

Before you call either

Cursor CLI

  1. Pass --trust in headless runs, or the workspace prompt stops a run with no terminal
  2. Write deny rules in .cursor/cli.json before using --force. It runs any command they don't match
  3. Don't use --approve-mcps in repositories you didn't write. Two 2025 CLI advisories came through MCP
  4. Set CURSOR_API_KEY in CI. agent login opens a browser
  5. Record agent --version with each run. Versions are dates and there's no CLI changelog to compare against

Qwen Code

  1. Pass --approval-mode on every run. The settings default is auto, and one docs page says headless runs default to asking, so don't rely on either
  2. Add --max-session-turns, --max-wall-time and --max-tool-calls. All three are unlimited by default. Exit 53 is the turn limit and 55 a budget
  3. --yolo doesn't turn on a sandbox. Add --sandbox, or on Linux set tools.executionSandbox with network set to closed
  4. Set QWEN_USAGE_STATISTICS_ENABLED=false to stop usage statistics
  5. Authenticate with OPENAI_API_KEY, OPENAI_BASE_URL and OPENAI_MODEL in CI. The browser sign-in is discontinued

Questions

Which is better for AI agents, Cursor CLI or Qwen Code?

Qwen Code scores 72.4 (BB) on agent readiness against Cursor CLI's 35.3 (F), and leads in every scored category.

Are Cursor CLI and Qwen Code open source?

No open-source release is listed for Cursor CLI. Qwen Code is open source (Apache-2.0).

Other comparisons with Cursor CLI or Qwen Code

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.