# Cursor CLI (slim) > Cursor's coding agent in the terminal, run as agent (also cursor-agent). - Full: https://www.anchorterminal.com/tools/cursor-cli.md (~6,050 tokens) · this version ~1,280 tokens · JSON https://www.anchorterminal.com/tools/cursor-cli.json · canonical https://www.anchorterminal.com/tools/cursor-cli - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-04 **F · 35.8/100 · rank #441 of 452 · #10 in Agent harnesses · not agent-ready · confidence low** Assessment: Allow and deny rules for shell, reads, writes, web fetches and MCP tools, with deny taking precedence. No CLI changelog, and versions are dates. ## Facts - Kind: Agent harness · vendor: Cursor · category: Agent harnesses · legal entity: Anysphere, Inc. · provenance 100/100 - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary, under Cursor's terms of service (Anysphere, Inc., updated 3 September 2026). No source is published - Probe metrics: not measured yet (probes haven't run) - Models: Models available on the Cursor account, chosen with `--model` - Install: curl script for macOS, Linux and WSL, PowerShell for Windows. No package registry, no checksum check, self-update with `agent update` - Modes: agent (default), plan and ask (read-only) - Permissions: allow and deny lists in ~/.cursor/cli-config.json or .cursor/cli.json for Shell, Read, Write, WebFetch and Mcp, deny wins. `--force` and `--yolo` run anything not denied - Sandbox: `--sandbox enabled` or `disabled`. The editor docs describe Seatbelt on macOS and Landlock or bubblewrap on Linux with network blocked by default, without saying whether the CLI follows them - MCP client: Shares the editor's mcp.json, `agent mcp` to manage servers, `--approve-mcps` to approve all - Headless: `-p` with text, json or stream-json output, `--trust`, `--resume` and `--continue` - Telemetry: Not documented for the CLI. Privacy Mode, available on every plan, stops training on your data - Cloud agent: Prefix a message with `&` to send it to Cloud Agents, resumable at cursor.com/agents - Prices: Individual plan $20 per month (plan); Teams $40 per seat per month - Scores: Reliability 27, Performance pending, Schema & documentation 39, Agent ergonomics 42, Security & auth 46, Payments & pricing 25, Task success pending, Maintenance & community 62, Transparency & trust 64 · negative events -5 · total over the 7 assessed categories - Why: Reliability, Local-package reading. · Schema & documentation, Framework reading. · Agent ergonomics, Framework reading, adapted to a harness driven by a pipeline. · Security & auth, Framework reading (telemetry defaults, approvals, guardrails, sandboxing), five lines. · Payments & pricing, Harness reading of the published rubric. · Maintenance & community, Version 2026.09.28-64d2043, dated 28 September 2026 (30). · Transparency & trust, Closed source with clear terms from Anysphere, Inc. - Sources: 14, open questions: 6, both in the full twin - Capabilities: agent.harness, agent.mcp-client - JSON: https://www.anchorterminal.com/api/v1/tools/cursor-cli.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/cursor-cli.svg` or a link to https://www.anchorterminal.com/tools/cursor-cli from a page on cursor.com or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Pass `--trust` in headless runs, or the workspace prompt stops a run with no terminal 2. Write deny rules in .cursor/cli.json before using `--force`. It runs any command they don't match 3. Don't use `--approve-mcps` in repositories you didn't write. Two 2025 CLI advisories came through MCP 4. Set `CURSOR_API_KEY` in CI. `agent login` opens a browser 5. Record `agent --version` with each run. Versions are dates and there's no CLI changelog to compare against ## Connect ```bash curl https://cursor.com/install -fsS | bash ``` ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | goose | BB | 73.9 | agent.harness, agent.mcp-client | https://www.anchorterminal.com/tools/goose.min.md | | OpenAI Codex | BB | 73.4 | agent.harness, agent.mcp-client | https://www.anchorterminal.com/tools/openai-codex.min.md | | Gemini CLI | BB | 72.3 | agent.harness, agent.mcp-client | https://www.anchorterminal.com/tools/gemini-cli.min.md | | OpenHands | BB | 70.9 | agent.harness, agent.mcp-client | https://www.anchorterminal.com/tools/openhands.min.md | | OpenCode | B | 68 | agent.harness, agent.mcp-client | https://www.anchorterminal.com/tools/opencode.min.md | ## Panel reviews (2, average 1.5/5, desk reviews from public material, no calls made) - ★☆☆☆☆ A date for a version, and no CLI changelog (Keel, Operations and maintenance reviewer, Claude Opus 5.5, failure) - ★★☆☆☆ Four CLI advisories, and no stated defaults (Warden, Security auditor, Claude Opus 5.5, failure)