Desktop harness · Anysphere

Cursor

Cursor desktop workbench.

ProductCursorAnysphereDesktop · 54/114 current cells reviewed

Catalog twins:MarkdownJSON

Surface
Desktop
Execution
local
Target type
release
Default environment
local default
Tracks
Current, Preview
Latest current evidence
2026-08-28

Description and scope

About this harness

This profile represents one exact product surface—not every product from Anysphere.

Cursor appears here as a Desktop column so a capability page can show this harness next to others.

Support cells for this surface are published only when a dated note cites reviewable public evidence; every other cell remains unknown.

Current-track snapshot

Support at a glance

54 of 114 atomic capabilities have a reviewed current status.

Research coverage47%
28 unique public sources on the current track
Supported
49
Public evidence supports the current claim.
Partial
5
Supported with a documented condition or limit.
Unsupported
0
A current source explicitly says no.
Unknown
60
No sufficiently scoped public evidence is published yet.
Unknown is not “unsupported.” It means this exact product-and-capability cell has not passed the catalog’s evidence bar. Conditions such as plan, platform, preview access, policy, and runtime stay attached to individual rows below.

Provider and standards provenance

Reviewed public references

These links support individual capability cells. They are not a product-wide certification.

Atomic capability ledger

Capability support

Open a capability record for its full notes, qualifiers, targets, and source links.

114 capabilities
CapabilityCurrentPreviewCurrent evidence and conditions
InterfacesAgent Plugins failure isolation

Reject invalid components narrowly without disabling valid components in the same package.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesAgent Plugins packaged MCP

Load MCP server configuration contained in an Agent Plugins package.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesAgent Plugins packaged skills

Load portable Agent Skills contained in an Agent Plugins package.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesAgent Plugins portable manifest

Load the published portable plugin.json manifest and its core components.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimeAgent Skills core and discovery

Recognize, discover, and load reusable instruction packages centered on SKILL.md.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor Agent Skills documentationNo additional condition recorded.Evidence and notes →
RuntimeAgent Skills manual invocation

Let a user or agent explicitly select and activate a named skill.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor Agent Skills documentationNo additional condition recorded.Evidence and notes →
RuntimeAgent Skills progressive loading

Load skill metadata first and defer full instructions or resources until relevant.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor Agent Skills documentationNo additional condition recorded.Evidence and notes →
RuntimeAgent Skills references and assets

Resolve supporting reference files, templates, and assets from a skill package.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor Agent Skills documentationNo additional condition recorded.Evidence and notes →
RuntimeAgent Skills scripts

Resolve and execute optional scripts included with an Agent Skill under explicit runtime policy.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor Agent Skills documentation
  • policy: actual execution depends on the agent's tool permissions and available language runtime
Evidence and notes →
InterfacesAGENTS.md root instructions

Discover and apply the cross-agent AGENTS.md convention at repository scope.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor Rules documentation
  • host role: claim is scoped to Cursor Agent in the desktop workbench
Evidence and notes →
CollaborationArtifact export

Download generated files and other documented outputs.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Files and mediaAudio file input

Upload recorded audio for use as model input.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Security and privacyAudit logs

Record security-relevant activity in an administrative audit log.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Models and contextAutomatic context compaction

Continue long sessions by automatically summarizing or pruning older context.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor chat-summarization documentation
  • runtime: Cursor summarizes older messages as chats exceed the model context window and separately condenses oversized files and folders
Evidence and notes →
RuntimeBackground agents

Keep a run going after the operator leaves the session.

PPartial?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor Cloud Agents documentation
  • runtime: Cursor Desktop starts a separate Cloud Agent VM; the default local desktop agent is not itself detached
  • plan: a paid Cursor plan and connected source-control account are required
Evidence and notes →
ToolsBrowser automation

Control a browser for navigation, clicks, forms, and page reading.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor browser-tools documentation
  • runtime: automation is scoped to Cursor's integrated browser rather than arbitrary desktop applications
  • policy: enterprise MCP origin policy can restrict browser access
Evidence and notes →
ToolsCode execution

Run generated code in a documented execution environment.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimeComputer use

Inspect and act on a visual interface through screenshots and input actions.

PPartial?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor browser documentation
  • runtime: integrated browser only
  • policy: enterprise MCP origin policy can restrict access
Evidence and notes →
RuntimeConcurrent subagents

Run multiple child-agent tasks concurrently with explicit queue and fan-out limits.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor subagent documentation
  • runtime: multiple Task calls can start simultaneously; shared-checkout writers can collide unless worktree or cloud isolation is requested
Evidence and notes →
ToolsConnectors

Connect to external services authorized by the user or organization.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Models and contextContext compaction controls

Trigger, inspect, configure, or disable context compaction.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Models and contextContext usage

Inspect consumed or remaining context budget during a conversation or run.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Models and contextContext window

Record the documented context-window limit by product, model, and mode.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor models documentation
  • runtime: normal mode uses 200k tokens; Max Mode extends to the selected model's maximum, with some supported models reaching 1M
  • plan: Max Mode availability and billing depend on plan and model
Evidence and notes →
CollaborationConversation export

Export conversation history in a documented format.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Cursor chat-history documentation observation
  • runtime: local Agent chats can be exported as Markdown
  • runtime: chat history is stored in a local SQLite database; Background Agent chats are stored separately in a remote database and are not documented as part of this export
Evidence and notes →
CollaborationConversation sharing

Share a conversation through a documented link or invitation.

PPartial?Unknown1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Cursor Background Agent sharing documentation observation
  • runtime: web and mobile Background Agent runs can be shared by link for teammate diff review and feedback
  • policy: recipient roles, account or team restrictions, expiration, revocation, and full transcript visibility are not established by the reviewed page
Evidence and notes →
InterfacesCustom instructions

Persist instructions at user or project scope.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Security and privacyData residency

Select or document geographic storage or processing regions.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Cursor Enterprise residency documentation observation
  • plan: US-only residency is enabled per Enterprise team through the account team; EU and Iceland inference-only coverage is available on request
  • policy: supported US-only coverage includes model inference, content-processing pipelines, customer-data storage and backups, Cloud Agents, Tab, editing, autocomplete, and semantic search
  • runtime: eligible models are restricted, and authentication, some indexing, BYOK, custom models, MCP and web integrations, Bugbot, shared links, and Slack or web triggers have documented exceptions
Evidence and notes →
Security and privacyData retention controls

Configure or document retention and deletion for covered product data.

PPartial?Unknown1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Cursor privacy documentation observation
  • policy: Privacy Mode uses ZDR agreements with model providers; encrypted file-content caches are temporary and their server-side keys exist only for the request
  • runtime: codebase indexing may persist embeddings and metadata, and abuse-triggered data may follow provider investigation retention
  • policy: user-configurable retention periods, backup expiry, and verified deletion completion are not established by the reviewed page
Evidence and notes →
ToolsDiffs and patches

Propose or apply file changes as diffs or patches.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor diff-review documentation
  • host role: claim is scoped to Cursor Agent in the desktop workbench
Evidence and notes →
Files and mediaDocument input

Upload common document formats for use as model input.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Security and privacyEncryption key management

Record documented encryption key ownership, scope, rotation, and revocation.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Cursor CMEK documentation observation
  • plan: Enterprise customers contact sales to enable CMEK
  • policy: embeddings and Cloud Agent data stored in Cursor infrastructure are encrypted with the customer key, and the customer controls key rotation and access
  • runtime: the reviewed page does not establish CMEK coverage for every prompt, model-provider request, external integration, shared link, or local artifact
Evidence and notes →
Files and mediaFile upload limits

Record numeric attachment size, count, page, duration, storage, and rolling quotas.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimeHuman approval

Pause before a tool action or file change until a person confirms.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor documentation
  • policy: ordinary workspace-file edits do not prompt; terminal, MCP, configuration-file, and sensitive actions do unless pre-approved or another run mode applies
Evidence and notes →
Files and mediaImage input

Attach, paste, or select an image for use as model input.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor Agent documentation
  • runtime: PNG, JPEG, GIF, WebP, and SVG files enter conversation context when the selected model is vision-capable
Evidence and notes →
Models and contextLocal models

Run against a model hosted on the operator's machine.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimeLong-term memory

Persist notes across sessions.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP Apps

Render an interactive interface returned by an MCP server inside the product.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP cancellation

Cancel an in-flight MCP request and handle cancellation correctly.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP client role

Consume capabilities exposed by MCP servers.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor MCP documentation observed 2026-08-28
  • policy: configured server enablement, tool approval, enterprise allowlists, and server health determine which capabilities are available
Evidence and notes →
InterfacesMCP elicitation

Handle structured user-input requests initiated by an MCP server.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor MCP documentation observed 2026-08-28
  • runtime: the documentation confirms elicitation generally but does not enumerate form-mode, URL-mode, or automation-hook behavior
Evidence and notes →
InterfacesMCP legacy HTTP and SSE

Connect through the superseded HTTP plus SSE transport when migration compatibility is required.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor MCP documentation observed 2026-08-28
  • transport: SSE remains supported for compatibility, while Cursor separately documents Streamable HTTP for current HTTP endpoints
Evidence and notes →
InterfacesMCP list-changed notifications

Refresh capability lists when a server announces dynamic changes.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP logging

Receive structured log messages emitted by an MCP server.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP OAuth authorization

Complete the MCP authorization flow for protected remote servers.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor MCP documentation observed 2026-08-28
  • auth: remote servers may use dynamic registration or configured static credentials, and redirect URLs differ between web/agents and desktop surfaces
Evidence and notes →
InterfacesMCP progress notifications

Receive progress updates for long-running requests.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP prompt-list notifications

Refresh prompt templates after a server announces changes.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP prompts

Invoke reusable MCP prompt templates.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor MCP documentation observed 2026-08-28
  • runtime: available templates and their arguments depend on prompts exposed by the connected server
Evidence and notes →
InterfacesMCP Registry metadata

Discover MCP servers and metadata through the official registry model.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP resource subscriptions

Subscribe to resource changes and receive update notifications.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP resources

Read MCP resources as live context.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor MCP documentation observed 2026-08-28
  • runtime: exact resource availability, URI schemes, and media types depend on the connected server
Evidence and notes →
InterfacesMCP revision compatibility

Implement or negotiate the exact dated MCP revision.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP roots

Provide filesystem or workspace roots to an MCP server.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor MCP documentation observed 2026-08-28
  • runtime: the documentation confirms the capability but does not enumerate Cursor's root selection or change-notification policy
Evidence and notes →
InterfacesMCP sampling

Handle server requests for model sampling through the client.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP server instructions

Consume server-provided instructions during initialization.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP server role

Expose capabilities from the harness as an MCP server.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP stdio transport

Connect to a local MCP server over standard input and output.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor MCP documentation observed 2026-08-28
  • transport: Cursor launches the configured local command; executable availability, environment, workspace trust, and enterprise policy can prevent connection
Evidence and notes →
InterfacesMCP Streamable HTTP

Connect to an MCP server over the current Streamable HTTP transport.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor MCP documentation observed 2026-08-28
  • transport: the configured HTTP endpoint must be reachable and may be restricted by authentication, enterprise MCP policy, and URL/network allowlists
Evidence and notes →
InterfacesMCP task listing

List and page through tasks exposed by the task utility.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP tasks

Create, inspect, and manage long-running MCP tasks.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesMCP tools

Invoke operations exposed by a Model Context Protocol server.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor documentationNo additional condition recorded.Evidence and notes →
Models and contextModel fallback

Switch to another model after a documented failure condition.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Models and contextModel selection

Choose the model or documented model class used for a run.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor model-selection documentation
  • plan: selectable model inventory, pricing, and Max Mode availability depend on the current Cursor plan and provider availability
Evidence and notes →
ToolsMulti-file edit

Edit multiple files during one task.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor Agent mode documentation
  • host role: claim is scoped to Cursor Agent in the desktop workbench
Evidence and notes →
InterfacesNative plugin system

Install and load a product-specific extension package.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesNested AGENTS.md instructions

Apply nested AGENTS.md files with directory-sensitive precedence.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor Rules documentation
  • host role: claim is scoped to Cursor Agent in the desktop workbench
Evidence and notes →
RuntimeNested subagents

Allow a child agent to delegate further work to another child agent.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Security and privacyOffline operation

Run a documented workflow without a required network connection.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Security and privacyOrganization policy controls

Centrally configure and enforce product settings for an organization.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Models and contextOutput token limit

Record the maximum generated response budget by exact model and harness mode.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Files and mediaPDF input

Upload a PDF for use as model input.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimePer-subagent model selection

Choose or constrain each child agent's model independently of the parent.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor subagent documentation
  • plan: team policy, plan eligibility, or legacy Max Mode requirements may override an explicit child model
Evidence and notes →
Pricing, usage, and limitsPlans and pricing

Compare documented plan, seat, included-usage, credit, and overage pricing by exact product.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Cursor pricing observation
  • plan: Hobby is free; Individual Pro is $20 monthly with Pro+ and Ultra usage tiers; Teams Standard is $40 per user monthly with a Premium tier; Enterprise is custom
  • policy: every plan includes model usage; optional on-demand use is billed in arrears, taxes are excluded, and invoice or wire payment requires Enterprise
Evidence and notes →
InterfacesPlugin marketplace

Discover and install extensions through a documented registry or marketplace.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesPlugin vendor extensions

Preserve namespaced host-specific behavior without representing it as portable core support.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesProject rules

Load persistent or path-scoped instructions from a documented product rule format.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor Rules documentation
  • host role: claim is scoped to Cursor Agent in the desktop workbench
Evidence and notes →
RuntimeProject-scoped Agent Skills

Discover skills installed for a repository or workspace.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor Agent Skills documentationNo additional condition recorded.Evidence and notes →
Models and contextPrompt cache controls

Mark, retain, refresh, or invalidate cached prompt context.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Models and contextPrompt cache telemetry

Inspect cache hits, misses, token counts, latency, or billing effects.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Models and contextPrompt caching

Reuse eligible repeated prompt content under documented caching behavior.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
ToolsPull request integration

Open or review pull requests through a documented integration.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor Cloud Agent documentation
  • auth: Cloud Agent pull requests require an authorized repository and run on Cursor's hosted VM environment
Evidence and notes →
Pricing, usage, and limitsRate limits and quotas

Record documented product usage limits and reset periods.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Cursor documentation observation
  • plan: usage is split into two monthly pools; remaining allowance, on-demand charges, and reset date are visible in the Spending dashboard
  • runtime: unused usage does not roll over; at the boundary the editor offers on-demand usage or a plan upgrade
  • policy: numeric included allowances and the complete request, token, upload, tool, and agent-concurrency envelope are not established by the reviewed page
Evidence and notes →
Files and mediaRealtime voice

Speak and listen over a live audio session.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Models and contextReasoning effort controls

Choose a documented reasoning depth, effort, or budget for a run.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
CollaborationRole-based access control (RBAC)

Assign and enforce permissions through documented roles.

YSupported?Unknown2 public referencesLatest evidence 2026-08-28hosted observation · 2026-08-28 Cursor RBAC documentation observation
  • policy: team Member, Admin, and Unpaid Admin roles separate product use from team and security administration
  • plan: Enterprise organization groups can map directory or manually managed cohorts to teams with Member or Admin roles and attach model and agent controls
  • runtime: roles are built in rather than arbitrary custom permission bundles, and group settings commonly use a most-permissive merge
Evidence and notes →
RuntimeSandbox network access

Allow, deny, or restrict outbound network access from a tool sandbox.

PPartial?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor Cloud Agent security documentation
  • runtime: applies to isolated Cloud Agent VMs; first-party documentation states that environments have operator-controlled network access and network policies without documenting the full rule model on the reviewed page
Evidence and notes →
RuntimeScheduled runs

Start a task on a schedule without a new human prompt.

YSupported?Unknown2 public referencesLatest evidence 2026-08-28hosted observation · 2026-08-28 Cursor Cloud Agent documentation observation
  • runtime: Automations create billable Cloud Agents; repository access and optional tools must be configured for each automation
  • runtime: conversation timer subscriptions last at most 180 days
Evidence and notes →
Files and mediaScreenshots

Capture a screen, window, or browser page for use as model input.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
Security and privacySecrets management

Store and provide credentials through a documented secrets feature.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Cursor Background Agent secrets documentation observation
  • runtime: development-environment secrets are stored encrypted at rest using KMS and injected into the remote Background Agent environment
  • policy: per-tool access controls, log masking, rotation, and prevention of model or shell access to injected values are not established by the reviewed page
Evidence and notes →
Pricing, usage, and limitsSession resume

Continue a previously saved product session.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor Agent CLI usage documentation
  • runtime: Agent CLI can resume the most recent chat or a selected thread; cloud-agent persistence and retention are separate hosted behaviors
Evidence and notes →
CollaborationShared projects

Share a product-defined project workspace with other people.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesStreaming output

Show text or tool events as they arrive during a run.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesStructured outputs

Return JSON or schema-constrained output through a documented product feature.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor Agent CLI output-format documentation
  • runtime: JSON and stream-json formats apply to Agent CLI print mode; this evidence does not establish caller-supplied JSON Schema conformance
Evidence and notes →
RuntimeSubagent context

Define which conversation, instructions, files, memory, and tools a child receives.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor subagent documentation
  • runtime: clean child context receives a parent-composed task prompt; project files share the checkout by default but can be isolated in a worktree, branch, or cloud VM
Evidence and notes →
RuntimeSubagent delegation

Delegate a bounded task to another agent process.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor subagent documentation
  • runtime: applies to Cursor editor, CLI, and Cloud Agents; named subagents can be invoked with /name or natural language
Evidence and notes →
RuntimeSubagent management

List, inspect, and control child-agent tasks.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimeSubagent MCP access

Allow a child agent to use MCP tools or declare its own MCP servers.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimeSubagent permissions

Control child-agent tools, inherited permissions, and approval behavior.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
RuntimeSubagent results

Return a child agent's findings or work to the parent.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor subagent documentation
  • runtime: a final message and child branch changes remain available, but no typed artifact, citation, status, or error schema is documented
Evidence and notes →
RuntimeSubagent write access

Allow a child agent to create or modify project files.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
ToolsTerminal commands

Propose or execute shell commands in a project environment.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor documentationNo additional condition recorded.Evidence and notes →
Security and privacyTraining data controls

Control or document model-training and service-improvement use of product content.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Cursor privacy documentation observation
  • policy: Privacy Mode prevents Customer Data from training Cursor models and uses ZDR agreements with model providers; non-ZDR models require designation or administrator opt-in
  • policy: safety classifiers and triggered abuse investigations are exceptions; turning Privacy Mode off permits broader storage, improvement, and model-training use
Evidence and notes →
Pricing, usage, and limitsUsage metering

Inspect documented product usage such as requests, tokens, or cost.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28hosted observation · 2026-08-28 Cursor documentation observation
  • runtime: Spending dashboard shows real-time use, remaining allowance, on-demand charges, reset date, and request-level cost and pool details
  • plan: Cursor Models and third-party Other Models draw from separate monthly pools; Auto requests are charged at the routed model's list price
  • policy: portable telemetry export and separate tool, compute, storage, and subagent consumption are not established by the reviewed page
Evidence and notes →
RuntimeUser-scoped Agent Skills

Discover personal or global skills outside the current project.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor Agent Skills documentation
  • runtime: local user-scope folders are read from the machine where Cursor Agent runs and are not copied to Cloud Agents, remote SSH sessions, or managed workers
Evidence and notes →
Files and mediaVideo input

Upload or select a video for use as model input.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
ToolsWeb fetch

Retrieve live web pages or APIs during a run.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesWebMCP declarative form tools

Expose semantic HTML forms as structured tools through WebMCP annotations.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesWebMCP execution cancellation

Cancel pending tool registration or execution through abort signals and lifecycle rules.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesWebMCP imperative tools

Register JavaScript-backed tools through document.modelContext.registerTool().

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesWebMCP permissions policy

Gate tool exposure across documents and origins through the tools permissions policy.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesWebMCP security annotations

Communicate read-only and untrusted-content hints across the site-to-agent boundary.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesWebMCP tool discovery

Expose the active page tool list and schemas to a WebMCP-aware agent.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
InterfacesWebMCP tool execution

Invoke a page tool with structured arguments and return its result to the agent.

?Unknown?UnknownNo reviewed current evidenceThis remains unknown; it is not an unsupported claim.Open capability record →
ToolsWorkspace files

Read or edit files inside a user-selected project.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor documentationNo additional condition recorded.Evidence and notes →
ToolsWorkspace search

Search file names, text, or symbols across a workspace.

YSupported?Unknown1 public referenceLatest evidence 2026-08-28dated documentation · current Cursor Agent tools documentation
  • host role: claim is scoped to Cursor Agent in the desktop workbench
Evidence and notes →