Cursor
Cursor: allow all terminal commands (Run Everything, allowlist, sandbox)
How do I let Cursor's agent run commands without asking?
Open Settings > Agents > Approvals & Execution and pick a Run Mode. Run Everything runs every tool call automatically with no sandbox or review; Allowlist runs only the commands you list; Auto-review runs allowlisted calls immediately and sends other shell commands to the sandbox when possible.
The three run modes
- Auto-review: allowlisted calls run immediately; other shell commands run in the sandbox when possible.
- Allowlist: actions in your allowlist run without approval; with sandboxing enabled, supported shell commands can run in the sandbox.
- Run Everything: every tool call runs automatically, with no sandbox or classifier review.
Steer Auto-review with permissions.json
Auto-review reads plain-English instructions from ~/.cursor/permissions.json (global) or .cursor/permissions.json in the project, under allow_instructions and block_instructions.
.cursor/permissions.json
{
"allow_instructions": ["Running the test suite and the linter is always fine."],
"block_instructions": ["Every AWS CLI command should go through approval first."]
}Before you pick Run Everything
Run Everything removes the sandbox, so the agent can reach the network and anything your user account can. Prefer Allowlist or Auto-review on your own machine, and keep Run Everything for disposable environments.
Sources
More on Cursor
Other guides
Get the weekly agent stack update
New official MCP servers, spec changes and harness releases, checked against the source. One email a week, no fluff.
Reviewed Oct 6, 2026. Settings change often; the linked vendor docs are the source of truth.