Cursor

Cursor: allow all terminal commands (Run Everything, allowlist, sandbox)

How do I let Cursor's agent run commands without asking?

Open Settings > Agents > Approvals & Execution and pick a Run Mode. Run Everything runs every tool call automatically with no sandbox or review; Allowlist runs only the commands you list; Auto-review runs allowlisted calls immediately and sends other shell commands to the sandbox when possible.

The three run modes

  • Auto-review: allowlisted calls run immediately; other shell commands run in the sandbox when possible.
  • Allowlist: actions in your allowlist run without approval; with sandboxing enabled, supported shell commands can run in the sandbox.
  • Run Everything: every tool call runs automatically, with no sandbox or classifier review.

Steer Auto-review with permissions.json

Auto-review reads plain-English instructions from ~/.cursor/permissions.json (global) or .cursor/permissions.json in the project, under allow_instructions and block_instructions.

.cursor/permissions.json

{
  "allow_instructions": ["Running the test suite and the linter is always fine."],
  "block_instructions": ["Every AWS CLI command should go through approval first."]
}

Before you pick Run Everything

Run Everything removes the sandbox, so the agent can reach the network and anything your user account can. Prefer Allowlist or Auto-review on your own machine, and keep Run Everything for disposable environments.

Sources

More on Cursor

Other guides

Get the weekly agent stack update

New official MCP servers, spec changes and harness releases, checked against the source. One email a week, no fluff.

Reviewed Oct 6, 2026. Settings change often; the linked vendor docs are the source of truth.