Cursor
Keep files out of Cursor with .cursorignore
How do I stop Cursor from reading certain files?
Create a .cursorignore file in your project root using .gitignore syntax, and Cursor will block matching files from Agent, Tab, Inline Edit, and @ mentions. Cursor also respects .gitignore, a built-in default ignore list, and optional global patterns in user settings. It is not a security boundary: terminal commands and MCP tools run by Agent can still read ignored files.
What .cursorignore does
Files listed in .cursorignore are blocked from code accessible by Agent, Tab, and Inline Edit, and from @ mention references. They are also blocked from codebase search. Use it to keep secrets out of AI context, or to exclude irrelevant parts of a large codebase or monorepo for more accurate file discovery.
- Cursor automatically respects .gitignore, so files ignored by git are also excluded. Use .cursorignore for extra exclusions beyond .gitignore.
- Cursor also has a default ignore list that includes .env*, .git/, lock files such as package-lock.json and yarn.lock, node_modules/, and many binary, media, and archive extensions.
- You can override a default with a ! prefix in .cursorignore.
Syntax
The file uses .gitignore syntax: * matches any characters except /, ** matches any characters including /, ? matches a single character, ! un-ignores a previously ignored path, lines starting with # are comments, and trailing spaces are ignored unless escaped with a backslash.
.cursorignore
# Specific file config.json # Directory dist/ # File extension *.log # Nested directories **/logs # Environment files .env*
You cannot re-include a file if its parent directory is excluded, because excluded directories are not traversed. Exclude the nested directory's contents explicitly instead.
Negation workaround
public/assets/* !public/assets/style.css
Test a pattern with git check-ignore -v followed by the file path.
What it does not protect
- The terminal and MCP server tools used by Agent cannot block access to files governed by .cursorignore.
- Cursor says complete protection is not guaranteed due to LLM unpredictability.
- Cursor's enterprise docs state that .cursorignore is not a security boundary: users can manually read ignored files, and agents might find ways to access ignored content.
- For real security, Cursor recommends file system permissions or encrypting sensitive data, and pairing .cursorignore with approvals.
Global and hierarchical ignore settings
Set ignore patterns for all projects in your user settings. The global ignore list is empty by default. Suggested patterns include **/.env, **/.env.*, **/credentials.json, **/secrets.json, **/*.key, **/*.pem, and **/id_rsa.
To have Cursor look in parent directories for .cursorignore files, enable Cursor Settings > Indexing > Ignore Files > Hierarchical Cursor Ignore.
Sources
More on Cursor
Other guides
Get the weekly agent stack update
New official MCP servers, spec changes and harness releases, checked against the source. One email a week, no fluff.
Reviewed Oct 6, 2026. Settings change often; the linked vendor docs are the source of truth.