Cursor

Cursor sandbox: sandbox.json, network allowlist and run modes

How does Cursor's agent terminal sandbox work and how do I configure it?

On macOS and Linux, Cursor can run agent terminal commands in a sandbox that limits writes to the workspace and blocks network access you have not allowed. Whether a command enters the sandbox depends on your run mode in Settings > Agents > Approvals & Execution. You tune the sandbox with sandbox.json in ~/.cursor/ or <project>/.cursor/, including a networkPolicy allow and deny list.

What the sandbox restricts

  • Commands can read and write inside the workspace.
  • /tmp and platform temp directories are writable unless you set disableTmpWrite.
  • Network access is limited by the network mode and your sandbox.json allowlist.
  • Some paths are always write protected, including .cursor/*.json, .vscode/**, .git/hooks/**, .git/config and .cursorignore.
  • Private IPv4 and IPv6 ranges, loopback and the cloud metadata endpoint are blocked by default.

Reads: with readBoundary "system" (the default) the agent can read outside the workspace. With "workspace" (Cursor 3.23 or later) Cursor asks first, except for paths in the Read Allowlist.

Supported platforms

  • macOS: Seatbelt through sandbox-exec. Cursor 2.0 or later, no extra setup.
  • Linux: creates a user namespace and remaps the process to UID 0. Uses Landlock, with a Bubblewrap fallback.

Inside the sandbox Cursor sets CURSOR_SANDBOX ("seatbelt" on macOS, "native" on Linux), plus CURSOR_ORIG_UID and CURSOR_ORIG_GID. On Linux, id -u returns 0, so scripts that need your real ID should read CURSOR_ORIG_UID.

How it fits with run modes

Set the run mode in Settings > Agents > Approvals & Execution. Sandboxing is a layer on top of run modes for shell commands.

  • Auto-review: allowlisted calls run immediately. Other shell commands go to the sandbox when possible. Calls outside the sandbox go to the classifier.
  • Allowlist: allowlisted actions run without approval. With sandboxing enabled, supported shell commands can run in the sandbox.
  • Run Everything: every tool call runs automatically, with no sandbox and no classifier.

If a sandboxed command fails on a sandbox restriction, the agent can rerun it outside the sandbox, and the classifier reviews that rerun.

Network modes and the allowlist

  • sandbox.json + Defaults (default): your allowlist plus Cursor's built-in defaults for package managers and language tools.
  • sandbox.json Only: only domains in your sandbox.json allowlist.
  • Allow All: all network access is allowed, regardless of sandbox.json.

.cursor/sandbox.json

{
  "networkPolicy": {
    "default": "deny",
    "allow": [
      "registry.npmjs.org",
      "pypi.org",
      "*.githubusercontent.com"
    ],
    "deny": ["*.internal.corp.example.com"]
  }
}

Patterns can be exact domains, wildcards like *.example.com (which also match the bare domain) or CIDR ranges. Deny always beats allow. URL paths are ignored.

sandbox.json keys

  • type: "workspace_readwrite" (default), "workspace_readonly" or "insecure_none" (sandbox disabled).
  • additionalReadwritePaths: extra read and write paths (only with workspace_readwrite).
  • additionalReadonlyPaths: extra read-only paths.
  • readBoundary: "system" (default) or "workspace".
  • additionalReadPaths: Read Allowlist paths and globs, used when readBoundary is "workspace".
  • disableTmpWrite: true removes write access to /tmp and temp directories.
  • enableSharedBuildCache: true shares npm, cargo and pip caches between sandboxed and unsandboxed commands.
  • networkPolicy: default ("allow" or "deny", default "deny"), allow, deny.

~/.cursor/sandbox.json applies to all projects. <project>/.cursor/sandbox.json applies to one project and wins when both exist. Path lists and deny lists are combined. Team admin policies and Cursor's hardcoded rules apply on top and cannot be weakened by local files.

Sources

More on Cursor

Other guides

Cursor: allow all terminal commandsClaude Code: allow commands without promptsCodex CLI: approval and sandbox modesGemini CLI: YOLO mode, auto_edit and allowing specific shell commandsCursor Privacy Mode: telemetry, training and data retentionClaude Code telemetry and data retention: what is sent and how to turn it offGemini CLI: turn off usage statistics and telemetryCLAUDE.md: where it goes, how it loads, and how it works with AGENTS.mdClaude Code hooks: format on save, block risky edits, get notifiedClaude Code subagents: create one, limit its tools, and call itAdd MCP servers to Cursor with mcp.json: Keep files out of Cursor with .cursorignore: Configure Codex with config.toml: Configure Gemini CLI with settings.json: Add MCP servers to Claude Code (claude mcp add, .mcp.json, scopes): Claude Code custom slash commands and skills (SKILL.md): GitHub Copilot custom instructions: Adding MCP servers to GitHub Copilot: Claude Code settings.json: file locations, precedence, and key settingsClaude Code plugins and marketplaces: install, create, and shareGemini CLI extensions and custom commands: Configuring OpenCode with opencode.json: Cline Rules: workspace, global, and conditional rulesKiro steering files: .kiro/steering, inclusion modes, and AGENTS.mdZed agent: instruction files, MCP servers, tool permissions, and ACP agentsCursor CLI: install, headless mode, permissions and CIAider: CONVENTIONS.md, .aider.conf.yml and API keysJunie guidelines, MCP and the Action Allowlist: Amp AGENTS.md, settings.json and MCP: Configure Goose extensions, hints, recipes and permissions: Customize OpenHands with skills, AGENTS.md, setup.sh and MCP: Configure Factory Droid CLI: AGENTS.md, settings.json, autonomy, custom droids and MCPConfigure Qwen Code: settings.json, providers, QWEN.md, MCP and approval modesCursor hooks: hooks.json, beforeShellExecution, afterFileEdit and exit codesCursor settings: settings.json, Cursor Settings and the ~/.cursor config filesCursor browser agent: @browser, browser automation and approval modesCursor subagents: .cursor/agents, frontmatter, built-in Explore, Bash and BrowserCursor telemetry and OpenTelemetry export (Privacy Mode, OTLP, Analytics API): Cursor rules setup: .cursor/rules, .mdc frontmatter, globs, alwaysApply and AGENTS.md

Get the weekly agent stack update

New official MCP servers, spec changes and harness releases, checked against the source. One email a week, no fluff.

Reviewed Oct 9, 2026. Settings change often; the linked vendor docs are the source of truth.