Cursor ↗
Cursor is an officially published AI tool from Anysphere. Anomity scores its risk at 10 out of 100 (low).
Analysis summary
Cursor is an officially published AI tool from Anysphere. Anomity scores its risk at 10 out of 100 (low).
AI-native code editor with built-in agent and MCP support
Why this entry scored 10 out of 100
This profile starts at the catalog's neutral base of 50. Because the entry is officially published, trust adjusts the score by -40. The entry declares no high-risk capabilities on its own, so capabilities add nothing. It matches no dangerous capability combinations. The clamped result is 10, placing it in the low band.
Findings
-
Published by the vendor Trust offset
Configuration surface
Files this AI tool reads on the host. Anything written here changes what the agent does next.
-
cursor-global-mcpglobal jsonGlobal MCP server configuration- win32
${USERPROFILE}\.cursor\mcp.json - darwin
${HOME}/.cursor/mcp.json - linux
${HOME}/.cursor/mcp.json
- win32
-
cursor-user-settingsglobal jsoncUser settings- win32
${APPDATA}\Cursor\User\settings.json - darwin
${HOME}/Library/Application Support/Cursor/User/settings.json - linux
${HOME}/.config/Cursor/User/settings.json
- win32
-
cursor-project-mcpproject jsonProject-level MCP servers- win32
${PROJECT}\.cursor\mcp.json - darwin
${PROJECT}/.cursor/mcp.json - linux
${PROJECT}/.cursor/mcp.json
- win32
-
cursor-extension-manifestglobal jsonInstalled Cursor extension manifests -
cursor-user-hooksglobal jsonUser-level hook configuration (sessionStart, beforeShellExecution, etc.)- win32
${USERPROFILE}\.cursor\hooks.json - darwin
${HOME}/.cursor/hooks.json - linux
${HOME}/.cursor/hooks.json
- win32
-
cursor-project-hooksproject jsonProject-level hook configuration- win32
${PROJECT}\.cursor\hooks.json - darwin
${PROJECT}/.cursor/hooks.json - linux
${PROJECT}/.cursor/hooks.json
- win32
-
cursor-enterprise-hooksglobal jsonEnterprise-managed hooks (system-wide policy)- win32
C:\ProgramData\Cursor\hooks.json - darwin
/Library/Application Support/Cursor/hooks.json - linux
/etc/cursor/hooks.json
- win32
-
cursor-project-rulesproject markdown-frontmatterProject rules (.cursor/rules/*.mdc — Markdown + frontmatter) -
cursor-project-rules-legacyproject markdownLegacy single-file project rules (.cursorrules)- win32
${PROJECT}\.cursorrules - darwin
${PROJECT}/.cursorrules - linux
${PROJECT}/.cursorrules
- win32
-
cursor-project-skillsproject markdown-frontmatterProject skills (.cursor/skills) -
cursor-project-skills-agentsproject markdown-frontmatterProject skills (cross-tool .agents/skills convention) -
cursor-first-party-skillsglobal markdown-frontmatterCursor first-party skills (Cursor-synced) -
cursor-skill-sync-manifestglobal jsonCursor skill-sync manifest (presence)- win32
${USERPROFILE}\.cursor\skills-cursor\.sync-manifest.json - darwin
${HOME}/.cursor/skills-cursor/.sync-manifest.json - linux
${HOME}/.cursor/skills-cursor/.sync-manifest.json
- win32
-
cursor-plugin-skillsglobal markdown-frontmatterCursor plugin skills (marketplace-delivered, third-party) -
cursor-plugin-marketplaceglobal jsonCursor plugin marketplace catalogs -
cursor-user-skillsglobal markdown-frontmatterUser-scope Cursor skills -
cursor-project-subagentsproject markdown-frontmatterProject custom subagents (.cursor/agents/*.md — own tool allowlist) -
cursor-user-subagentsglobal markdown-frontmatterUser-scope custom subagents (~/.cursor/agents/*.md) -
cursor-cli-permissions-projectproject jsonCursor CLI project permissions (allow/deny)- win32
${PROJECT}\.cursor\cli.json - darwin
${PROJECT}/.cursor/cli.json - linux
${PROJECT}/.cursor/cli.json
- win32
-
cursor-cli-permissions-globalglobal jsonCursor CLI global permissions (allow/deny)- win32
${USERPROFILE}\.cursor\cli-config.json - darwin
${HOME}/.cursor/cli-config.json - linux
${HOME}/.cursor/cli-config.json
- win32