Cursor talks to several model providers and to local MCP servers over stdio; a network proxy sees encrypted traffic at best and local tool calls not at all. AccuroAI’s endpoint coverage inspects the context Cursor assembles and the actions its agent takes on the machine itself — 40+ classifiers and 60+ secret types at under 38 ms p99 — so developers notice nothing and the raw values never leave.
Commands Cursor’s agent proposes are classified before execution. Reads and builds flow; deletes, force-pushes, credential use and outbound requests to unreviewed domains wait for a human, with the decision logged. Auto-run settings do not bypass the gate, because it sits below the editor.
Servers declared in .cursor/mcp.json are discovered per device, matched against the catalog, and allowlisted or quarantined; manifests are pinned so a changed tool description re-triggers review. Rules files and fetched content are scanned for hidden instructions, and tool calls are evaluated at argument level.
Privacy Mode governs what Cursor and its providers retain after your code arrives. AccuroAI governs what arrives — secrets and protected source are redacted on the device first — and it covers the agent’s actions and MCP calls, which retention settings do not touch.
Inspection runs under 38 ms at p99, below the threshold developers perceive next to model latency. Policies default to redact rather than block, so work continues.
Yes. Policies are per group and per repository path — protected source trees can be excluded from context entirely while the rest of the codebase stays available.
Background agents run with repository and GitHub access and are governed through the same agent-action and MCP controls. The same policy engine covers Claude Code, GitHub Copilot, Windsurf and the other assistants your engineers use.