← All agents

Cursor

noneide-extension

Runs commands with full privileges plus a best-effort sandbox the vendor explicitly calls 'not a security boundary'.

Cursor runs commands directly in your terminal with full privileges, layering a best-effort OS sandbox (Seatbelt on macOS, Landlock+seccomp on Linux, WSL2 on Windows) that blocks out-of-workspace writes and network by default, while explicitly stating it is 'not a security boundary' (commands needing full access escape with a prompt). Its strong isolation is the separate Background/Cloud Agents product: isolated Ubuntu VMs on AWS, one branch each, HSM-signed commits; the specific / tech is not disclosed, so any Firecracker/gVisor claim is inference.

Isolation tech (linux)

Isolation tech (macos)

Sources