cursor-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| CURSOR_SANDBOX | No | enabled or disabled, passed as --sandbox <mode>: the sandbox confines what an auto-approved agent may run; any other value ends the server at startup | |
| CURSOR_ALLOW_YOLO | No | true runs cursor_agent and cursor_reply with --force (auto-approve every tool call). Without it cursor-agent in headless mode only proposes file changes and applies none (Cursor's headless docs). DANGEROUS — only for trusted environments, best with CURSOR_SANDBOX=enabled | false |
| CURSOR_KILL_GRACE_MS | No | After SIGTERM (timeout or cancellation), a child still alive this long is sent SIGKILL — an integer of milliseconds from 1 to 2147483647 (what a timer can wait); anything else is the default | 5000 |
| CURSOR_MAX_CONCURRENCY | No | Maximum concurrent cursor-agent processes — an integer from 1 to 64; anything else is the default | 3 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| cursor_agentA | Execute a prompt using Cursor's AI agent with any model id the installed cursor-agent accepts (Composer, Claude, GPT, Gemini, Grok families on your plan; run cursor_models for ids). Modes: 'agent' (tools, terminal, search), 'plan' (design-focused), 'ask' (read-only). In headless mode cursor-agent only PROPOSES file changes unless the server operator set CURSOR_ALLOW_YOLO=true (then --force applies them; CURSOR_SANDBOX=enabled confines them). The result lists the files changed and the model used; a client that sends a progress token gets a progress notification per tool call. |
| cursor_replyA | Continue an existing Cursor agent session. Send a follow-up message in the same conversation context. Requires a session_id from a previous cursor_agent call. |
| cursor_modelsA | List the model ids the installed cursor-agent offers (its |
| cursor_sessionsA | List Cursor agent sessions created during this MCP server instance. Shows session IDs, models, and prompts. Use session IDs with cursor_reply to continue a conversation. |
| cursor_healthA | Check Cursor CLI installation, authentication, and server configuration. Run this first to verify everything is set up correctly. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 5 tools
Each tool targets a distinct operation: starting an agent session, continuing it, listing models, listing sessions, and checking health. The session_id requirement in cursor_reply clearly separates it from cursor_agent, leaving no ambiguity.
All tools share the consistent `cursor_` prefix and snake_case, but suffixes mix nouns (agent, models, sessions, health) with a verb-like action (reply). This minor deviation is still readable and predictable.
Five tools is well-scoped for a Cursor agent wrapper, covering execution, continuation, discovery, and diagnostics without redundancy. Each tool clearly earns its place.
Core workflows for interacting with the Cursor agent are covered: starting, continuing, listing models/sessions, and health checks. Minor gaps like session cancellation or status inspection exist but are not essential for typical use.