Repository / project instructions
Documented.cursor/rules can supply version-controlled project instructions.
View source detailAgent intelligence
Official Cursor evidence covers rules, memories, tools, model choice, permissions, Origin, Cloud Agent subscriptions, Custom Modes, and self-hosted Cloud Agent execution without establishing a published full system prompt.
Cursor is documented as an AI code editor and agent platform with project rules, user guidance, repository memories, tools, selectable models, permissions, Cloud Agent subscriptions, Custom Modes, an early-beta git forge called Origin, and self-hosted Cloud Agent execution. The September 2, 2026 changelog keeps tool execution on self-hosted infrastructure and documents worker pools plus Linux/Mac computer use with the required desktop packages. These product capabilities do not establish a complete current base system prompt.
Scope: Cursor editor · Cursor CLI · Cursor Cloud Agents · Cursor Origin · Selectable provider models · reviewed Sep 05, 2026
Reviewed product surfaces
Each layer links to the detailed evidence map. Its state applies only to the reviewed evidence.
Source-backed answers
Each answer is scoped to the selected evidence. “Not established” means the evidence does not support the claim; it does not assert absence.
.cursor/rules can supply version-controlled project instructions.
View source detailUser-level rules provide preferences across projects.
View source detailApproved memories preserve repository-scoped learnings as rules.
View source detailSearch, read, edit, delete, terminal, and MCP tools are documented.
View source detailAllow and deny controls can constrain shell, read, and write operations.
View source detailA selected skill can remain in context across turns in the Agents Window and CLI.
View source detailThe selected official sources do not publish a complete current Cursor base system prompt.
Review evidence scopeEditorial guidance
These conservative editorial implications come from the linked evidence. They add no vendor claims or generic prompt advice.
.cursor/rules is the documented project scope, while user rules provide preferences across projects.
Supporting evidenceMemories preserve repository-scoped learnings as generated rules rather than establishing the hidden base prompt.
Supporting evidenceGlobal and project allow/deny controls can constrain shell, read, and write operations even when the agent has corresponding tools.
Supporting evidenceCustom Modes keep the selected skill in context in the Agents Window and CLI until the mode is exited.
Supporting evidenceThe self-hosted machines entry keeps tool execution on your infrastructure, documents named worker pools, and scopes Linux/Mac computer use to workers with the required desktop packages.
Supporting evidenceUseful next actions
Product scope
Evidence status
Official Cursor documentation and the September 2, 2026 changelog cover rules, memory, tools, models, permissions, Origin, Cloud Agent subscriptions, Custom Modes, and self-hosted execution. The review does not claim a complete current base system prompt.
Detailed instruction layers
The map separates the unestablished base prompt from product surfaces, project and user rules, memories, tools, models, permissions, subscriptions, and Custom Modes.
The selected official sources do not publish a complete current Cursor base system prompt.
Source detail.cursor/rules can supply version-controlled project instructions.
Source detailApproved memories preserve repository-scoped learnings as rules.
Source detailSearch, read, edit, delete, terminal, and MCP tools are documented.
Source detailAllow and deny controls can constrain shell, read, and write operations.
Source detailA selected skill can remain in context across turns in the Agents Window and CLI.
Source detailSupporting instruction evidence
Official sources document the product but do not support a standalone public system-prompt page.
Evidence-backed capabilities
Each capability links to its supporting prompt section or first-party source and keeps its stated confidence level.
| Capability | What the source establishes | Confidence | Evidence |
|---|---|---|---|
| Plan Mode | The editor agent researches the codebase, asks clarifying questions, and creates a reviewable plan before building. Plans can be edited and saved to the workspace. This describes a workflow, not a universal permission or isolation guarantee. | high | Primary source |
| Web search | The editor Agent Web tool generates queries and performs web searches. This does not establish unrestricted network access, page retrieval fidelity, or identical CLI and Cloud Agent behavior. | high | Primary source |
| Agentic codebase work | Cursor's agent is documented as searching, understanding, and changing codebases. | high | Primary source |
| Project and user rules | Project rules and user rules supply persistent model context at different scopes. | high | Primary source |
| Repository memories | Approved memories preserve repository-scoped learnings as generated rules. | high | Primary source |
| Agent tools | Search, read, edit, delete, terminal, and MCP tools are documented. | high | Primary source |
| CLI permission controls | Global and project configuration can allow or deny shell, read, and write operations. | high | Primary source |
| Selectable models | Cursor supports models from multiple providers and an automatic selection mode. | high | Primary source |
| Origin git forge | Origin is documented as an early-beta git forge with repositories, pull requests, search, and agent-connected workflows. | high | Primary source |
| Cloud Agent subscriptions | A Cloud Agent can resume the same conversation when configured GitHub, Slack, Linear, or timer events occur. | high | Primary source |
| Custom Modes | A selected skill can stay in context across turns in the Agents Window and CLI. | high | Primary source |
| Self-hosted Cloud Agent execution | Cursor's September 2, 2026 changelog documents Cloud Agent tool execution on self-hosted machines, with codebase, build outputs, and secrets kept on internal infrastructure, plus My Machines, team pools, and Linux/Mac computer use with the required desktop packages. | high | Primary source |
Version evidence
The selected evidence establishes no compatible first-party full-prompt snapshots. Documentation updates are not treated as prompt versions.
Provenance
Every source lists its origin, retrieval date, completeness, publication limits, and rights separately.
The editor agent researches the codebase, asks clarifying questions, and creates a reviewable plan before building. Plans can be edited and saved to the workspace. This describes a workflow, not a universal permission or isolation guarantee.
Open primary sourceThe editor Agent Web tool generates queries and performs web searches. This does not establish unrestricted network access, page retrieval fidelity, or identical CLI and Cloud Agent behavior.
Open primary sourceEstablishes the coding-product and agent context, not a complete runtime prompt.
Open primary sourceDocuments rule inputs rather than the complete instruction assembly.
Open primary sourceTool availability and automatic execution can vary with configuration.
Open primary sourceModel availability can change and does not define one universal Cursor runtime.
Open primary sourceDocuments saved memory behavior, not every context input.
Open primary sourceDocuments CLI permission configuration; editor and deployment controls can differ.
Open primary sourceDocuments an early-beta git forge and staged availability; it does not establish the full Cursor instruction stack.
Open primary sourceDocuments subscription triggers and limits for Cloud Agents; supported integrations and limits can change.
Open primary sourceDocuments Custom Modes as persistent skill context in supported agent surfaces, not a complete base prompt.
Open primary sourceRecords the August 2026 release state, including the current Cloud Agent-only subscription limitation.
Open primary sourceDocuments self-hosted Cloud Agent execution, dynamic worker pools, sandbox infrastructure, and Linux/Mac computer use as described in the entry; it does not establish all deployment requirements, availability, or Cursor's full instruction stack.
Open primary source