Agent intelligence

Cursor

Official Cursor evidence covers rules, memories, tools, model choice, permissions, Origin, Cloud Agent subscriptions, Custom Modes, and self-hosted Cloud Agent execution without establishing a published full system prompt.

Cursor is documented as an AI code editor and agent platform with project rules, user guidance, repository memories, tools, selectable models, permissions, Cloud Agent subscriptions, Custom Modes, an early-beta git forge called Origin, and self-hosted Cloud Agent execution. The September 2, 2026 changelog keeps tool execution on self-hosted infrastructure and documents worker pools plus Linux/Mac computer use with the required desktop packages. These product capabilities do not establish a complete current base system prompt.

Scope: Cursor editor · Cursor CLI · Cursor Cloud Agents · Cursor Origin · Selectable provider models · reviewed Sep 05, 2026

Reviewed product surfaces

Product Surface Schematic

Each layer links to the detailed evidence map. Its state applies only to the reviewed evidence.

Source-backed answers

Key behaviors

Each answer is scoped to the selected evidence. “Not established” means the evidence does not support the claim; it does not assert absence.

Repository / project instructions

Documented

.cursor/rules can supply version-controlled project instructions.

View source detail

Persistent user guidance

Documented

User-level rules provide preferences across projects.

View source detail

Memory / persistent guidance

Documented

Approved memories preserve repository-scoped learnings as rules.

View source detail

Filesystem, shell, and agent tools

Documented

Search, read, edit, delete, terminal, and MCP tools are documented.

View source detail

Approvals / permissions

Documented

Allow and deny controls can constrain shell, read, and write operations.

View source detail

Pinned skill guidance

Documented

A selected skill can remain in context across turns in the Agents Window and CLI.

View source detail

Base prompt visibility

Not established

The selected official sources do not publish a complete current Cursor base system prompt.

Review evidence scope

Editorial guidance

What this means in practice

These conservative editorial implications come from the linked evidence. They add no vendor claims or generic prompt advice.

Editorial implication

Use version-controlled project rules for repository guidance.

.cursor/rules is the documented project scope, while user rules provide preferences across projects.

Supporting evidence
Editorial implication

Treat repository memories as approved persistent guidance.

Memories preserve repository-scoped learnings as generated rules rather than establishing the hidden base prompt.

Supporting evidence
Editorial implication

Account for explicit CLI operation boundaries.

Global and project allow/deny controls can constrain shell, read, and write operations even when the agent has corresponding tools.

Supporting evidence
Editorial implication

Use Custom Modes for guidance that should persist across turns.

Custom Modes keep the selected skill in context in the Agents Window and CLI until the mode is exited.

Supporting evidence
Editorial implication

Match Cloud Agent execution to the infrastructure boundary you need.

The self-hosted machines entry keeps tool execution on your infrastructure, documents named worker pools, and scopes Linux/Mac computer use to workers with the required desktop packages.

Supporting evidence

Useful next actions

Continue your research

Product scope

Cursor is the coding product; its agent mode and selected provider model are separate context.

Organization
Cursor
Product
AI code editor, coding-agent platform, and early-beta git forge
Surface
Cursor editor · Cursor CLI · Cursor Cloud Agents · Cursor OriginThe code-editor surface for agentic codebase work.
Model context
Selectable provider modelsCursor documents model selection and Auto mode separately from the editor and agent harness.

Evidence status

Coverage and review

Official Cursor documentation and the September 2, 2026 changelog cover rules, memory, tools, models, permissions, Origin, Cloud Agent subscriptions, Custom Modes, and self-hosted execution. The review does not claim a complete current base system prompt.

Coverage
partial
Primary source
Tier A · vendor-published
Review freshness
currentOfficial Cursor documentation and the September 2, 2026 self-hosted machines changelog were reviewed for the editor agent, rules, tools, memories, model selection, CLI permissions, Origin, Cloud Agent subscriptions, Custom Modes, and self-hosted Cloud Agent execution. Targeted planning and web evidence was consulted on September 14, 2026; see the separately dated sources. Other evidence was not re-reviewed.
Reviewed
Sep 05, 2026

Detailed instruction layers

Instruction-system map

The map separates the unestablished base prompt from product surfaces, project and user rules, memories, tools, models, permissions, subscriptions, and Custom Modes.

Base system promptnot established

The selected official sources do not publish a complete current Cursor base system prompt.

Source detail
Project rulesdocumented

.cursor/rules can supply version-controlled project instructions.

Source detail
User rulesdocumented

User-level rules provide preferences across projects.

Source detail
Repository memoriesdocumented

Approved memories preserve repository-scoped learnings as rules.

Source detail
Agent toolsdocumented

Search, read, edit, delete, terminal, and MCP tools are documented.

Source detail
CLI permissionsdocumented

Allow and deny controls can constrain shell, read, and write operations.

Source detail
Custom Modesdocumented

A selected skill can remain in context across turns in the Agents Window and CLI.

Source detail

Supporting instruction evidence

Documentation and source coverage

Official sources document the product but do not support a standalone public system-prompt page.

Selected snapshot
Cursor instruction architecture · reviewed August 25, 2026
Evidence coverage
Through Aug 25, 2026Cursor instruction architecture · reviewed August 25, 2026
Latest known vendor version
Not established by selected evidence
Current product state
Not established by selected evidence
Publication
Full prompt unavailable
Instruction page
Not availableNo verified current full first-party Cursor prompt artifact was established in the selected official sources.

Evidence-backed capabilities

Capabilities with evidence

Each capability links to its supporting prompt section or first-party source and keeps its stated confidence level.

Cursor capability evidence
CapabilityWhat the source establishesConfidenceEvidence
Plan ModeThe editor agent researches the codebase, asks clarifying questions, and creates a reviewable plan before building. Plans can be edited and saved to the workspace. This describes a workflow, not a universal permission or isolation guarantee. high Primary source
Web searchThe editor Agent Web tool generates queries and performs web searches. This does not establish unrestricted network access, page retrieval fidelity, or identical CLI and Cloud Agent behavior. high Primary source
Agentic codebase workCursor's agent is documented as searching, understanding, and changing codebases. high Primary source
Project and user rulesProject rules and user rules supply persistent model context at different scopes. high Primary source
Repository memoriesApproved memories preserve repository-scoped learnings as generated rules. high Primary source
Agent toolsSearch, read, edit, delete, terminal, and MCP tools are documented. high Primary source
CLI permission controlsGlobal and project configuration can allow or deny shell, read, and write operations. high Primary source
Selectable modelsCursor supports models from multiple providers and an automatic selection mode. high Primary source
Origin git forgeOrigin is documented as an early-beta git forge with repositories, pull requests, search, and agent-connected workflows. high Primary source
Cloud Agent subscriptionsA Cloud Agent can resume the same conversation when configured GitHub, Slack, Linear, or timer events occur. high Primary source
Custom ModesA selected skill can stay in context across turns in the Agents Window and CLI. high Primary source
Self-hosted Cloud Agent executionCursor's September 2, 2026 changelog documents Cloud Agent tool execution on self-hosted machines, with codebase, build outputs, and secrets kept on internal infrastructure, plus My Machines, team pools, and Linux/Mac computer use with the required desktop packages. high Primary source

Version evidence

Snapshots and meaningful changes

The selected evidence establishes no compatible first-party full-prompt snapshots. Documentation updates are not treated as prompt versions.

  1. selected Cursor instruction architecture · reviewed August 25, 2026Reviewed Aug 25, 2026
    Documentation coverage

Provenance

Source ledger

Every source lists its origin, retrieval date, completeness, publication limits, and rights separately.

Tier A · vendor-published

Cursor Plan Mode

Publisher
Cursor
Retrieved
Sep 14, 2026
Upstream ref
Live official documentation consulted 2026-09-14
Rights posture
Original summary; no prompt text republished.

The editor agent researches the codebase, asks clarifying questions, and creates a reviewable plan before building. Plans can be edited and saved to the workspace. This describes a workflow, not a universal permission or isolation guarantee.

Open primary source
Tier A · vendor-published

Cursor documentation overview

Publisher
Cursor
Retrieved
Aug 11, 2026
Upstream ref
Live official documentation reviewed 2026-08-11
Rights posture
Original summary of official documentation; no prompt text copied.

Establishes the coding-product and agent context, not a complete runtime prompt.

Open primary source
Tier A · vendor-published

Cursor rules documentation

Publisher
Cursor
Retrieved
Aug 11, 2026
Upstream ref
Live official documentation reviewed 2026-08-11
Rights posture
Original summary of official documentation.

Documents rule inputs rather than the complete instruction assembly.

Open primary source
Tier A · vendor-published

Cursor agent tools

Publisher
Cursor
Retrieved
Aug 11, 2026
Upstream ref
Live official documentation reviewed 2026-08-11
Rights posture
Original summary of official documentation.

Tool availability and automatic execution can vary with configuration.

Open primary source
Tier A · vendor-published

Cursor models documentation

Publisher
Cursor
Retrieved
Aug 11, 2026
Upstream ref
Live official documentation reviewed 2026-08-11
Rights posture
Original summary of official documentation.

Model availability can change and does not define one universal Cursor runtime.

Open primary source
Tier A · vendor-published

Cursor memories documentation

Publisher
Cursor
Retrieved
Aug 11, 2026
Upstream ref
Live official documentation reviewed 2026-08-11
Rights posture
Original summary of official documentation.

Documents saved memory behavior, not every context input.

Open primary source
Tier A · vendor-published

Cursor CLI permissions

Publisher
Cursor
Retrieved
Aug 11, 2026
Upstream ref
Live official documentation reviewed 2026-08-11
Rights posture
Original summary of official documentation.

Documents CLI permission configuration; editor and deployment controls can differ.

Open primary source
Tier A · vendor-published

Cursor Origin documentation

Publisher
Cursor
Retrieved
Aug 25, 2026
Upstream ref
Live official documentation reviewed 2026-08-25
Rights posture
Original summary of official documentation.

Documents an early-beta git forge and staged availability; it does not establish the full Cursor instruction stack.

Open primary source
Tier A · vendor-published

Cursor Cloud Agent capabilities

Publisher
Cursor
Retrieved
Aug 25, 2026
Upstream ref
Live official documentation reviewed 2026-08-25
Rights posture
Original summary of official documentation.

Documents subscription triggers and limits for Cloud Agents; supported integrations and limits can change.

Open primary source
Tier A · vendor-published

Cursor agent prompting documentation

Publisher
Cursor
Retrieved
Aug 25, 2026
Upstream ref
Live official documentation reviewed 2026-08-25
Rights posture
Original summary of official documentation.

Documents Custom Modes as persistent skill context in supported agent surfaces, not a complete base prompt.

Open primary source
Tier A · vendor-published

Cursor cloud harness changelog

Publisher
Cursor
Retrieved
Aug 25, 2026
Upstream ref
Cursor changelog published 2026-08-19
Rights posture
Original summary of official changelog.

Records the August 2026 release state, including the current Cloud Agent-only subscription limitation.

Open primary source
Tier A · vendor-published

Cursor changelog — Self-hosted machines

Publisher
Cursor
Retrieved
Sep 05, 2026
Upstream ref
Cursor changelog published 2026-09-02
Rights posture
Original summary of official changelog; no prompt text copied.

Documents self-hosted Cloud Agent execution, dynamic worker pools, sandbox infrastructure, and Linux/Mac computer use as described in the entry; it does not establish all deployment requirements, availability, or Cursor's full instruction stack.

Open primary source

Available pages

Search Promptcred

Type to search available pages.