Independent register of AI agents & harnesses · no sponsored placementsEdition 2026-09 · 107 entries · evidence to 26 Sept 2026

The Register / Coding agents / Cursor

Register entry · Coding agents · updated 26 Sept 2026

Cursor

Cursor is a desktop code editor forked from VS Code, built around an Agents Window that runs several local, worktree, SSH and cloud agents in parallel. The Cursor CLI brings plan, ask and agent modes to the terminal and can hand a session off to a cloud agent. Cloud agents run in isolated remote VMs with computer use, test their own changes and return pull requests; they can also be started from Slack, the web, iOS and iPad. Cursor ships its own Composer models alongside third-party models and has been owned by SpaceX since August 2026.

What reviewers and users praise

  • Users repeatedly cite the IDE integration and visual diff review as the reason they prefer it over terminal agents (HN, June 2026).
  • Cloud agents with computer use and Bugbot code review are singled out as standout features by team users (HN, June 2026).
  • Speed of its harness and in-house Composer models is praised relative to token cost (HN, June 2026).

What they criticise

  • Resource usage and stability complaints: high CPU/RAM, buggy Agent Window, users moving back to VS Code with extensions (HN, June 2026).
  • Frequent pricing and plan changes (legacy request plan forced into Max mode, usage display switched to tokens) draw heavy forum backlash (July 2026).
  • Repeated serious sandbox-escape and prompt-injection CVEs in 2025-2026, all patched.
Rating certificate · AW/26-09/79126 Sept 2026

Cursor

Anysphere (wholly owned by SpaceX since 2026-08-14) · Coding agents

No. 8 of 16 in categoryhigh confidenceTrust B
Adoption68
Experts75
Crowd50
Experts vs the crowdcrowd cooler by 25
Experts75
Crowd50
PriceFree, paid from $20
Use it viaDesktop app, CLI, Web app, Mobile app, Chat apps, API
Runs onmacos, windows, linux, web
Licenceproprietary
UpdatedEvidence collected 26 Sept 2026

How the rating was worked out

Weights for Coding agents: adoption 35%, experts 40%, crowd 25%. Pillars without enough evidence are left out and the others re-weighted. The method.

Adoption & momentumweight 35%68Reported users 1M → 54 · 15 releases in 90 days → 100
reach × 0.7 + momentum × 0.3
Expertsindependent reviews · weight 40%759 independent reviews (6 positive · 3 mixed · 0 negative), averaged toward 50 for small samples.
Crowdcommunity sample · weight 25%5014 dated posts from hackernews, forum, reddit: 6 positive · 2 mixed · 6 negative
(positive + ½ mixed) ÷ n, averaged toward 50 for small samples
Rating66high confidence (3 of 3 pillars, 14 community posts).

Evidence checks. 8 posts over the three-per-thread limit not counted. 1 item could not be checked at the source (the page could not be fetched, or the quote is from a comment under the linked post); kept and marked “unverified”. How evidence is checked.

Editorial adjustment. Incident-history re-grade under methodology revision 2 (see the trust section).

Trust & safety

Seven dimensions graded A–D from documented facts. Overall: B.

A

Permission model

Default run mode is Auto-review: allowlisted calls run, other shell commands run in a sandbox (workspace-only writes, network blocked by default), and a classifier asks for approval on the rest. Allowlist and Run Everything modes documented. Sandbox is documented for macOS (Seatbelt) and Linux (Landlock, kernel 6.2+); Windows sandbox support is not stated on the page. source

A

Data access scope

Sandboxed commands read/write only inside the workspace with protected system paths blocked; network opened only via network mode and sandbox.json. Enterprise plan adds repository, model and MCP access controls. source

B

Data storage

Prompts and code context go to Cursor's cloud and model providers; cloud agents run on Cursor's VMs, with a self-hosted machines option added Sept 2026. Documented controls: Privacy Mode (enforceable org-wide), ZDR agreements with model providers, no China infrastructure. Data-region selection not documented on the pages read. source

C

Data retention & training

Data-use page: with Privacy Mode off Cursor 'may use and store codebase data, prompts, editor actions, code snippets, and other code data and actions to improve our AI features and train our models'. Privacy Mode is on by default only for Enterprise teams; for individuals the docs describe switching it on. No retention period stated. ZDR does not apply with own API keys or some models. source

C

Incident history (24 months)

Repeated serious CVEs in 24 months, all patched: CurXecute and MCPoison (2025), a Git-hooks flaw (Feb 2026), and the DuneSlide sandbox escapes (CVSS 9.8, fixed in 3.0, disclosed July 2026). Regraded from D: Revision 2: serious issues that were each fixed and publicly disclosed grade C; D is kept for unresolved issues or slow or undisclosed fixes. source

A

Compliance

Security page states SOC 2 Type II attestation plus ISO/IEC 27001:2022, ISO/IEC 42001:2023 and AIUC-1 certifications; trust center at trust.cursor.com. source

B

Transparency

Closed source; detailed public changelog (multiple dated entries per month) and public docs. source

The experts

9 named independent reviews found; dated reviews from the last 12 months are scored.

  • positive
    Cursor 3 ships a unified agent-first workspace — parallel Agents with per-task scope, design-driven workflows that turn references into component code via ComposerDigital Applied · 10 May 2026 · digitalapplied.com
  • mixed
    Use Cursor as your default if you're a) an organic coder who finds abstracting all code away to behavior scary, or b) want to learn how to code.Silen (blog.silennai.com) · 19 Jan 2026 · blog.silennai.com
  • mixed
    Cursor shines when a human is actively involved. It is excellent for thinking, reviewing, navigating diffs, and shaping changes interactively.Hoang Nguyen (codeaholicguy) · 10 Jan 2026 · codeaholicguy.com
  • positive
    working with the Cursor Agent was eerily similar to working with a human developer on my team ... but way, way faster because the feedback loop was real-time.Reilly Chase · 8 Oct 2025 · blog.rchase.com
  • mixed
    One honest complaint: Cursor 3’s pivot to “agent-first” has confused a lot of existing users who feel like they’re using a different product.Kim Jangwook (jangwook.net) · 26 Apr 2026 · jangwook.net
  • positive
    After two weeks of daily testing, I rate Cursor 3 at 9 out of 10 for professional developers and 7 out of 10 for occasional coders or beginners .Abdullah Rao (PublorAI) · 9 May 2026 · publorai.com
  • positive
    We tested Cursor in real conditions across three production projects, and it's one of the smoothest transitions we've experienced from a traditional code editor.Romain Cochard (Hack'celeration) · 1 Jan 2026 · hackceleration.com
  • positive
    Cursor 3 is the most ambitious release in the AI coding tools category in 2026. Not because it has the best underlying model — Claude Code edges it there.Sawyer Ruhl (ComputerTech) · 7 Apr 2026 · computertech.co
  • positive
    Cursor 3 just dropped, and the design overhaul completely changes the game for agentic software development.BridgeMind (YouTube) · 3 Apr 2026 · youtube.com

The crowd

14 coded posts from hackernews, forum, reddit.

6 positive2 mixed6 negative
  • positive
    Fully on Cursor at work and I love it over CC, OpenCode and Pi that I use for personal work.Ask HN: Is anyone on HN still actually using Cursor in 2026? · 16 Jun 2026 · news.ycombinator.com
  • mixed
    Do the heavy lifting in Claude code , Codex. Basic tasks in cursor. It's decent and damn fast.Ask HN: Is anyone on HN still actually using Cursor in 2026? · 16 Jun 2026 · news.ycombinator.com
  • negative
    I stopped using Cursor because of how terribly optimised it is (worse than VSCode despite being a fork).Ask HN: Is anyone on HN still actually using Cursor in 2026? · 16 Jun 2026 · news.ycombinator.com
  • negative
    on my legacy requests individual plan, I have been able to use frontier models with MAX mode off. Now its saying that Max mode is requiredforum.cursor.com: Legacy Individual Plan - Max Mode Required (1,285 likes) · 7 Jul 2026 · forum.cursor.com
  • negative
    I am being forced to use Grok 4.5 High Fast regardless of what model I initialize.forum.cursor.com: Cursor IDE force enabling Grok 4.5 as default model · 22 Jul 2026 · forum.cursor.com
  • negative
    Is it just me, or does Cursor feel like it’s more buggy than beforeforum.cursor.com: Usage Page $$ to Token Amount? · 31 Jul 2026 · forum.cursor.com
  • positive
    In my work with Claude Code vs Cursor+Gpt55, Claude is noticeably slower and more expensive.HN comment on 'Previewing GPT-5.6 Sol: a next-generation model' · 26 Jun 2026 · news.ycombinator.com
  • positive
    I implemented my own version with Cursor tab completion. It took the same amount of time, 4 hours. The code had a clear object-oriented architecture, with a structure for evolution.HN comment on 'Labor market impacts of AI: A new measure and early evidence' · 6 Mar 2026 · news.ycombinator.com

Pricing

As published, checked 26 Sept 2026.

PlanPriceNotes
HobbyFreeLimited Agent requests; Composer access.
Individual$20 / monthlyExtended Agent limits, frontier models, cloud agents, MCPs/skills/hooks; Bugbot on usage-based billing.
Teams$40 / monthly per userCentral billing/admin, team marketplace, shared cloud agents and automations, Bugbot, team-wide privacy mode, SAML/OIDC SSO.
EnterpriseCustomPooled usage, SCIM, repository/model/MCP access controls, audit logs, AI code tracking API.

Recent changes

Ranked alongside

Other ranked entries in Coding agents.

Compare with the top two
OpenCodeAnomaly75
Claude CodeAnthropic73
Zed (Agent Panel)Zed Industries73
GitHub CopilotGitHub (Microsoft)72

Sources

Every figure above traces to one of these, observed up to 26 Sept 2026.

  1. TechCrunch 2026-06-16: "SpaceX has agreed to acquire AI coding startup Cursor in a $60 billion stock deal"
  2. The Next Web 2026-08-14: "The SpaceX Cursor acquisition became effective on 14 August"; "Cursor keeps its name, its blog and its own transactions."
  3. Cursor changelog: CLI Agent Modes and Cloud Handoff (Jan 2026)
  4. Cursor Docs: Cloud Agents
  5. Cursor Security page
  6. Cursor: How your data is used
  7. Terminal-Bench 2.1 and 3.0 leaderboards (via research/2026-09/benchmarks/terminal-bench-newer.json)
  8. HN: Is anyone on HN still actually using Cursor in 2026? (2026-06-16)