Agent Blast Radiusby Kloudle

Answers / Does Cursor Expose My API Keys or Secrets?

Answer

Does Cursor expose my API keys or other secrets?

Cursor doesn't deliberately exfiltrate secrets, but two gaps let them leak: .cursorignore only hides files from the Agent's context and @ mentions, not from its terminal or MCP tools, and the agent terminal runs shell commands with your own OS permissions, so it can read and output anything you can. Letting it run every command automatically removes the review step that would normally catch that.

Updated · Kloudle

What does .cursorignore actually protect?

Cursor's own documentation is specific about scope: .cursorignore restricts "code accessible by Agent, Tab, and Inline Edit" and "code accessible via @ mention references." That's it — it's a context filter for completions and explicit file references, not a file-access control.

The same documentation states the limitation directly: "the terminal and MCP server tools used by Agent cannot block access to code governed by .cursorignore." A file you've ignored for autocomplete purposes can still be opened by a terminal command the agent runs, or read by an MCP server it calls, and either one can print that file's contents straight back into the chat. Cursor's docs add one more caveat on top of that: because the ignore rule still passes through an LLM, "complete protection isn't guaranteed due to LLM unpredictability," so even the context filter isn't absolute.

Does Cursor's agent terminal run with my own access?

Yes. The agent terminal executes shell commands the same way you would — as your OS user, with your shell environment and whatever credentials that environment exposes. A command that can read .env, an AWS credentials file, or an SSH key when you type it yourself can do the same when the agent types it.

Cursor has added an optional sandbox for terminal commands that "runs terminal commands in a restricted environment that blocks unauthorized file access and network activity," configurable through Run Modes. The most permissive of those modes, Run Everything, runs "every tool call" automatically with no prompt at all. Security write-ups covering Cursor flag that kind of unattended execution specifically: letting an agent auto-run commands "removes critical review steps, increasing the risk of unsafe scripts executing unnoticed," and the standing advice is to avoid it unless the terminal sandbox is also on.

What does Cursor do with my code and secrets?

Cursor's security page states that with Privacy Mode on, the company will not train on your data, and that it applies "technical controls and contractual requirements with our model providers" to protect it. Privacy Mode is available to anyone on a free or Pro plan and can also be enforced by a team or enterprise admin.

None of that changes what's covered above: Privacy Mode governs what Cursor's backend retains, not what the agent's own terminal or MCP tools can read and paste back into a transcript, a commit, or a pull request on your machine. A security review of Cursor also calls out the more basic risk directly: "AI-generated outputs can accidentally include API keys, authentication tokens, or login credentials" when a model pattern-matches on something that looks like example code but is actually your real secret.

How do you reduce the risk in practice?

Treat ignore files as an indexing control, not a secret boundary.

  • Avoid the Run Everything mode, or turn on the terminal sandbox if you keep it on, so a command touching a credential file gets a human look first.
  • Keep real secrets out of the working directory and environment the agent inherits — reference them through a vault or short-lived session instead of a plaintext .env the agent's terminal can read directly.
  • Don't rely on .cursorignore for anything the terminal or an MCP server could still open; it only filters the Agent and Tab context.
  • Enable Privacy Mode if you need a retention guarantee from Cursor's backend, understanding it doesn't touch local terminal or MCP access.
  • Run Agent Blast Radius to see, independent of any single tool's settings, which credentials on your machine a process running as you — including Cursor's agent terminal — could currently read.

Check your own machine

See what an agent running as you can reach. Offline, read-only, never prints values:

$npx -y @kloudle/agent-blast-radius@0.3.0

Inside your agent: install guides for Claude Code, Codex, Cursor, Claude Desktop and more. Which keys are live? npx -y @kloudle/agent-blast-radius@0.3.0 verify (paid per check).

Frequently asked

Does .cursorignore stop Cursor's Agent from reading a secret file?

Not completely. It stops the file from entering Agent, Tab, and @ mention context, but Cursor's own docs say the terminal and MCP tools the Agent calls are not bound by .cursorignore, so a shell command or MCP tool can still read and surface that file's contents.

Does Cursor's terminal run commands with my own credentials?

Yes, by default. The agent terminal executes as your OS user with your environment, unless you've turned on Cursor's terminal sandbox, which restricts file and network access for commands run inside it.

Does Privacy Mode stop local secret exposure?

No. Privacy Mode controls whether Cursor's backend retains or trains on your code; it doesn't change what the agent's local terminal or MCP tools can read from your machine or paste into chat, a commit, or a generated file.

Can an AI-written commit or PR leak a key by accident?

Yes. Security reviews of Cursor note that AI-generated code or terminal output can include real API keys or tokens the model mistook for safe example values, so a leak can end up in version control even without any deliberate attack.

Sources

  1. Ignore Files (.cursorignore) — Cursor
  2. Agent Terminal Tool — Cursor
  3. Security — Cursor
  4. Cursor Security: Risks and Best Practices — TrueFoundry

Related