Cursor
A Cursor hook sends each shell command the agent wants to run to dagsec before it runs. Install commands are checked; everything else is allowed immediately and nothing is stored.
Setup
- Create an API key.
- Put this in
~/.cursor/hooks.json(your user settings, not the repository, since it holds your key), replacingYOUR_DAGSEC_API_KEY:
{
"version": 1,
"hooks": {
"beforeShellExecution": [
{
"command": "curl -s -m 15 -H \"Authorization: Bearer YOUR_DAGSEC_API_KEY\" -H \"Content-Type: application/json\" --data-binary @- https://app.dagsec.net/api/hooks/cursor",
"timeout": 20
}
]
}
}On Windows, write curl.exe instead of curl. The Integrations page in the dashboard shows this file ready to copy.
What it does
dagsec answers with Cursor's permission:
| Result | Permission |
|---|---|
| Not an install, or nothing risky | allow |
| Risky, block mode | deny, with the reason shown to you and the agent |
| Risky, warn mode | ask: you decide |
Warn mode: add ?mode=warn to the URL (or send the header X-Dagsec-Mode: warn). Team members get the team's mode regardless.
Commands recognized
Because Cursor sends every command, dagsec recognizes more package managers than the Claude Code plugin's filter:
| Tool | Commands |
|---|---|
| npm, cnpm | install, i, add |
| Yarn, pnpm, Bun | add, install, i |
| pip, pip3, pipx, Poetry, PDM | install, add |
| uv | uv add, uv pip install |
| Python | python -m pip install, python3 -m pip install, py -m pip install |
| Cargo | cargo add |
| Go | go get, go install |
| .NET | dotnet add package <id> [--version <v>], dotnet add <project> package <id> |
Commands chained with ;, &&, | or newlines are split and each is checked. Leading sudo and VAR=value are ignored. Local paths, URLs, git sources and tarballs are skipped. Up to 10 packages per command are checked.
Failure behaviour
If dagsec can't be reached within the timeout, or the key is wrong, the command runs. Rules are the same as for Claude Code.