Skip to content

Cursor ​

A Cursor hook sends each shell command the agent wants to run to dagsec before it runs. Install commands are checked; everything else is allowed immediately and nothing is stored.

Setup ​

  1. Create an API key.
  2. Put this in ~/.cursor/hooks.json (your user settings, not the repository, since it holds your key), replacing YOUR_DAGSEC_API_KEY:
json
{
  "version": 1,
  "hooks": {
    "beforeShellExecution": [
      {
        "command": "curl -s -m 15 -H \"Authorization: Bearer YOUR_DAGSEC_API_KEY\" -H \"Content-Type: application/json\" --data-binary @- https://app.dagsec.net/api/hooks/cursor",
        "timeout": 20
      }
    ]
  }
}

On Windows, write curl.exe instead of curl. The Integrations page in the dashboard shows this file ready to copy.

What it does ​

dagsec answers with Cursor's permission:

ResultPermission
Not an install, or nothing riskyallow
Risky, block modedeny, with the reason shown to you and the agent
Risky, warn modeask: you decide

Warn mode: add ?mode=warn to the URL (or send the header X-Dagsec-Mode: warn). Team members get the team's mode regardless.

Commands recognized ​

Because Cursor sends every command, dagsec recognizes more package managers than the Claude Code plugin's filter:

ToolCommands
npm, cnpminstall, i, add
Yarn, pnpm, Bunadd, install, i
pip, pip3, pipx, Poetry, PDMinstall, add
uvuv add, uv pip install
Pythonpython -m pip install, python3 -m pip install, py -m pip install
Cargocargo add
Gogo get, go install
.NETdotnet add package <id> [--version <v>], dotnet add <project> package <id>

Commands chained with ;, &&, | or newlines are split and each is checked. Leading sudo and VAR=value are ignored. Local paths, URLs, git sources and tarballs are skipped. Up to 10 packages per command are checked.

Failure behaviour ​

If dagsec can't be reached within the timeout, or the key is wrong, the command runs. Rules are the same as for Claude Code.