Anonymous - 4 days ago

Originally posted by: imshaikot

Measured, 1 Oct 2026

cursor-agent 2026.09.18-9a7762b on the Auto model. The runner's own plan ran through drive.ts, with a stand-in MCP server in place of browsentic mcp that logs every start, list and call. That is 6 real turns.

Question Answer
Does the run's MCP server load? No: it never has. A server in a project .cursor/mcp.json is not loaded (needs approval), and the run's model saw no browser tools at all. It searched, grepped and tried the shell until Cursor stopped it with Agent Looping Detected. Every Cursor run since [#25] has gone without the browser
What approves it? cursor-agent mcp enable browsentic, run in the run's folder. It takes 0.26–0.35 s and writes one key to ~/.cursor/projects/<folder>/mcp-approvals.json. The key is browsentic- plus a hash of { folder, server config }, and that config includes BROWSENTIC_AGENT_RUN, so every turn needs its own approval. --approve-mcps would approve every server the user has, so it stays forbidden
How does the model reach the tools? Behind a lookup. The model calls Cursor's GetMcpTools, searching by pattern or fetching one tool's schema by name, before each new tool: one or two extra round trips, like Codex exec's tool_search. No client switch turns it off
A tool cap? None at 55 tools: t52 and t01 both answered
Pictures Reach the model: it named the stand-in's orange square
A 60 KB result Spilled to ~/.cursor/projects/<folder>/agent-tools/<uuid>.txt; the model is handed the path, Read is denied, the shell is denied, and it answered with the path instead of the codeword
A 70 s call Cut at exactly 60.0 s with MCP error -32001: Request timed out; the server does receive the cancel
A resumed turn after AGENTS.md changed Answered with the first turn's codeword: Cursor keeps the prompt a session began with (keepsFirstPrompt, like Claude Code and Codex)
ls, with the user's own Shell(ls) allow in ~/.cursor/cli-config.json Refused: the run's deny wins
grep pointed outside the folder Searched the run's own folder instead
A one-shot handed a PNG, then a PDF Both read correctly, so opens can be text, PDF and image

Found on the way:

  • Plugin MCP servers load in every run, named plugin-<plugin>-<server>, and the runner denies only the servers in ~/.cursor/mcp.json. Mcp(...) rules glob the server name, so a Mcp(plugin-*:*) deny closes that.
  • Reader: our own calls arrive as mcpToolCall with providerIdentifier: "browsentic" and no server key, so the timeline draws each one twice. Cursor's own tools never get a toolResult. The closing usage adds up every request in the turn (about 20k per request here), so it cannot fill the context card.

That adds four items to the plan above, ahead of the 60 s and 40 KB work: approve the run's server before every turn (vetted like any other argv), deny plugin servers, the prompt section that names the tools to look up in one go, and the reader fixes. Plus keepsFirstPrompt and opens: text, pdf, image.

 

Related

Tickets: #25