Answers
How do I make Cursor’s agent ask before risky tool calls?
Put the MCP tools Cursor’s agent uses behind Immiscible’s MCP proxy, and add Immiscible’s MCP server so it can ask before paying or sharing data. Keep Cursor’s own settings for its terminal commands; Immiscible’s hook is for Claude Code.
Put the MCP tools Cursor’s agent uses behind Immiscible’s MCP proxy, which holds their credentials and decides each call, and add Immiscible’s MCP server so the agent can ask before paying or sharing data. For Cursor’s own terminal commands, use Cursor’s own settings: Immiscible’s command hook is built for Claude Code, not Cursor.
#How do I set it up?
- Get an agent key:
npx immiscible init --yeswrites it to.env. - Put each tool server behind the proxy and point Cursor at it in
.cursor/mcp.json:
{
"mcpServers": {
"github": {
"url": "https://immiscible.fly.dev/mcp/proxy/mcu_6c1d0e",
"headers": { "Authorization": "Bearer ${env:IMMISCIBLE_AGENT_KEY}" }
}
}
}Then remove Cursor’s direct connection to the same tool. See the MCP proxy.
- Add Immiscible’s own MCP server for payments and personal data:
npx immiscible mcp --client cursorprints the entry and a one-click install link. See add the MCP server.
#What about commands in Cursor’s terminal?
Cursor decides those itself, with its own allow and deny settings for terminal commands. Use them. Immiscible does not see a command Cursor runs unless it passes through something Immiscible stands in front of, such as a proxied tool or the gateway.
#Can Immiscible govern Cursor’s model spend?
Not the inference Cursor runs on its own hosted models: that cannot pass through any gateway. That usage can be reconciled from the vendor’s API and is marked as not governed. Model calls your own code or your own keys make can go through the gateway.
#What does it not do?
- It does not install anything inside Cursor beyond MCP configuration, and it has no Cursor-specific hook.
- A tool Cursor can still reach with its own credential is not governed.