update-cli-config — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited update-cli-config (Agent Skill) and scored it 45/100 (orange). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.
*.sig, SIGNATURES) outside the documentation.Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This skill explains how to view and modify Cursor CLI settings stored in ~/.cursor/cli-config.json.
The config file is ~/.cursor/cli-config.json.
Projects can layer overrides via .cursor/cli.json files. The CLI walks from the git root to the current working directory and merges each .cursor/cli.json it finds (deeper files take precedence). Project overrides only affect the current session; they are not written back to the home config.
Read ~/.cursor/cli-config.json, apply changes, and write it back. The file is standard JSON. Changes take effect after restarting the CLI.
permissions (required)Tool permission rules. Each entry is a string pattern.
allow: string[] — patterns for allowed tool calls (e.g. "Shell(**)", "Mcp(server-name, tool-name)")deny: string[] — patterns for denied tool callseditorvimMode: boolean — enable vim keybindings in the CLI inputdefaultBehavior: "ide" | "agent" — default behavior modedisplay (optional)showLineNumbers: boolean (default: false) — show line numbers in code outputshowThinkingBlocks: boolean (default: false) — show model thinking/reasoning blocksshowStatusIndicators: boolean (default: false) — show status indicators in the UIchannel (optional)Release channel: "prod" | "staging" | "lab" | "static"
maxMode (optional)boolean (default: false) — enable max mode for higher-quality model responses
approvalMode (optional)Controls tool approval behavior:
"allowlist" (default) — require approval for tools not in the allow list"unrestricted" — auto-approve all tool calls (yolo mode)sandbox (optional)Sandbox execution environment settings:
mode: "disabled" | "enabled" (default: "disabled")networkAccess: "user_config_only" | "user_config_with_defaults" | "allow_all" — controls network access from sandboxnetworkAllowlist: string[] — domains the sandbox is allowed to reachnetwork (optional)useHttp1ForAgent: boolean (default: false) — use HTTP/1.1 instead of HTTP/2 for agent connections (enables SSE-based streaming)bedrock (optional)AWS Bedrock integration settings:
enabled: boolean (default: false)mode: "access-key" | "team-role" (default: "access-key")region: string — AWS regiontestModel: string — model to use for testingteamRoleArn: string — IAM role ARN for team modeteamExternalId: string — external ID for STS assume-roleattribution (optional)Controls how agent work is attributed in git:
attributeCommitsToAgent: boolean (default: true) — attribute commits to the agentattributePRsToAgent: boolean (default: true) — attribute PRs to the agentwebFetchDomainAllowlist (optional)string[] — domains the web fetch tool is allowed to access (e.g. "docs.github.com", "*.example.com", "*")
These are internal/cached state and should not be edited manually:
version — config schema versionmodel / selectedModel / modelParameters / hasChangedDefaultModel — managed by the model pickerprivacyCache — cached privacy mode stateauthInfo — cached authentication infoshowSandboxIntro — one-time UI flagconversationClassificationScoredConversations — internal cache~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.