Agent deletes critical files without confirmation

Where does the bug appear (feature/product)?

Cursor IDE

Describe the Bug

Issue Summary for Cursor
Critical Safety Issue: AI Assistant Deleted User Files Without Confirmation
What happened:
The AI assistant (Auto) deleted a 16MB database dump file (rs-st0x6o_2025-10-18_12-56-09.sql) without explicit user confirmation
The file was deleted when the user asked “Are there any diff/changes that are not needed and can be deleted now?”
The assistant interpreted this as permission to delete files immediately, rather than asking for confirmation first
Why this is critical:
Database dumps are important backups that cannot be easily recovered
File deletion is a destructive operation that should require explicit confirmation
The assistant should err on the side of caution with potentially important files
Expected behavior:
The assistant should list files that could be deleted
The assistant should ask for explicit confirmation before deleting each file or category
The assistant should warn about potentially important files (backups, database dumps, etc.)

Steps to Reproduce

Use Agent mode.
The file was deleted when the user asked “Are there any diff/changes that are not needed and can be deleted now?”

Expected Behavior

The assistant should list files that could be deleted
The assistant should ask for explicit confirmation before deleting each file or category
The assistant should warn about potentially important files (backups, database dumps, etc.)

Operating System

MacOS

Current Cursor Version (Menu → About Cursor → Copy)

Version: 2.2.43
VSCode Version: 1.105.1
Commit: 32cfbe848b35d9eb320980195985450f244b3030
Date: 2025-12-19T06:06:44.644Z (6 days ago)
Electron: 37.7.0
Chromium: 138.0.7204.251
Node.js: 22.20.0
V8: 13.8.258.32-electron.0
OS: Darwin arm64 24.6.0

For AI issues: which model did you use?

Auto

For AI issues: add Request ID with privacy disabled

814e70ec-ada9-4c9c-b0a0-2a07ee0742c1

Does this stop you from using Cursor

No - Cursor works, but with this issue

hi @IAmX and thank you for your bug report.

Could you share more details so we can understand better what caused the issue?

  • Which Auto-Run setting do you have: Ask, Allowlist or Everything
  • How did the Agent delete files? (Terminal, direct file deletion without terminal)
  • Did it occur in a new chat or in an already longer thread?

We do have several precautions to prevent exactly this issue from occurring:

  • Auto-Run settings to Always Ask
  • Agent setting to not allow deleting files

Also note that AI is not infallible and may make mistakes including misinterpreting your instructions. Longer chats can also be confusing for AI as the information in the context may be contradicting.

Allowlist, it doesn’t have anything related to removing.
Directly.
Already longer thread yet it did not have anything related to removing files but creating files mostly.

I understand the precautions and if you can point me I would like to turn on the agent setting that prevents deleting files without my exact confirmation. Thank you for your time and patience with me.

In Settings > Agents > Auto-Run you will see following.