Catastrophic damage and chaos IN PLAN MODE

Hey, thanks for the report. I see this is a different aspect of the issue - here the agent ignores Plan Mode’s system constraints and runs destructive commands despite the explicit “DO NOT RUN ANYTHING”.

In the previous thread PLAN mode switches to AGENT mode without user input, causes extensive damage, the problem was auto-execution without confirmation. Here it’s a violation of Plan Mode’s read-only constraint.

Could you please share:

  • Request IDs of the problematic calls (Privacy Mode off) - instructions: Getting a Request ID | Cursor Docs
  • A screenshot of the moment the agent executed a command despite “DO NOT RUN ANYTHING”
  • Confirmation that the Plan Mode indicator was active in the UI during the destructive commands

I’ll pass this to the team along with the previous report - this is a critical bug in Plan Mode constraint enforcement.