Command allowlist never sticks because a later command must be a complete match of a prior one

Where does the bug appear (feature/product)?

Cursor IDE

Describe the Bug

Allowlist mode does not approve a command type. It only skips the approval card when the new command is a complete match of one already approved. Agents vary arguments, quoting, working directories, and small helper commands on every turn, so the same kind of command keeps raising an approval card. The allowlist never becomes useful, and the only way to get work done is Run Everything, which drops the safety control the allowlist is supposed to provide.

Steps to Reproduce

  1. Set Agent run mode to Allowlist (not Run Everything) in Cursor Settings > Agents > Approvals & Execution.
  2. Let the agent run a routine command, for example a git status/diff or a PowerShell Get-ChildItem.
  3. On the approval card, allow that command type (Always run).
  4. On a later turn, let the agent run the same command type with different arguments, quoting, a path, or a short chain (&&, |, or a PowerShell script block).
  5. The approval card appears again, even though this is the same general command that was already allowed.

Expected Behavior

Approving a command type should cover later invocations of that type, including normal argument and path changes. The card should come back only for a new command type, or for something the allowlist explicitly excludes. Allowlist mode should be usable without falling back to Run Everything.

Actual: a command is treated as new unless it completely matches a prior approved command. The card keeps asking to approve the same general command type. After a few turns the allowlist is effectively unused, and Run Everything is the only mode that stops the prompts.

Operating System

Windows 10/11

Version Information

Version: 3.21.9
Commit: d5c0e77a0214208f36b56d42e8e787de88d02ea4
OS: Windows 11 (10.0.26200)
Shell: PowerShell

Additional Information

Related reports already describe pieces of this: literal matching (“$HOME/.dotnet/dotnet” vs $HOME/.dotnet/dotnet), chained commands and PowerShell control flow still prompting when each binary is allowlisted, and Always Run not persisting. From the user’s side these are the same failure: the allowlist matches a complete prior command, not a command type, so it cannot keep up with normal agent commands.

Does this stop you from using Cursor

Sometimes - I can sometimes use Cursor

Hey @Steve_Carlisle1, thanks for the report.

The allowlist actually matches by command prefix, not by the whole line. An entry of git covers every git command, while git status only covers git status .... When the approval card appears, open the “Always Run” dropdown and pick the broadest entry you’re comfortable with (for example git or Get-ChildItem) rather than the full command line.

Two things still cause repeat prompts. Every command in a chain has to be on the list, including small helpers like cd, Select-Object or Where-Object. And PowerShell script blocks, if ($LASTEXITCODE ...) checks and 2>$null redirects currently always ask for approval, even when the real commands are allowlisted. That last part is a known issue on our side and I’ve added your report to it.

In the meantime, a User Rule (Cursor Settings > Rules) like “Run one shell command per tool call. Don’t chain commands or use PowerShell script blocks unless required.” cuts these down a lot. If you want approvals judged by what a command does rather than an exact list, Auto-Review in the Run Mode dropdown is built for that.

If a command still prompts when every part of it is already on your list, could you share a screenshot of the approval card (it lists what it thinks is missing) and your current allowlist?

Thank you for the settings suggestions. I will try them. I will post a screenshot next time if it continues to be a problem.