I appreciate your response and the recovery tips. However, to be completely frank, the reason I stopped writing to the disk is because my life and my business are now completely frozen. This is an absolute disaster. I do not use GitHub to back up my files, nor do I have any other backup systems in place.
You suggested switching Auto-Run to “Ask Every Time.” Let’s be real: if I simply ask the agent to clone a GitHub repository, and I have to live in fear that it might arbitrarily wipe my entire C: drive, delete every script on my desktop, erase my documents, and destroy every installed program—then the Auto-Run feature is fundamentally broken and meaningless.
The entire point of Auto-Run is trusting the agent to take sensible, logical steps to achieve a specific goal I gave it. I had Auto-Run enabled because I trusted it to do that isolated simple task. It is completely absurd to expect that executing a basic git command would spiral into nuking an entire operating system. If Auto-Run means asking the agent to create a simple text file could result in a wiped PC, there is zero reason to ever use the feature.
What truly flabbergasts me is that I have been a loyal Cursor subscriber for over a year. I was using Composer 2.5 (not on fast mode), which is the model I consistently use. It was always on point and has never done anything remotely like this before.
Looking at the exact thought process of the agent (which you can see in the image I am attaching to this post), the root of the problem is horrifying. The agent decided on its own that “the build folder may not have been fully cleared.” Based on that assumption alone, it started blindly firing off recursive delete commands, wiping out absolutely everything. Ironically, it even deleted the very library it was trying to use next.
To make matters worse, I had invested a massive amount of time and money generating these files. I had a “scripts” folder on my desktop filled with code entirely written by the Cursor agent. I have spent hundreds of dollars over many months on my Cursor subscription, API usage, and even purchased additional Anthropic Claude API tokens to generate this work. In a matter of two to three seconds, everything I paid for and built was flushed down the drain.
These files were critical for my business—specifically, a large YouTube channel I’m running. I was heavily investing in AI to write this code, fully trusting that my local environment was safe. Now, my business operations are severely damaged and facing massive delays because of this incident.
Finally, you might ask why I didn’t add delete commands to a “forbidden prompts” list or an allowlist. Logically speaking, why would I ever think to do that? I never instructed the AI to delete anything. An agent should strictly do what it is explicitly told to do. The fact that the agent independently decides to scan through different project files and run highly destructive commands without any instruction is not just reckless—it’s highly suspicious.
Let’s be completely real here: your tool has left my system and my business completely stripped and ruined.