# Disable permissions ask in sandbox

**URL:** <https://forum.cursor.com/t/disable-permissions-ask-in-sandbox/157243>\
**Category:** Feature Requests\
**Tags:** sandbox, cli, auto-run, terminal\
**Created:** [April 10, 2026, 12:53am UTC](https://forum.cursor.com/t/disable-permissions-ask-in-sandbox/157243 "2026-04-10T00:53:13Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hedi\_Ghediri](https://avatars.discourse-cdn.com/v4/letter/h/858c86/32.png) [@Hedi\_Ghediri](https://forum.cursor.com/u/Hedi_Ghediri)\
**Post date:** [April 10, 2026, 12:53am UTC](https://forum.cursor.com/t/disable-permissions-ask-in-sandbox/157243/1 "2026-04-10T00:53:13Z")

</div>

Hi,

I’m using the Cursor CLI with **Auto-Run in Sandbox** for autonomous workflows, where the sandbox boundaries are exactly what I want, but I’m running into a friction point.

Even with Auto-Run in Sandbox enabled, I get frequently prompted to approve commands like `python` or arbitrary bash scripts. I’m aware I could extend the command allowlist, but I’d rather not go that route. The whole point of relying on the sandbox is to define boundaries at the OS level (filesystem, network) rather than maintaining a list of trusted commands.

What I’m looking for: **a way to make Cursor never prompt**. When a command isn’t allowlisted or hits a sandbox restriction, I’d like it to simply fail (and let the agent react to that failure on its own) rather than interrupting with an approval dialog.

Is there a config flag, env var setting for this today? If not, I’d like to flag it as a feature request.

Thanks!

---

<div class="post-metadata">

**Author:** ![Colin](https://sea3.discourse-cdn.com/cursor1/user_avatar/forum.cursor.com/colin/32/90452_2.png) [@Colin](https://forum.cursor.com/u/Colin)\
**Post date:** [April 13, 2026, 3:47pm UTC](https://forum.cursor.com/t/disable-permissions-ask-in-sandbox/157243/4 "2026-04-13T15:47:33Z")

</div>

Hey @Hedi_Ghediri!

Thanks for the feedback. This isn’t possible today in the interactive TUI. There’s no flag to make sandbox-mode silently deny unapproved commands instead of prompting.

However, if you’re running autonomous workflows, headless mode does exactly what you’re describing:

```auto
agent --print --trust --sandbox enabled "your prompt"

```

In headless/print mode without `--force`, every command that isn’t on the allowlist is silently denied (no prompt, the agent sees the failure and reacts). Combined with `--sandbox enabled`, sandboxed commands auto-execute and everything else just fails. The tradeoff is you lose the interactive TUI.

> [@Hedi\_Ghediri](#):
>
> Even with Auto-Run in Sandbox enabled, I get frequently prompted to approve commands like `python` or arbitrary bash scripts.

Could you share more information about which version of Cursor you’re using / what OS, and also provide examples of commands that trigger the approval dialog? Curious what isn’t happy to run in the sandbox.
