Subagents can still use disabled models

Where does the bug appear (feature/product)?

Cursor IDE

Describe the Bug

Subagent used Opus 4.8 and I was charged for it despite having only composer 2.5 enabled as my model options

Request ID: cabfa121-32f1-46a2-9141-c80c7cef5ea0

Screenshot 1: Model selections only allow composer 2.5, opus 4.8 is explicitly disabled
Screenshot 2: review subagent uses opus
Screenshot 3: in my usage history, I was charge for it

Steps to Reproduce

unsure

Expected Behavior

Only composer 2.5 should be used

Screenshots / Screen Recordings

Operating System

MacOS

Version Information

Version: 3.7.36 (Universal)
VS Code Extension API: 1.105.1
Commit: 776d1f9d76df50a4e0aeca61819a88e7c1b861e0
Date: 2026-06-13T00:31:56.287Z
Layout: glass
Build Type: Stable
Release Track: Default
Electron: 39.8.1
Chromium: 142.0.7444.265
Node.js: 22.22.1
V8: 14.2.231.22-electron.0
xterm.js: 6.1.0-beta.256
OS: Darwin arm64 25.5.0

For AI issues: which model did you use?

Opus 4.8

For AI issues: add Request ID with privacy disabled

cabfa121-32f1-46a2-9141-c80c7cef5ea0

Does this stop you from using Cursor

No - Cursor works, but with this issue

Hi @chenjay!

Can you share this screenshot? Were you using the /review / review-bugbot subagent, or something else?

This is the kind of modelcontrol issue that matters a lot for trust.

If a user disables an expensive model, subagents should probably inherit that constraint by default. Otherwise the main agent may look cheap and predictable, while the hidden review or helper path quietly spends on a model the user explicitly tried to avoid.

ah sorry i thought all of the screenshots went through but it seems it only let me post 1 in the original filing. i think it was indeed from a /review subagent run, but one piece of note is that i did not explicitly call the skill, i asked the thread to perform a review and it automatically kicked off a /review subagent run with the wrong model. i presume we can still run that skill using composer. in another thread i kicked off /review which kicked off /review-bugbotand it used composer instead

screenshot 1:

screenshot 2:

screenshot 3: