Hey, thanks for the report, and sorry for the scare. I can see an antivirus detection in your screenshot, we’ll look into it.
This is most likely a false positive. Cursor CLI on Windows updates itself in the background. It downloads and runs its installer script via PowerShell. Some antivirus tools, including Windows Defender’s ML heuristics, flag this “download and execute” pattern because real malware often uses similar techniques. Detections ending in !ml are heuristic guesses, not confirmed signature matches. We’ve seen a few reports like this, here’s a similar thread: Cursor CLI installation gets blocked by Windows Defender
To confirm it’s the same thing, could you share the exact detection name and the file path Defender flagged. You can find both in Windows Security → Virus & threat protection → Protection history.
If the flagged item is in the cursor-agent folder, or it’s a PowerShell command that links to cursor.com, you can safely restore it from quarantine and run Windows Update to refresh Defender definitions. It also helps to submit it as a false positive to Microsoft via their submission portal so they can fix it faster on the vendor side.
If the flagged file is somewhere not related to Cursor, please treat the warning seriously and tell us what it shows.