The FireAI Security Blog

By FireAI Security & Research Team · Published

Monitor Cursor Network Connections on Mac: AI Agent Security

Monitor Cursor Network Connections on Mac: AI Agent Security

Cursor is an AI code editor developed by Anysphere, Inc. Besides completing code, its agent can run shell commands in a terminal, and the editor keeps connections open to Cursor’s backend for requests, updates and its extension marketplace. This article summarises what Cursor documents about its run modes, its macOS sandbox and the hosts it uses, then shows how to watch the editor’s connections with FireAI.

What Cursor is

Cursor’s security page describes the product as an AI-powered code editor and states that the application makes requests to Cursor backend domains to deliver API, update and marketplace functionality. It also documents a Privacy Mode that prevents model training on your data and is available on free and paid plans. Privacy Mode is a policy about how Cursor treats data it receives. It does not change which hosts the editor connects to.

What the agent can do and how it is controlled

Cursor’s documentation says the agent executes shell commands in the terminal, with behaviour controlled by Run Mode settings. There are three modes:

  • Auto-review runs known-safe calls, sandboxes shell commands when it can, and asks a classifier to review anything else.
  • Allowlist runs only trusted, pre-approved actions.
  • Run Everything executes all commands without prompts, which the documentation treats as the highest-risk option.

On macOS, the documentation says Cursor sandboxes commands with Seatbelt and sandbox-exec, restricting file access, network connectivity and process behaviour across the subprocess tree. This requires Cursor v2.0 or later and needs no extra configuration on desktop installs. Network inside the sandbox is limited to the domains in a sandbox.json allowlist when that file is used alone, and by default the allowlist is combined with Cursor’s built-in domains for package managers and development tools.

A sandbox of this kind restricts commands the agent starts. The editor itself, which talks to Cursor’s servers, runs outside that boundary, so its own connections remain visible only at the network level.

The hosts Cursor documents

Cursor’s network configuration page lists the domains the editor uses. The vendor-documented ones are:

Source: Cursor documentation, network configuration. Cursor states it uses HTTP/2 bidirectional streaming by default, with an HTTP/1.1 Server-Sent Events fallback, and TLS 1.2 or higher for all connections.
HostDocumented purpose
api2.cursor.shMost API requests
api5.cursor.sh and agent subdomains such as agent.api5.cursor.shCursor’s agent requests
api3.cursor.sh, api4.cursor.sh and *.gcpp.cursor.sh gatewaysCursor Tab requests (HTTP/2 only)
repo42.cursor.shCodebase search (HTTP/2 only)
authenticate.cursor.sh, authenticator.cursor.shAuthorization endpoint and login webview
marketplace.cursorapi.com, cursor-cdn.com, downloads.cursor.comMarketplace and updates

Because Cursor documents a stable set of its own domains, a connection from the editor to a host outside that set, and outside the package managers and sites you work with, is the kind of event worth a second look. It is not by itself evidence of a problem: extensions, MCP servers and the commands you approve all have destinations of their own.

Why a network view still helps

Run modes decide what the agent may do. They do not give you a record of where the machine connected afterwards. With Run Everything selected, for example, there is no prompt at all, and the network is then the place to look. See also the companion articles on Claude Code and Windsurf, which cover similar tools.

Watching Cursor with FireAI

FireAI is a firewall for macOS made by HisnLabs, and since version 1.0.2 it has a feature called Agent profile. It recognises 19 AI agents, learns where each one normally connects, and flags unusual behaviour for you to review. Cursor is recognised by its code signature.

Cursor is one of the three agents FireAI checks against its developer’s code signature, so a match is more than a name.

FireAI also recognises the agent’s child processes, such as a shell, git or curl that the agent runs, by walking up the process’s parents until it reaches the agent. Those connections are therefore counted as the agent’s own.

What FireAI flags

  1. For the first 3 days FireAI learns the destinations the agent normally contacts, grouped by domain. Nothing is flagged during this learning period.
  2. After that, a first-ever destination outside the learned baseline is flagged for review.
  3. An upload spike is flagged too: an hour in which the agent sent at least 4 times its busiest hour so far, and never less than 25 MB.

Agent profile uses only metadata, meaning host names and byte counts. FireAI never reads the payload of a connection, and it cannot read inside an encrypted one.

Set it up for Cursor

  1. Install FireAI and finish the setup, then keep using Cursor as you normally do. The 3-day learning period starts from what FireAI sees.
  2. Open Suggestions and look at the AI agents card. It lists the agents FireAI has recognised and what it has learned about each.
  3. When Cursor reaches a destination it has never contacted, the flag appears in the AI agents card and in Quick Review. Swipe left to block, or right for “It’s fine”.
  4. Block creates a rule for the process that connected. “It’s fine” adds the destination to the agent’s baseline so it is not flagged again.
  5. If you want the agent kept to the places it already uses, choose Agent profile in the security mode menu, next to Home, Coffee shop, Paranoid and Under attack. Once the agent has finished learning, a connection to a destination outside its baseline is blocked instead of flagged.
  6. A blocked destination shows in the AI agents card with Allow and Keep blocked. Allow adds it to the baseline and the agent can reach it right away. Keep blocked creates a block rule, so the destination stays blocked in every mode.

Limits

  • FireAI does not prevent prompt injection. A prompt hidden in a web page or a file can still steer an agent. What FireAI can do is flag, and let you block, the path data would take out of your Mac.
  • FireAI cannot see prompts, the contents of MCP tools, or which files Cursor reads, such as ~/.ssh. TLS hides the payload, and FireAI is not inside the agent.
  • Child processes that exit very quickly may be missed, and child processes are matched by path, not by signature.
  • During the 3-day learning period nothing is flagged.
  • In the Agent profile mode, a connection to a bare IP address with no host name is matched by its address. If a service the agent normally uses answers from a new address, it is blocked until you allow it.
  • FireAI’s plain-words explanation of a flag is written from facts it measured. It never says a destination is safe or dangerous. The decision is yours.

Related guides

The same approach applies to the other agents FireAI recognises: Claude Code, the Claude desktop app, the ChatGPT Mac app, Codex CLI, OpenClaw, Hermes Agent, Gemini CLI, GitHub Copilot CLI, Amp, Qwen Code, opencode, Aider, Goose, Crush, Windsurf, Kiro, Trae, Muse from Meta, any other AI agent run by Python or Node. The full feature description is in the Agent profile documentation.

How FireAI and HisnLabs fit in

Cursor’s agent can run commands. FireAI shows where your Mac connects while it works.

FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac.

You can read the technical decisions behind it, or try FireAI for 17 days, at FireAI, by HisnLabs.

Sources