# Monitor Cursor Network Connections on Mac: AI Agent Security > Cursor’s agent runs terminal commands and talks to several Cursor domains. What its docs say about run modes, the macOS sandbox and hosts, and how FireAI flags a new destination. FireAI Security & Research Team (HisnLabs) · Published 2026-10-04 Canonical: https://hisnlabs.com/en/blog/monitor-cursor-network-mac-fireai Cursor is an AI code editor developed by Anysphere, Inc. Besides completing code, its agent can run shell commands in a terminal, and the editor keeps connections open to Cursor’s backend for requests, updates and its extension marketplace. This article summarises what Cursor documents about its run modes, its macOS sandbox and the hosts it uses, then shows how to watch the editor’s connections with FireAI. ## What Cursor is Cursor’s security page describes the product as an AI-powered code editor and states that the application makes requests to Cursor backend domains to deliver API, update and marketplace functionality. It also documents a Privacy Mode that prevents model training on your data and is available on free and paid plans. Privacy Mode is a policy about how Cursor treats data it receives. It does not change which hosts the editor connects to. ## What the agent can do and how it is controlled Cursor’s documentation says the agent executes shell commands in the terminal, with behaviour controlled by Run Mode settings. There are three modes: - Auto-review runs known-safe calls, sandboxes shell commands when it can, and asks a classifier to review anything else. - Allowlist runs only trusted, pre-approved actions. - Run Everything executes all commands without prompts, which the documentation treats as the highest-risk option. On macOS, the documentation says Cursor sandboxes commands with Seatbelt and `sandbox-exec`, restricting file access, network connectivity and process behaviour across the subprocess tree. This requires Cursor v2.0 or later and needs no extra configuration on desktop installs. Network inside the sandbox is limited to the domains in a `sandbox.json` allowlist when that file is used alone, and by default the allowlist is combined with Cursor’s built-in domains for package managers and development tools. A sandbox of this kind restricts commands the agent starts. The editor itself, which talks to Cursor’s servers, runs outside that boundary, so its own connections remain visible only at the network level. ## The hosts Cursor documents Cursor’s network configuration page lists the domains the editor uses. The vendor-documented ones are: | Host | Documented purpose | | --- | --- | | api2.cursor.sh | Most API requests | | api5.cursor.sh and agent subdomains such as agent.api5.cursor.sh | Cursor’s agent requests | | api3.cursor.sh, api4.cursor.sh and *.gcpp.cursor.sh gateways | Cursor Tab requests (HTTP/2 only) | | repo42.cursor.sh | Codebase search (HTTP/2 only) | | authenticate.cursor.sh, authenticator.cursor.sh | Authorization endpoint and login webview | | marketplace.cursorapi.com, cursor-cdn.com, downloads.cursor.com | Marketplace and updates | *Source: Cursor documentation, network configuration. Cursor states it uses HTTP/2 bidirectional streaming by default, with an HTTP/1.1 Server-Sent Events fallback, and TLS 1.2 or higher for all connections.* Because Cursor documents a stable set of its own domains, a connection from the editor to a host outside that set, and outside the package managers and sites you work with, is the kind of event worth a second look. It is not by itself evidence of a problem: extensions, MCP servers and the commands you approve all have destinations of their own. ## Why a network view still helps Run modes decide what the agent may do. They do not give you a record of where the machine connected afterwards. With Run Everything selected, for example, there is no prompt at all, and the network is then the place to look. See also the companion articles on [Claude Code](https://hisnlabs.com/en/blog/monitor-claude-code-network-mac-fireai) and [Windsurf](https://hisnlabs.com/en/blog/monitor-windsurf-network-mac-fireai), which cover similar tools. > Cursor’s agent can run commands. FireAI shows where your Mac connects while it works. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Watching Cursor with FireAI FireAI is a firewall for macOS made by HisnLabs, and since version 1.0.2 it has a feature called [Agent profile](https://hisnlabs.com/en/docs/agent-profile). It recognises 19 AI agents, learns where each one normally connects, and flags unusual behaviour for you to review. Cursor is recognised by its code signature. Cursor is one of the three agents FireAI checks against its developer’s code signature, so a match is more than a name. FireAI also recognises the agent’s child processes, such as a shell, git or curl that the agent runs, by walking up the process’s parents until it reaches the agent. Those connections are therefore counted as the agent’s own. ## What FireAI flags 1. For the first 3 days FireAI learns the destinations the agent normally contacts, grouped by domain. Nothing is flagged during this learning period. 2. After that, a first-ever destination outside the learned baseline is flagged for review. 3. An upload spike is flagged too: an hour in which the agent sent at least 4 times its busiest hour so far, and never less than 25 MB. Agent profile uses only metadata, meaning host names and byte counts. FireAI never reads the payload of a connection, and it cannot read inside an encrypted one. ## Set it up for Cursor 1. Install FireAI and finish the setup, then keep using Cursor as you normally do. The 3-day learning period starts from what FireAI sees. 2. Open Suggestions and look at the AI agents card. It lists the agents FireAI has recognised and what it has learned about each. 3. When Cursor reaches a destination it has never contacted, the flag appears in the AI agents card and in [Quick Review](https://hisnlabs.com/en/docs/quick-review-suggestions). Swipe left to block, or right for “It’s fine”. 4. Block creates a rule for the process that connected. “It’s fine” adds the destination to the agent’s baseline so it is not flagged again. 5. If you want the agent kept to the places it already uses, choose Agent profile in the security mode menu, next to Home, Coffee shop, Paranoid and Under attack. Once the agent has finished learning, a connection to a destination outside its baseline is blocked instead of flagged. 6. A blocked destination shows in the AI agents card with Allow and Keep blocked. Allow adds it to the baseline and the agent can reach it right away. Keep blocked creates a block rule, so the destination stays blocked in every mode. > **Note:** The Agent profile security mode arrived in FireAI 1.0.3. While an agent is still learning nothing is blocked, and upload spikes are flagged, not blocked. An allow rule you wrote yourself for a website, domain or address still wins, and DNS and your local network are never blocked. > Want to see where Cursor connects on your Mac? FireAI is free to try. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Limits - FireAI does not prevent prompt injection. A prompt hidden in a web page or a file can still steer an agent. What FireAI can do is flag, and let you block, the path data would take out of your Mac. - FireAI cannot see prompts, the contents of MCP tools, or which files Cursor reads, such as ~/.ssh. TLS hides the payload, and FireAI is not inside the agent. - Child processes that exit very quickly may be missed, and child processes are matched by path, not by signature. - During the 3-day learning period nothing is flagged. - In the Agent profile mode, a connection to a bare IP address with no host name is matched by its address. If a service the agent normally uses answers from a new address, it is blocked until you allow it. - FireAI’s plain-words explanation of a flag is written from facts it measured. It never says a destination is safe or dangerous. The decision is yours. ## Related guides The same approach applies to the other agents FireAI recognises: [Claude Code](https://hisnlabs.com/en/blog/monitor-claude-code-network-mac-fireai), [the Claude desktop app](https://hisnlabs.com/en/blog/monitor-claude-desktop-app-network-mac-fireai), [the ChatGPT Mac app](https://hisnlabs.com/en/blog/monitor-chatgpt-mac-app-network-fireai), [Codex CLI](https://hisnlabs.com/en/blog/monitor-openai-codex-cli-network-mac-fireai), [OpenClaw](https://hisnlabs.com/en/blog/monitor-openclaw-network-mac-fireai), [Hermes Agent](https://hisnlabs.com/en/blog/monitor-hermes-agent-network-mac-fireai), [Gemini CLI](https://hisnlabs.com/en/blog/monitor-gemini-cli-network-mac-fireai), [GitHub Copilot CLI](https://hisnlabs.com/en/blog/monitor-github-copilot-cli-network-mac-fireai), [Amp](https://hisnlabs.com/en/blog/monitor-amp-agent-network-mac-fireai), [Qwen Code](https://hisnlabs.com/en/blog/monitor-qwen-code-network-mac-fireai), [opencode](https://hisnlabs.com/en/blog/monitor-opencode-network-mac-fireai), [Aider](https://hisnlabs.com/en/blog/monitor-aider-network-mac-fireai), [Goose](https://hisnlabs.com/en/blog/monitor-goose-agent-network-mac-fireai), [Crush](https://hisnlabs.com/en/blog/monitor-crush-agent-network-mac-fireai), [Windsurf](https://hisnlabs.com/en/blog/monitor-windsurf-network-mac-fireai), [Kiro](https://hisnlabs.com/en/blog/monitor-kiro-network-mac-fireai), [Trae](https://hisnlabs.com/en/blog/monitor-trae-network-mac-fireai), [Muse from Meta](https://hisnlabs.com/en/blog/monitor-muse-meta-network-mac-fireai), [any other AI agent run by Python or Node](https://hisnlabs.com/en/blog/monitor-any-ai-agent-mac-python-node-fireai). The full feature description is in the [Agent profile documentation](https://hisnlabs.com/en/docs/agent-profile). > FireAI is built by HisnLabs and runs on your Mac, with no cloud account. Download it and see which destinations your agents have contacted. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## How FireAI and HisnLabs fit in Cursor’s agent can run commands. FireAI shows where your Mac connects while it works. FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac. You can read the technical decisions behind it, or try FireAI for 17 days, at [FireAI, by HisnLabs](https://hisnlabs.com/en/download). ## Sources - [Cursor: Security](https://cursor.com/security) - [Cursor documentation: Run modes, sandboxing and agent security](https://cursor.com/docs/agent/security/run-modes) - [Cursor documentation: Network configuration (domains and protocols)](https://cursor.com/docs/enterprise/network-configuration) - [Cursor documentation: Terminal](https://cursor.com/docs/agent/terminal) - [FireAI docs: Agent profile](https://hisnlabs.com/en/docs/agent-profile) - [FireAI docs: Quick Review and Suggestions](https://hisnlabs.com/en/docs/quick-review-suggestions) - [FireAI docs: Security modes](https://hisnlabs.com/en/docs/security-modes)