Agent governance

Cursor Agent Hooks: govern prompts, tools, and effects

Model routing sees what reaches the model. Cursor Agent Hooks see what the agent does on the developer machine. Together they cover the request and the work that follows it.

By Munis Badar · ·

Why model routing is only half the control

An AI coding agent can ask a model for a plan, then read files, run a shell command, call an MCP server, or write a file locally. A gateway that sees only model traffic cannot refuse the command before it runs. Cursor hooks add that second control point while keeping policy in AI-FW.

What AI-FW can decide

The integration applies the same rules and tool governance model to Cursor events, with observe-first behavior so teams can understand usage before enabling blocking.

  • Scan prompts and file content before they reach the model
  • Govern shell, MCP, tool, file-read, tab-read, and subagent events
  • Attribute decisions to an API key, agent label, and owner
  • Correlate prompts, tools, and effects with a conversation ID

Start with visibility

Enable Cursor Agent Hooks from AI Firewall -> Agent Config -> Integrations, begin with capture and observe-only governance, and review the Skills & Tools and Artifacts pages before selecting a blocking posture. This avoids treating an empty allow-list as an accidental deny policy.

Read the implementation guide

The public hook package includes a hooks.json template plus Node and Python shims. The detailed guide explains scopes, credentials, repeat-window deduplication, failure posture, and privacy boundaries.