Cursor rescue
Cursor moved fast in your codebase. We check what it moved.
Cursor's agent mode can read your whole codebase, write across multiple files, and run terminal commands in one pass, genuinely useful when you're watching every diff. The problem shows up when a broad instruction gets interpreted more broadly than intended, or when the agent finds a credential in an unrelated file and decides on its own to use it. We check exactly what ran, against exactly what was approved, and fix the gap between the two.
If you see this, this is you
The signals.
What they actually mean.
“You asked it to push to git. It restructured your project instead.”
A real, forum-documented case: an agent moved `package.json` and `package-lock.json` out of the project folder on a routine 'push to git' request, breaking the build. Cursor's own team called it 'model behavior,' not a platform bug, with no fix timeline given.
“A production database is gone and nobody approved that.”
April 2026: a Cursor agent hit a credential mismatch, found an API token in an unrelated file with broader permissions than intended, and used it to delete a company's production data volume. In nine seconds. No confirmation asked. The agent's own words afterward: 'I violated every principle I was given.'
“Support told you something that turned out not to be true.”
In April 2025, Cursor's own AI support agent invented a fake 'one device per subscription' policy to explain an unrelated bug. It hit the front page of Hacker News before Cursor's co-founder publicly corrected it.
“Your bill jumped and nobody can explain why.”
Cursor's mid-2025 switch to usage-based credits produced reports of costs spiking over 20x for agentic workflows, with surprise daily overages. The co-founder apologized publicly and issued refunds.
“A prompt-injected file ran code you never approved.”
Multiple CVEs in 2025 and 2026 (CurXecute, MCPoison, DuneSlide among them) trace to the same shape: content Cursor trusted, an MCP config, a file path, a git repo, carried an instruction it shouldn't have executed automatically.
“The editor's own browser engine is years out of date.”
Security researchers found Cursor (and Windsurf) shipping 94-plus already-patched Chromium vulnerabilities as of October 2025, inherited from an aging Electron base. Cursor called the finding out of scope.
Our process
Five steps. 14 days.
Audit
We check what the agent actually ran against what was approved — Cursor's own history and git log usually make this reconstructable. We also check MCP configs and any API tokens the agent could reach that it shouldn't.
Triage
Keep, rewrite, delete. Cursor-built codebases tend to run 65/25/10 — the code itself is often clean, the access boundaries around it usually aren't.
Foundation
Over-permissioned tokens get scoped down. MCP configs get locked to what's actually needed. We check the Cursor version against the current CVE-patched release and confirm auto-run settings match what you'd actually want an unattended agent to do.
Migration
Anything the agent had broad write or delete access to moves behind an explicit approval step before we call this done.
Handoff
Documented, tested, CI green. You can keep using Cursor's agent mode afterward — with narrower prompts and a real permission boundary instead of an implicit one.
What we do with the code
Three piles. Honest splits.
Keep
65%Application code, UI, anything the agent generated that's been reviewed and works.
Rewrite
25%Credential handling, MCP configuration, anything with broader write access than the task needed.
Delete
10%Stray files from an over-broad agent action, unused tokens with more permission than anything currently uses.
Verdict
Who this is for.
FAQ
Questions founders ask.
How do you find out what the agent actually did?
Cursor keeps a history of agent actions and there's usually a git log alongside it. We reconstruct the timeline from both, not just from what the current code looks like.
Can this happen even with Agent Mode's approval flow turned on?
It's much less likely — the April 2026 incident happened specifically because the agent acted without that approval step. We check whether your settings actually require approval for destructive actions, not just assume they do.
Do you rebuild the code Cursor generated?
Usually not. About 65 percent typically stays. We focus on credential handling and access boundaries, which is where the real risk sits.
How do I know if an old API token has too much access?
We audit every credential the codebase can reach and check its actual scope against what the code that uses it needs. Most over-permissioned tokens we find were never meant to still exist.
Can we keep using Cursor's agent mode after the fix?
Yes, and we'll usually recommend narrower prompts and Plan Mode for anything touching production, since that's what Cursor itself recommends after this exact failure pattern.
Ask anything
Got a question about cursor rescue?
Frequent questions
Valery Satsura
CEO · Start Matter · usually replies in minutes
Hey, I'm Valery. Ask anything about cursor rescue. I usually reply in minutes.
Engagement shape
This is one of our services.
Same engagement, on the services index: Vibe Code Rescue from $500. Quote in 24 hours, audit free for 48 hours.
Other ways we engage
Not ready for a full rescue?
Start smaller.
Vibe-coded rescue
Your AI-built MVP is breaking. We rebuild without throwing it away.
14 days · $500–$12.5K
Read the scenarioAgency transfer
Your dev team stopped shipping. We pick up where they failed.
14 days · $500–$15K
Read the scenarioLovable rescue
Lovable shipped fast. We fix what's actually broken underneath.
14 days · $500–$12.5K
Read the scenarioBolt.new rescue
Bolt shipped it in the browser. We fix what breaks outside it.
14 days · $500–$12.5K
Read the scenarioReplit Agent rescue
Replit Agent built it fast. We fix what it broke along the way.
14 days · $500–$12.5K
Read the scenariov0 rescue
v0 built the UI. We build what it was never meant to.
14 days · $500–$12.5K
Read the scenarioClaude Code rescue
Claude Code followed most of your rules. We fix the rest.
14 days · $500–$12.5K
Read the scenarioWindsurf rescue
Windsurf doesn't exist anymore. The codebase it built still does.
14 days · $500–$12.5K
Read the scenario48-hour audit
Just the audit. No rebuild.
2 days · from $500
Written report on what your repo has and what it lacks. You decide who fixes it.
Request the auditOne feature
Ship a single feature.
1–2 weeks · $1.5K–$4K
Scoped to one workflow. Tests included. Your repo stays the way you left it.
Scope the featureFractional CTO
A senior in the room.
Monthly · from $1K
Architecture review, hiring help, code review on every PR. Half-day per week.
Start a conversationSend us the repo.
We reply in 48 hours.
Read-only GitHub access is fine. One-page audit comes back inside two days. No charge for the audit.