Install
$ agentstack add skill-kensaurus-cursor-kenji-update-cli-config ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Cursor CLI Configuration
This skill explains how to view and modify Cursor CLI settings stored in ~/.cursor/cli-config.json.
Config File Location
The config file is ~/.cursor/cli-config.json.
Projects can layer overrides via .cursor/cli.json files. The CLI walks from the git root to the current working directory and merges each .cursor/cli.json it finds (deeper files take precedence). Project overrides only affect the current session; they are not written back to the home config.
How to Modify
Read ~/.cursor/cli-config.json, apply changes, and write it back. The file is standard JSON. Changes take effect after restarting the CLI.
Available Settings
permissions (required)
Tool permission rules. Each entry is a string pattern.
allow: string[] — patterns for allowed tool calls (e.g."Shell(**)","Mcp(server-name, tool-name)")deny: string[] — patterns for denied tool calls
editor
vimMode: boolean — enable vim keybindings in the CLI inputdefaultBehavior:"ide"|"agent"— default behavior mode
display (optional)
showLineNumbers: boolean (default: false) — show line numbers in code outputshowThinkingBlocks: boolean (default: false) — show model thinking/reasoning blocksshowStatusIndicators: boolean (default: false) — show status indicators in the UI
channel (optional)
Release channel: "prod" | "staging" | "lab" | "static"
maxMode (optional)
boolean (default: false) — enable max mode for higher-quality model responses
approvalMode (optional)
Controls tool approval behavior:
"allowlist"(default) — require approval for tools not in the allow list"unrestricted"— auto-approve all tool calls (yolo mode)
sandbox (optional)
Sandbox execution environment settings:
mode:"disabled"|"enabled"(default:"disabled")networkAccess:"user_config_only"|"user_config_with_defaults"|"allow_all"— controls network access from sandboxnetworkAllowlist: string[] — domains the sandbox is allowed to reach
network (optional)
useHttp1ForAgent: boolean (default: false) — use HTTP/1.1 instead of HTTP/2 for agent connections (enables SSE-based streaming)
bedrock (optional)
AWS Bedrock integration settings:
enabled: boolean (default: false)mode:"access-key"|"team-role"(default:"access-key")region: string — AWS regiontestModel: string — model to use for testingteamRoleArn: string — IAM role ARN for team modeteamExternalId: string — external ID for STS assume-role
attribution (optional)
Controls how agent work is attributed in git:
attributeCommitsToAgent: boolean (default: true) — attribute commits to the agentattributePRsToAgent: boolean (default: true) — attribute PRs to the agent
webFetchDomainAllowlist (optional)
string[] — domains the web fetch tool is allowed to access (e.g. "docs.github.com", "*.example.com", "*")
Fields You Should NOT Modify
These are internal/cached state and should not be edited manually:
version— config schema versionmodel/selectedModel/modelParameters/hasChangedDefaultModel— managed by the model pickerprivacyCache— cached privacy mode stateauthInfo— cached authentication infoshowSandboxIntro— one-time UI flagconversationClassificationScoredConversations— internal cache
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: kensaurus
- Source: kensaurus/cursor-kenji
- License: MIT
- Homepage: https://github.com/kensaurus/cursor-kenji
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.