PRAE for the agent in Cursor.

In part

Cursor’s agent reads files, runs commands and calls MCP tools with a developer’s access. Today PRAE governs the file access you route through its MCP server, and reads the .cursorrules it follows as proposed policy.

Serves: Developer agents →

  1. 01 · Where the agent operates

    Cursor

  2. 02 · What it can reach

    The repository and files on the developer’s machine, the terminal, and the MCP servers it is configured with.

  3. 03 · Where PRAE intervenes

    At PRAE’s MCP server: file reads routed through it are judged before contents return.

04 · What PRAE does: Evaluate → Enforce → Steer → Prove

  1. Evaluate

    Each file read the agent routes through PRAE’s MCP server is judged against your pack before it runs. The .cursorrules it follows is read and proposed as rules you review.

  2. Enforce

    A refused read returns nothing: the file’s contents never reach the model, and the agent is told why.

  3. Steer

    Not on this surface yet.

  4. Prove

    Every decision is sealed in the hash-chained, signed ledger, with the rule that produced it.

05 · What you get, and how it plugs in

  1. Register PRAE’s MCP server in Cursor npx -p prae-cli prae mcp --root <workspace> --pack <policy.json> --ledger <decisions.jsonl>
  2. Read the rules it follows prae instructions . && prae propose .

File reads and listings routed through PRAE’s MCP server; .cursorrules read and proposed as rules.

Cursor’s own built-in tools (its terminal, its editor writes, other MCP servers) are not intercepted yet; that is on the roadmap.