Cursor hooks: govern what Cursor's agent can do
Cursor runs hooks from .cursor/hooks.json around tool calls. npx @scopebond/hook@latest init --cursor registers a Scopebond hook on beforeShellExecution, beforeMCPExecution, beforeReadFile and afterFileEdit. Each action is checked against your policy; an out-of-policy action is denied once you turn its rule on (rules enforce <rule>; until then it is recorded), and everything is recorded into a signed, offline-verifiable receipt — the same policy and record you use for Claude Code.
On Windows, type npx.cmd instead of npx in PowerShell: its default script policy blocks npx, and npx.cmd works in PowerShell and Command Prompt alike.
1. Install for Cursor
The installer auto-detects Cursor; you can also name it explicitly:
npx @scopebond/hook@latest init --cursor # or: scopebond install (detects Cursor)
2. One policy, both agents
The same .scopebond/policy.json governs Claude Code and Cursor. A developer install (npm i -g @scopebond/hook@latest then scopebond install) registers the hook once per machine, and a project-local policy still takes precedence.
3. See the decisions
scopebond-hook log
scopebond-hook verify
What this does not do
The hook checks actions Cursor sends through its tool system. An action taken outside the hook is not covered. Scopebond decides on typed actions and does not read your code or classify content.
Alternatives
- Cursor's own hooks and privacy/agent settings — native controls; Scopebond adds a portable policy and a signed record shared with Claude Code and GitHub.
FAQ
Do I need a separate policy for Cursor?
No. The same policy file governs Cursor and Claude Code; install once per machine and each project you open is governed.
Which Cursor events are covered?
beforeShellExecution, beforeMCPExecution, beforeReadFile and afterFileEdit — the hook maps each to a normalized action and checks it against your policy.
Last verified 2026-09-22. Commands are covered by the public repo's tests (packages/hook/test/map.test.mjs).