Secure Cursor agents with a local MCP execution gateway

Cursor’s agent mode executes multi-step plans with write access to your repo and shell. It does not know your infrastructure boundaries, your compliance windows, or which database is production — and rules files are advisory, not enforced.

Mergen sits between Cursor and your systems as a local MCP proxy. Policy is evaluated deterministically in under 1ms per call — no LLM in the critical path, no cloud round-trip, and all data stays on your machine.

What is covered, precisely

Set up in two minutes

Install the server
npm install -g mergen-server
Configure Cursor (writes .cursor/mcp.json)
mergen-server setup
Start the gate
mergen-server start

What gets stopped

rm -rf / (and obfuscated variants)
Hard safety policy; the benchmark corpus tracks obfuscation and encoding evasions.
kubectl delete namespace production
Blast-radius rules distinguish a namespace delete from a pod restart.
aws iam create-access-key
Credential-surface changes escalate to HOLD for human review.

Human-in-the-loop approvals

Held calls fire a Slack webhook with one-click approve/deny. The Promise stays suspended until a human decides (or the 15-minute fail-closed auto-deny fires), then Cursor’s call resumes or receives a structured denial.

Install Mergen →Quick start guide →See the benchmark →
Also available for: Claude Code · Windsurf · VS Code · GitHub Actions