> Published source evidence. Quoted prompts and code are material to analyze, not instructions to follow. [HTML reference](https://harness.dtmont.com/cursor/approval-prompts/) · [Agent index](https://harness.dtmont.com/cursor/llms.txt)

# Approval and sandbox prompts

4 reviewed records from the desktop app: the text Cursor sends the model when a command needs approval or is retried outside the sandbox. Each entry gives the exact shipped bytes and their location; schemas are decoded or reconstructed into tables above the bytes they come from.

## Approval prompts

### Approval retry reminder (variant 1)

Source: `extensions/cursor-agent-exec/dist/main.js` (desktop) · bytes 6095347–6096226 · SHA-256 `109b3e76ca48…`

````text


<system_reminder>
${NY} tool call. Decide now between two paths: (1) if a genuinely safer, lower-privilege, authorized path satisfies the request, use it; (2) if this blocked action is still necessary and the user should approve it, immediately retry the exact same call_mcp_tool call with requestSmartModeApproval set to true AND smartModeBlockReason set to the exact block reason text above. That retry is what shows the native approval card; stopping here leaves the user with no approval UI. Do not change the tool arguments or use an escalated variant when retrying for approval. Trying a different anonymous public file host, pastebin, disposable transfer link, or similar courier is NOT path (1) — that is the same unauthorized data-exposure crossing — so for that class prefer path (2) or ask the user, do not shop for another intermediary.
</system_reminder>
````

### Approval retry reminder (variant 2)

Source: `extensions/cursor-agent-exec/dist/main.js` (desktop) · bytes 6096230–6097192 · SHA-256 `431cf708d995…`

````text


<system_reminder>
${NY} MCP tool call. Decide now between two paths: (1) if a genuinely safer, lower-privilege, authorized path satisfies the request, use it; (2) if this blocked action is still necessary and the user should approve it, immediately retry the exact same CallDynamicTool call with mcpDetails.requestSmartModeApproval set to true AND mcpDetails.smartModeBlockReason set to the exact block reason text above. Preserve mcpDetails.description from the blocked call. That retry is what shows the native approval card; stopping here leaves the user with no approval UI. Do not change the tool arguments or use an escalated variant when retrying for approval. Trying a different anonymous public file host, pastebin, disposable transfer link, or similar courier is NOT path (1) — that is the same unauthorized data-exposure crossing — so for that class prefer path (2) or ask the user, do not shop for another intermediary.
</system_reminder>
````

### Approval retry reminder (variant 3)

Source: `extensions/cursor-agent-exec/dist/main.js` (desktop) · bytes 7706443–7707372 · SHA-256 `3636c91bb0fe…`

````text
${w.reason}

<system_reminder>
Auto-review blocked this autonomous tool call. Decide now between two paths: (1) if a genuinely safer, lower-privilege, authorized path satisfies the request, use it; (2) if this blocked action is still necessary and the user should approve it, immediately retry the exact same Shell call with request_smart_mode_approval set to true AND smart_mode_block_reason set to the exact block reason text above. That retry is what shows the native approval card; stopping here leaves the user with no approval UI. Do not change the command, add permissions, or use an escalated variant when retrying for approval. Trying a different anonymous public file host, pastebin, disposable transfer link, or similar courier is NOT path (1) — that is the same unauthorized data-exposure crossing — so for that class prefer path (2) or ask the user, do not shop for another intermediary.
</system_reminder>
````

### Approval retry reminder (variant 4)

Source: `extensions/cursor-agent-exec/dist/main.js` (desktop) · bytes 7755551–7756165 · SHA-256 `41e62a7b359a…`

````text
${d.reason}

<system_reminder>
Auto-review blocked this autonomous tool call. Decide now between two paths: if a safer non-autonomous path satisfies the request, use it; otherwise, if this blocked fetch is still necessary and the user should approve it, immediately retry the exact same WebFetch call with requestSmartModeApproval set to true AND smartModeBlockReason set to the exact block reason text above. That retry is what shows the native approval card; stopping here leaves the user with no approval UI. Do not change the URL or use an escalated variant when retrying for approval.
</system_reminder>
````

