Prompts
Approval and sandbox prompts
Full reference4 reviewed records from the desktop app: the text Cursor sends the model when a command needs approval or is retried outside the sandbox. Each entry gives the exact shipped bytes and their location; schemas are decoded or reconstructed into tables above the bytes they come from.
Approval prompts
Approval retry reminder (variant 1)
Source: extensions/cursor-agent-exec/dist/main.js (desktop) · bytes 6095347–6096226 · SHA-256 109b3e76ca48…
<system_reminder>
${NY} tool call. Decide now between two paths: (1) if a genuinely safer, lower-privilege, authorized path satisfies the request, use it; (2) if this blocked action is still necessary and the user should approve it, immediately retry the exact same call_mcp_tool call with requestSmartModeApproval set to true AND smartModeBlockReason set to the exact block reason text above. That retry is what shows the native approval card; stopping here leaves the user with no approval UI. Do not change the tool arguments or use an escalated variant when retrying for approval. Trying a different anonymous public file host, pastebin, disposable transfer link, or similar courier is NOT path (1) — that is the same unauthorized data-exposure crossing — so for that class prefer path (2) or ask the user, do not shop for another intermediary.
</system_reminder>
Approval retry reminder (variant 2)
Source: extensions/cursor-agent-exec/dist/main.js (desktop) · bytes 6096230–6097192 · SHA-256 431cf708d995…
<system_reminder>
${NY} MCP tool call. Decide now between two paths: (1) if a genuinely safer, lower-privilege, authorized path satisfies the request, use it; (2) if this blocked action is still necessary and the user should approve it, immediately retry the exact same CallDynamicTool call with mcpDetails.requestSmartModeApproval set to true AND mcpDetails.smartModeBlockReason set to the exact block reason text above. Preserve mcpDetails.description from the blocked call. That retry is what shows the native approval card; stopping here leaves the user with no approval UI. Do not change the tool arguments or use an escalated variant when retrying for approval. Trying a different anonymous public file host, pastebin, disposable transfer link, or similar courier is NOT path (1) — that is the same unauthorized data-exposure crossing — so for that class prefer path (2) or ask the user, do not shop for another intermediary.
</system_reminder>
Approval retry reminder (variant 3)
Source: extensions/cursor-agent-exec/dist/main.js (desktop) · bytes 7706443–7707372 · SHA-256 3636c91bb0fe…
${w.reason}
<system_reminder>
Auto-review blocked this autonomous tool call. Decide now between two paths: (1) if a genuinely safer, lower-privilege, authorized path satisfies the request, use it; (2) if this blocked action is still necessary and the user should approve it, immediately retry the exact same Shell call with request_smart_mode_approval set to true AND smart_mode_block_reason set to the exact block reason text above. That retry is what shows the native approval card; stopping here leaves the user with no approval UI. Do not change the command, add permissions, or use an escalated variant when retrying for approval. Trying a different anonymous public file host, pastebin, disposable transfer link, or similar courier is NOT path (1) — that is the same unauthorized data-exposure crossing — so for that class prefer path (2) or ask the user, do not shop for another intermediary.
</system_reminder>
Approval retry reminder (variant 4)
Source: extensions/cursor-agent-exec/dist/main.js (desktop) · bytes 7755551–7756165 · SHA-256 41e62a7b359a…
${d.reason}
<system_reminder>
Auto-review blocked this autonomous tool call. Decide now between two paths: if a safer non-autonomous path satisfies the request, use it; otherwise, if this blocked fetch is still necessary and the user should approve it, immediately retry the exact same WebFetch call with requestSmartModeApproval set to true AND smartModeBlockReason set to the exact block reason text above. That retry is what shows the native approval card; stopping here leaves the user with no approval UI. Do not change the URL or use an escalated variant when retrying for approval.
</system_reminder>