分发 permissions.json
通过受管文件设置命令与 MCP 允许范围,区分合并和管理端覆盖。
可用 MDM 将 permissions.json 写到用户 Cursor 目录,集中分发终端/MCP allowlist 和 Auto-review 指令。它是普通文件,项目文件仍可能参与合并,不能把单独分发用户文件等同不可扩展的硬边界。
路径与格式
读取 ~/.cursor/permissions.json 与 <workspace>/.cursor/permissions.json。可选 terminalAllowlist、mcpAllowlist、autoRun。
{
"terminalAllowlist": ["pnpm test", "python -m pytest"],
"mcpAllowlist": ["github:create_pull_request", "*:search"],
"autoRun": {
"block_instructions": ["Block any command that drops or truncates a database table."]
}
}terminalAllowlist 按完整 command string 匹配。未列出的受支持终端调用仍可在启用的沙箱执行,不等于一律禁止。普通 Run Mode 的终端 sandbox 不自动包住 MCP;Enterprise 的服务器级策略可另为本地 stdio MCP 配置 sandbox,见MCP 治理。
MCP 匹配
server:tool 指单个工具,server:* 指 server 全部工具,:tool 指所有 server 同名工具,:* 指全部工具。按需要选择最小范围,不把空数组当作 deny-all。
优先级和回退
- Team dashboard 或其他 admin-controlled settings。
- 用户与项目 permissions.json 的拼接结果。
- 编辑器 settings 和 Add to allowlist。
管理端按类别替换文件值;两个文件拼接,编辑器值不与文件合并。某 key 缺失或拼接后为空,则该类别回退编辑器允许列表。文件受监控,修改无需重启。
Auto-review
autoRun 的 allow_instructions/block_instructions 为自然语言数组,用于影响分类器,Cursor 3.6+ 适用于 shell、MCP 和 Fetch。它不替代系统级沙箱或外部工具本身的权限,分类器行为见Auto-review。