Ecosystem Guides: MCP Server · Claude Code · Cursor · Local Agent · How It Works · All Docs
CirvixGuides / Cursor

Cursor,
under policy.

CIRVIX evaluates Cursor's agent tool calls locally before they execute.

Install

  1. npm install -g @cirvix_ai/agent-control

Init

  1. cirvix init

Connect

  1. cirvix runtime # local enforcement endpoint on a unix socket / named pipe
  2. # route Cursor's shell and edit tools through the local endpoint

Policy

  1. cirvix policy check

Test — watch a decision

With Claude Code running under CIRVIX, ask it to read a credential file such as ~/.aws/credentials. The read is denied by policy before it happens, an audit event is written, and the agent sees a structured denial instead of your secrets.

Verify

Run cirvix logs to see the decision record: action normalized, rule matched, decision DENY, payload redacted. A legitimate workspace read shows PERMIT. If both behave that way, Claude Code is under control.

Install Free See the Attack Lab

Copied to clipboard