Skip to content

[Bug]: Cursor agent config not loaded — plugins, MCP servers, and skills are dropped #16431

Description

@NK-Works

Before submitting

  • I searched existing issues and did not find a duplicate (found related but distinct issues below — this is the umbrella covering the whole Cursor agent-config surface).
  • I included enough detail to reproduce or investigate the problem.

Area

apps/server — Cursor V2 provider (@cursor/sdk local-agent runtime)

Summary

All native Cursor agent configuration — user/plugin/project MCP servers, plugin skills, and disable-model-invocation skills — is effectively not loaded for Cursor threads started from T3 Code. settingSources is set correctly at Agent.create, but (1) every send re-passes mcpServers which the SDK treats as a full override, and (2) T3's own skill discovery only scans a fixed set of folder roots and never sees plugin skill dirs. Net effect: a Cursor thread in T3 behaves like a bare agent with only cursor + t3-code tools, while the same project opened in Cursor proper sees the full config.

Related / similar issues (checked, not duplicates)

Steps to reproduce

MCP half (from #15268, reproduced on main):

  1. Configure a user MCP server for Cursor, e.g. in ~/.cursor/mcp.json:
    {"mcpServers":{"datadog":{"url":"https://mcp.us3.datadoghq.com/api/unstable/mcp-server/mcp"}}}
    Authenticate it for the project folder so ~/.cursor/projects/<slug>/mcp-auth.json has tokens.
  2. Start a Cursor thread in T3 Code for that project.
  3. Ask the agent to call GetDynamicTools and list the namespaces.

Skills half (from #16408):

  1. Install a Cursor plugin that ships one or more skills (marketplace, team, or local under ~/.cursor/plugins/local). Confirm they appear in Cursor Customize and are invokable with /skill-name.
  2. Open a Cursor thread in T3 Code on a project.
  3. Open the $ skill picker, and ask the agent (without letting it read the filesystem) which skills are in its catalog.

Invocation half (from #15606):

  1. Put a skill in ~/.agents/skills/ whose frontmatter sets disable-model-invocation: true.
  2. Open a Cursor thread in T3 Code, send /grill-me <request> or $grill-me <request>.

Expected behavior

Cursor threads see everything Cursor proper loads through settingSources: ["project", "user", "team", "mdm", "plugins"] (#13499):

Actual behavior

  • Only cursor and t3-code appear in GetDynamicTools. Every ambient server is dropped with no error / needsAuth status.
  • The $ picker only lists folder skills. Plugin skills under ~/.cursor/plugins/cache/.../skills/ never enter the list, and the agent catalog has the same hole (confirmed with Grok 4.6/4.7 in [Bug]: Cursor plugin skills are missing from the composer and from the agent catalog #16408).
  • /grill-me reaches the model as plain text. All 10 disable-model-invocation: true skills in the repro folder are absent from the model-facing list, so the model has no way to look them up.

Detailed reason (code pointers on main)

  1. Send-level mcpServers replaces the workspace lease instead of merging.
    • makeCursorAgentOptions → Agent.create passes { mcpServers: { "t3-code": ... } } — apps/server/src/orchestration-v2/Adapters/CursorAdapterV2.ts:305-329, with cursorMcpServers() at :205-219 and settingSources: [...CURSOR_AGENT_SETTING_SOURCES] at :321.
    • Every turn re-passes the same object on agent.session.send({ options: { mcpServers } }) — CursorAdapterV2.ts:2205-2213.
    • In @cursor/sdk 1.0.31 that send-level value becomes mcpServersOverride for the run; the local session runtime then picks sessionLease ?? workspaceLease, where the session lease holds only the inline servers (includeUserMcp: false, includeProjectMcp: false, includePluginMcp: false). So the override replaces the workspace lease instead of adding to it. Direct SDK repro in [Bug]: Cursor threads lose all user, plugin, and project MCP servers because mcpServers is passed on every send #15268 shows send-1 (create-only) lists datadog, slack, plugin servers; send-2 (also passed on send, what T3 does) lists only cursor + inline. Possible fix per [Bug]: Cursor threads lose all user, plugin, and project MCP servers because mcpServers is passed on every send #15268: stop passing mcpServers on send, keep t3-code on Agent.create (keeping its per-thread auth header current through agent options), or upstream SDK merge fix.
  2. T3 skill discovery never scans plugin roots.
    • inspectCursorSkills() builds exactly 8 roots — apps/server/src/provider/Drivers/CursorSkills.ts:225-231:
      <cwd>/{.cursor,.agents,.codex,.claude}/skills + $HOME/{.cursor,.agents,.codex,.claude}/skills.
    • Plugin skills live under ~/.cursor/plugins/cache/<marketplace>/<plugin>/<sha>/skills/ (plus team/local plugin equivalents) and are never visited. Both the composer $ picker (snapshotForCwd → probeCursorSkills in apps/server/src/provider/Drivers/CursorDriver.ts:267-285) and rewriteCursorSkillMentions inherit the hole, so $name → /name rewriting also misses them. The SDK-side CursorPluginsAgentSkillsService exists but those skills never reach the model catalog either (see [Bug]: Cursor plugin skills are missing from the composer and from the agent catalog #16408).
  3. No expansion path for disable-model-invocation: true skills.

Impact

Major degradation or frequent failure — Cursor threads in T3 silently lose the user's entire Cursor customization layer (MCP integrations, plugin tools, plugin skills, invocation-only skills) with no error surfaced.

Version or commit

main @ 4dfe1a0444 (checked 2026-10-06); SDK references in tree are @cursor/sdk 1.0.31–1.0.35. Reporters confirmed on 0.0.46-nightly.20261003.2632 through 0.0.46-nightly.20261005.2702.

Environment

  • OS: Linux 6.12.111+deb13-amd64 (reporter environments in linked issues: macOS darwin 27.x, T3 Code Nightly desktop, Cursor V2 provider)
  • Node: v20.19.2 (repo-required 22.13+ for the SDK runtime path)
  • Provider: Cursor V2 / @cursor/sdk local-agent runtime, orchestrator v2

Logs or stack traces

Provider log for an affected thread shows correct settingSources yet no ambient servers (from #15268):

"local":{"hasCwd":true,"autoReview":false,"settingSources":["project","user","team","mdm","plugins"],"sandboxEnabled":false,"enableAgentRetries":true}

Across all provider logs, every MCP tool call uses providerIdentifier "t3-code" — no other server is ever reachable.

Workaround

  • MCP: none in T3 (direct SDK without send-level mcpServers loads correctly).
  • Plugin skills: copy/symlink each plugin skill dir into ~/.cursor/skills or ~/.agents/skills.
  • Invocation-only skills: reference the file directly (follow ~/.agents/skills/grill-me/SKILL.md) or remove disable-model-invocation.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    duplicateThis issue or pull request already exists

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions