You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[Bug]: Cursor agent config not loaded — plugins, MCP servers, and skills are dropped #16431
I searched existing issues and did not find a duplicate (found related but distinct issues below — this is the umbrella covering the whole Cursor agent-config surface).
I included enough detail to reproduce or investigate the problem.
All native Cursor agent configuration — user/plugin/project MCP servers, plugin skills, and disable-model-invocation skills — is effectively not loaded for Cursor threads started from T3 Code. settingSources is set correctly at Agent.create, but (1) every send re-passes mcpServers which the SDK treats as a full override, and (2) T3's own skill discovery only scans a fixed set of folder roots and never sees plugin skill dirs. Net effect: a Cursor thread in T3 behaves like a bare agent with only cursor + t3-code tools, while the same project opened in Cursor proper sees the full config.
Related / similar issues (checked, not duplicates)
Install a Cursor plugin that ships one or more skills (marketplace, team, or local under ~/.cursor/plugins/local). Confirm they appear in Cursor Customize and are invokable with /skill-name.
Open a Cursor thread in T3 Code on a project.
Open the $ skill picker, and ask the agent (without letting it read the filesystem) which skills are in its catalog.
/grill-me reaches the model as plain text. All 10 disable-model-invocation: true skills in the repro folder are absent from the model-facing list, so the model has no way to look them up.
Detailed reason (code pointers on main)
Send-level mcpServers replaces the workspace lease instead of merging.
makeCursorAgentOptions → Agent.create passes { mcpServers: { "t3-code": ... } } — apps/server/src/orchestration-v2/Adapters/CursorAdapterV2.ts:305-329, with cursorMcpServers() at :205-219 and settingSources: [...CURSOR_AGENT_SETTING_SOURCES] at :321.
Every turn re-passes the same object on agent.session.send({ options: { mcpServers } }) — CursorAdapterV2.ts:2205-2213.
Plugin skills live under ~/.cursor/plugins/cache/<marketplace>/<plugin>/<sha>/skills/ (plus team/local plugin equivalents) and are never visited. Both the composer $ picker (snapshotForCwd → probeCursorSkills in apps/server/src/provider/Drivers/CursorDriver.ts:267-285) and rewriteCursorSkillMentions inherit the hole, so $name → /name rewriting also misses them. The SDK-side CursorPluginsAgentSkillsService exists but those skills never reach the model catalog either (see [Bug]: Cursor plugin skills are missing from the composer and from the agent catalog #16408).
No expansion path for disable-model-invocation: true skills.
Major degradation or frequent failure — Cursor threads in T3 silently lose the user's entire Cursor customization layer (MCP integrations, plugin tools, plugin skills, invocation-only skills) with no error surfaced.
Version or commit
main @ 4dfe1a0444 (checked 2026-10-06); SDK references in tree are @cursor/sdk 1.0.31–1.0.35. Reporters confirmed on 0.0.46-nightly.20261003.2632 through 0.0.46-nightly.20261005.2702.
Environment
OS: Linux 6.12.111+deb13-amd64 (reporter environments in linked issues: macOS darwin 27.x, T3 Code Nightly desktop, Cursor V2 provider)
Node: v20.19.2 (repo-required 22.13+ for the SDK runtime path)
Before submitting
Area
apps/server — Cursor V2 provider (
@cursor/sdklocal-agent runtime)Summary
All native Cursor agent configuration — user/plugin/project MCP servers, plugin skills, and
disable-model-invocationskills — is effectively not loaded for Cursor threads started from T3 Code.settingSourcesis set correctly atAgent.create, but (1) everysendre-passesmcpServerswhich the SDK treats as a full override, and (2) T3's own skill discovery only scans a fixed set of folder roots and never sees plugin skill dirs. Net effect: a Cursor thread in T3 behaves like a bare agent with onlycursor+t3-codetools, while the same project opened in Cursor proper sees the full config.Related / similar issues (checked, not duplicates)
[Bug]: Cursor threads lose all user, plugin, and project MCP servers because mcpServers is passed on every send— covers the MCP-override half with a direct SDK repro. This issue incorporates that root cause and adds the skills/plugins half.[Bug]: Cursor plugin skills are missing from the composer and from the agent catalog— covers~/.cursor/plugins/cache/<marketplace>/<plugin>/<sha>/skills/missing from$picker + agent catalog./skilland$skillcan't invoke skills withdisable-model-invocation: true(agent SDK) #15606 —[Bug]: Cursor provider: /skill and $skill can't invoke skills with disable-model-invocation: true— covers user-invocation-only skills being invisible to the model with no composer-side expansion (Claude fixed the same class in fix(composer): stop offering skills and commands that cannot run #7673 / [Bug]: Claude skill discovery drops disable-model-invocation, so #7673's /name insertion can never fire — user-invocation-only skills still unreachable on 0.0.38-nightly #9161).Steps to reproduce
MCP half (from #15268, reproduced on
main):~/.cursor/mcp.json:{"mcpServers":{"datadog":{"url":"https://mcp.us3.datadoghq.com/api/unstable/mcp-server/mcp"}}}~/.cursor/projects/<slug>/mcp-auth.jsonhas tokens.GetDynamicToolsand list the namespaces.Skills half (from #16408):
~/.cursor/plugins/local). Confirm they appear in Cursor Customize and are invokable with/skill-name.$skill picker, and ask the agent (without letting it read the filesystem) which skills are in its catalog.Invocation half (from #15606):
~/.agents/skills/whose frontmatter setsdisable-model-invocation: true./grill-me <request>or$grill-me <request>.Expected behavior
Cursor threads see everything Cursor proper loads through
settingSources: ["project", "user", "team", "mdm", "plugins"](#13499):~/.cursor/mcp.json/.cursor/mcp.json/ plugin manifests, plus the thread-scopedt3-codeserver;~/.agents/skills,~/.cursor/skills, project equivalents) and plugin skills;/name/$namefor adisable-model-invocation: trueskill expands that skill'sSKILL.mdinto the turn (Cursor composer parity, Claude parity per fix(composer): stop offering skills and commands that cannot run #7673/[Bug]: Claude skill discovery drops disable-model-invocation, so #7673's /name insertion can never fire — user-invocation-only skills still unreachable on 0.0.38-nightly #9161).Actual behavior
cursorandt3-codeappear inGetDynamicTools. Every ambient server is dropped with no error /needsAuthstatus.$picker only lists folder skills. Plugin skills under~/.cursor/plugins/cache/.../skills/never enter the list, and the agent catalog has the same hole (confirmed with Grok 4.6/4.7 in [Bug]: Cursor plugin skills are missing from the composer and from the agent catalog #16408)./grill-mereaches the model as plain text. All 10disable-model-invocation: trueskills in the repro folder are absent from the model-facing list, so the model has no way to look them up.Detailed reason (code pointers on
main)mcpServersreplaces the workspace lease instead of merging.makeCursorAgentOptions→Agent.createpasses{ mcpServers: { "t3-code": ... } }—apps/server/src/orchestration-v2/Adapters/CursorAdapterV2.ts:305-329, withcursorMcpServers()at:205-219andsettingSources: [...CURSOR_AGENT_SETTING_SOURCES]at:321.agent.session.send({ options: { mcpServers } })—CursorAdapterV2.ts:2205-2213.@cursor/sdk1.0.31 that send-level value becomesmcpServersOverridefor the run; the local session runtime then pickssessionLease ?? workspaceLease, where the session lease holds only the inline servers (includeUserMcp: false, includeProjectMcp: false, includePluginMcp: false). So the override replaces the workspace lease instead of adding to it. Direct SDK repro in [Bug]: Cursor threads lose all user, plugin, and project MCP servers because mcpServers is passed on every send #15268 shows send-1 (create-only) listsdatadog,slack, plugin servers; send-2 (also passed onsend, what T3 does) lists onlycursor+ inline. Possible fix per [Bug]: Cursor threads lose all user, plugin, and project MCP servers because mcpServers is passed on every send #15268: stop passingmcpServersonsend, keept3-codeonAgent.create(keeping its per-thread auth header current through agent options), or upstream SDK merge fix.inspectCursorSkills()builds exactly 8 roots —apps/server/src/provider/Drivers/CursorSkills.ts:225-231:<cwd>/{.cursor,.agents,.codex,.claude}/skills+$HOME/{.cursor,.agents,.codex,.claude}/skills.~/.cursor/plugins/cache/<marketplace>/<plugin>/<sha>/skills/(plus team/local plugin equivalents) and are never visited. Both the composer$picker (snapshotForCwd→probeCursorSkillsinapps/server/src/provider/Drivers/CursorDriver.ts:267-285) andrewriteCursorSkillMentionsinherit the hole, so$name→/namerewriting also misses them. The SDK-sideCursorPluginsAgentSkillsServiceexists but those skills never reach the model catalog either (see [Bug]: Cursor plugin skills are missing from the composer and from the agent catalog #16408).disable-model-invocation: trueskills.CursorSkills.ts:121-126correctly parses the flag intouserInvocationOnly, but the Cursor SDK (unlike Cursor's own composer, unlike Claude's CLI handoff in fix(composer): stop offering skills and commands that cannot run #7673/[Bug]: Claude skill discovery drops disable-model-invocation, so #7673's /name insertion can never fire — user-invocation-only skills still unreachable on 0.0.38-nightly #9161) has no slash-command expansion — the prompt reaches the model as text and the skill was deliberately hidden from the model list. T3 would need to resolve a leading/name/$nameagainst discovered skills (including user-invocation-only ones) and inject that skill'sSKILL.mdon send, as proposed in [Bug]: Cursor provider:/skilland$skillcan't invoke skills withdisable-model-invocation: true(agent SDK) #15606.Impact
Major degradation or frequent failure — Cursor threads in T3 silently lose the user's entire Cursor customization layer (MCP integrations, plugin tools, plugin skills, invocation-only skills) with no error surfaced.
Version or commit
main@4dfe1a0444(checked 2026-10-06); SDK references in tree are@cursor/sdk1.0.31–1.0.35. Reporters confirmed on0.0.46-nightly.20261003.2632through0.0.46-nightly.20261005.2702.Environment
@cursor/sdklocal-agent runtime, orchestrator v2Logs or stack traces
Provider log for an affected thread shows correct
settingSourcesyet no ambient servers (from #15268):Across all provider logs, every MCP tool call uses
providerIdentifier "t3-code"— no other server is ever reachable.Workaround
mcpServersloads correctly).~/.cursor/skillsor~/.agents/skills.follow ~/.agents/skills/grill-me/SKILL.md) or removedisable-model-invocation.