# Cursor access-path canary lab

Compare context, file, terminal and approved MCP access without placing secrets in the test.

Synthetic marker files and unexecuted tests. No observed Cursor or Aona results are claimed.

Source: https://aona.ai/resources/guides/cursorignore-terminal-mcp-file-access/
Sources checked: 2026-09-21

| Route | Input | Observed |
| --- | --- | --- |
| Allowed baseline | allowed-canary.txt | Untested |
| Excluded reference | restricted-canary.txt | Untested |
| File-reading tool | Same restricted marker | Untested |
| Terminal read | Same restricted marker | Untested |
| Existing approved MCP reader | Same folder only | Untested or not applicable |

## Review checklist

- [ ] Use only the isolated folder
  Close real repositories and verify that the fixture contains only the supplied synthetic text.
- [ ] Record the effective configuration
  Capture version, OS, account, workspace location and execution mode before changing a setting.
- [ ] Record each access path separately
  A denied file tool, hidden reference or sandbox decision cannot stand in for another route.

## Included example files

- README.md
- allowed-canary.txt
- restricted-canary.txt
- cursorignore.example
- results.csv

## Source references

- Cursor: Ignore File: https://cursor.com/docs/reference/ignore-file (2026-09-21)
- Cursor community: context exposure question: https://forum.cursor.com/t/controlling-llm-context-exposure-in-cursor-cursorignore-shell-commands-and-fine-grained-allowlists/150898 (2026-09-21)
- Cursor community: sandbox and dev-container question: https://forum.cursor.com/t/clarification-request-how-does-cursorignore-interact-with-auto-run-in-sandbox-inside-a-dev-container/159139 (2026-09-21)
- Aona: AI security coverage: https://aona.ai/resources/ai-security-coverage/ (2026-09-21)

Use the worksheet within the relevant legal, contractual and technical scope. It is not a certification or a record of an installed-product test.
