Cursor Auto-review mode and paid Sume tool calls: keep dry_run on

Cursor's Auto-review classifier can allow a call you would block. For paid Sume tools, rely on server-side dry_run, max_spend_usd and OAuth scope.

5 min readSume
All posts

Should Cursor's Auto-review mode be trusted to stop a paid Sume generation? Not on its own. Cursor's docs say the Auto-review classifier can make mistakes: it can allow a call you would have blocked, or block one you would have allowed (Cursor run modes, read 2026-10-04). For a call that spends credits, put the limit on the server side, where it applies in every run mode.

Sume gives you three such limits on its hosted MCP: the OAuth scope you granted, dry_run, and max_spend_usd.

What Auto-review does, per Cursor

In Auto-review mode, allowlisted calls run immediately, other shell commands run in a sandbox when possible, and calls that do not use the sandbox go to the Auto-review classifier. The classifier uses Cursor-managed models, listed as Gemini 3.5 Flash Lite with Claude 4.5 Haiku as the fallback, and it can make read-only file and search calls on your machine to judge a request.

Cursor's MCP page adds that Cursor asks for approval before using MCP tools by default, and that MCP follows the same run modes as terminal commands (Cursor MCP docs, read 2026-10-04). So a Sume tool call is judged by whichever mode you picked.

Where Sume's limits sit

Sume's gates do not depend on the client's judgment. Under OAuth, a session with only mcp:read sees read-only tools, and a mutating call returns insufficient_scope. There is no mcp:paid scope, so paid tools need mcp:write or an API key. idempotency_key is required on write and paid tools, and it is dedup, not human approval (MCP tools and gates).

Who enforces what when Cursor calls a paid Sume tool. Sources: Cursor docs and Sume docs, read 2026-10-04.
LayerWhat it doesCan it be wrong?
Cursor Auto-review classifierJudges the call, per CursorYes, Cursor says it can allow or block wrongly
Sume OAuth scopeHides write and paid tools without mcp:writeNo: a missing scope refuses the call
dry_run=truePreviews admission and cost, submits nothingOnly if the agent skips it
max_spend_usdCaps the call, enforced only when sentOnly if the agent omits it

A setup that holds under Auto-review

Connect with OAuth and leave the Write toggle off for exploration. When a task needs generation, reconnect with Write on, and tell the agent to preview first. Calling generation_admission_preview or the paid tool with dry_run=true shows the estimate and balance before anything is submitted.

  • Exploration session: OAuth mcp:read only, and read tools only.
  • Generation session: mcp:write, with a rule in the project instructions to dry run first and send max_spend_usd.
  • Check the session with mcp_health: authenticated.auth_source should read mcp_oauth.

What Sume does not do

max_spend_usd is optional, so an agent that omits it is not stopped by it, and the optional legacy allow_paid flag cannot bypass a missing scope but is not required either. Treat the project rule as the place that says "always send a cap", and treat Auto-review as one more layer, not the layer.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume