Cursor Auto-review mode and paid Sume tool calls: keep dry_run on
Cursor's Auto-review classifier can allow a call you would block. For paid Sume tools, rely on server-side dry_run, max_spend_usd and OAuth scope.

Should Cursor's Auto-review mode be trusted to stop a paid Sume generation? Not on its own. Cursor's docs say the Auto-review classifier can make mistakes: it can allow a call you would have blocked, or block one you would have allowed (Cursor run modes, read 2026-10-04). For a call that spends credits, put the limit on the server side, where it applies in every run mode.
Sume gives you three such limits on its hosted MCP: the OAuth scope you granted, dry_run, and max_spend_usd.
What Auto-review does, per Cursor
In Auto-review mode, allowlisted calls run immediately, other shell commands run in a sandbox when possible, and calls that do not use the sandbox go to the Auto-review classifier. The classifier uses Cursor-managed models, listed as Gemini 3.5 Flash Lite with Claude 4.5 Haiku as the fallback, and it can make read-only file and search calls on your machine to judge a request.
Cursor's MCP page adds that Cursor asks for approval before using MCP tools by default, and that MCP follows the same run modes as terminal commands (Cursor MCP docs, read 2026-10-04). So a Sume tool call is judged by whichever mode you picked.
Where Sume's limits sit
Sume's gates do not depend on the client's judgment. Under OAuth, a session with only mcp:read sees read-only tools, and a mutating call returns insufficient_scope. There is no mcp:paid scope, so paid tools need mcp:write or an API key. idempotency_key is required on write and paid tools, and it is dedup, not human approval (MCP tools and gates).
| Layer | What it does | Can it be wrong? |
|---|---|---|
| Cursor Auto-review classifier | Judges the call, per Cursor | Yes, Cursor says it can allow or block wrongly |
| Sume OAuth scope | Hides write and paid tools without mcp:write | No: a missing scope refuses the call |
| dry_run=true | Previews admission and cost, submits nothing | Only if the agent skips it |
| max_spend_usd | Caps the call, enforced only when sent | Only if the agent omits it |
A setup that holds under Auto-review
Connect with OAuth and leave the Write toggle off for exploration. When a task needs generation, reconnect with Write on, and tell the agent to preview first. Calling generation_admission_preview or the paid tool with dry_run=true shows the estimate and balance before anything is submitted.
- Exploration session: OAuth
mcp:readonly, and read tools only. - Generation session:
mcp:write, with a rule in the project instructions to dry run first and sendmax_spend_usd. - Check the session with
mcp_health:authenticated.auth_sourceshould readmcp_oauth.
What Sume does not do
max_spend_usd is optional, so an agent that omits it is not stopped by it, and the optional legacy allow_paid flag cannot bypass a missing scope but is not required either. Treat the project rule as the place that says "always send a cap", and treat Auto-review as one more layer, not the layer.
Sources
Related posts
More in Integrations
- Cursor Run Everything mode: a read-only Sume token is the guardrail
In Run Everything, Cursor runs every tool call without review. Connect Sume with mcp:read so paid and write tools are not even visible.
- Cline Connectors tab tool count: Sume read-only vs write session
Cline's desktop Connectors tab shows how many tools a connector adds to new sessions. Sume's count depends on the scope you grant or an API key.
- Discord multiline slash options: send a script to Sume Avatar
Discord string options now accept multiline input. Use one for an avatar script and post it to Sume's talking-video endpoint with an interaction-keyed id.
- Evaluating a video MCP server: five checks, with Runway as context
Runway shipped MCP and plugin channels on Sep 17, 22, 23 and Oct 1. Before you connect any video MCP server, check scopes, idempotency, spend caps and waits.
Written by Sume