Cursor Run Everything mode: a read-only Sume token is the guardrail

In Run Everything, Cursor runs every tool call without review. Connect Sume with mcp:read so paid and write tools are not even visible.

5 min readSume
All posts

If you run Cursor in Run Everything mode, connect Sume with OAuth read-only and keep Write off. Cursor's docs say that in this mode every tool call runs automatically, with no classifier review or sandbox protections (Cursor run modes, read 2026-10-04). A read-only Sume token means the paid and write tools are hidden from the session, so there is nothing expensive for an unreviewed call to reach.

What Run Everything removes

Cursor describes three modes. Auto-review sends non-sandboxed calls to a classifier. Allowlist mode runs only actions in your allowlist without approval. Run Everything skips both the classifier and the sandbox. Team administrators can override which modes are available to users, so the right default may not be yours to choose.

That makes the credential, not the mode, the real control for a remote server. Whatever the token can do is what an unreviewed run can do.

What a read-only Sume session can and cannot do

On the hosted endpoint https://mcp.sume.com/mcp, OAuth consent shows Permissions with Read locked on and the Write toggle off by default. A session with mcp:read sees read-only tools, and a mutating call returns insufficient_scope. Granting write always includes read (MCP OAuth and API keys).

An API key is the opposite: it gets the full hosted tool set. Do not put an API key behind a client that runs every call unreviewed unless you are happy with every tool being reachable.

Credential choice under an unreviewed run mode. Source: Sume docs, read 2026-10-04.
CredentialTools the session seesA paid call
OAuth mcp:readRead-only toolsNot visible; a mutating call returns insufficient_scope
OAuth mcp:read and mcp:writeRead, write and paid toolsNeeds idempotency_key; dry_run and max_spend_usd optional
API keyFull hosted tool setSame gates; spend is wallet and admission

Prove the session is read-only

After connecting, ask the agent to call mcp_health and check that the auth source is mcp_oauth, then call tools_list and confirm that only read tools appear. If a write tool is listed, the session was granted more than you intended, and you should reconnect with Write off.

  • Useful read tools: catalog_list, balance_get, jobs_list, jobs_status, assets_list.
  • Generation tools such as generate_image and generate_video need mcp:write or an API key.
  • Switch to a write session only for the task that needs it, then disconnect.

When you do need to generate

Move to a separate connection with Write on, and pair it with a more careful run mode for that session. Preview with dry_run=true, send max_spend_usd, and use a stable idempotency_key so a retry cannot double-submit.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume