Skip to lesson
Exit
Protect secrets and review cloud artifacts1 / 2

1 min lesson

Choose the secret and artifact boundary

Choose the secret type, egress hosts and artifact audience for one staging run.

Step 1 of 2

Runtime Secrets protect sensitive values from model-visible output. Artifact links need a separate audience check.

Use an Environment Variable for non-sensitive configuration the agent may read. Use a Runtime Secret for a password or token: Cursor injects it as an environment variable but replaces its value with [REDACTED] in model-visible tool output, the transcript and commits. A person controlling the VM through its terminal can still reveal the value. Build Secrets exist only during a Docker build. An environment-scoped secret reaches every repository in that environment, not one task. Computer use lets the agent drive its VM desktop and browser. Remote desktop lets you take control and hand it back. Screenshots, videos and log references show what the agent tested. Direct GitHub embeds are optional, and their long URLs are open without authentication. Restricted egress must name the exact artifact upload host. Secrets remain until removed. Conversations and artifacts remain indefinitely by default; the Delete Agent API removes both.

Where this fits
Entry point
Cloud AgentsAgents that run in a Cursor-managed virtual machine, check out the repo, do the work and open a pull request, then shut down, with no load on your laptop. Press Enter for the full definition. dashboard Secrets and Security settings, the agent page and artifact settings
Source
Cursor Cloud Agent Capabilities, Secrets & Network, Setup and Security docs

Check secret types and scopes, network egress, computer use, GitHub artifact exposure and retention in Cursor's current docs.