What happened
.cursor/install.sh was run on a developer workstation. It installed root-owned ec and typos binaries into /usr/local/bin, on a machine that already gets both from mise, so there are now two copies and the system one can shadow the pinned one depending on PATH order.
Evidence (checked against origin/main)
- The header (lines 1-2) says this is the "Cloud Agent install step", but nothing enforces that.
.cursor/install.sh:35 sets BIN_DIR="/usr/local/bin". Lines 40-48 use sudo whenever sudo -n true succeeds and fall back to ~/.local/bin only when it does not, so a workstation with passwordless sudo gets a system-wide install.
install_typos (:100-104) and install_ec (:106-110) then go through install_bin, which runs "${SUDO[@]}" install -m 0755 ... into that directory.
Expected behavior
Running the script on a developer machine does not write outside the user's home.
Suggested direction
Either of these:
- Refuse to run unless it is inside Cursor's cloud agent or CI (for example, require an environment marker set by the cloud-agent environment or
CI=true), with a message naming the override.
- Install to
~/.local/bin by default and use /usr/local/bin only when the cloud-agent marker is present.
What happened
.cursor/install.shwas run on a developer workstation. It installed root-ownedecandtyposbinaries into/usr/local/bin, on a machine that already gets both from mise, so there are now two copies and the system one can shadow the pinned one depending on PATH order.Evidence (checked against
origin/main).cursor/install.sh:35setsBIN_DIR="/usr/local/bin". Lines 40-48 usesudowheneversudo -n truesucceeds and fall back to~/.local/binonly when it does not, so a workstation with passwordless sudo gets a system-wide install.install_typos(:100-104) andinstall_ec(:106-110) then go throughinstall_bin, which runs"${SUDO[@]}" install -m 0755 ...into that directory.Expected behavior
Running the script on a developer machine does not write outside the user's home.
Suggested direction
Either of these:
CI=true), with a message naming the override.~/.local/binby default and use/usr/local/binonly when the cloud-agent marker is present.