Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Avoid common Cursor IDE pitfalls: AI feature mistakes, security gotchas, configuration errors, and team workflow issues. Triggers on "cursor pitfalls", "cursor mistakes", "cursor gotchas", "cursor issues", "cursor problems", "cursor tips".
.claude/skills/jeremylongshore-cursor-known-pitfalls/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-04 | ✗→✓ | ▲ Improved | 51% | 0% |
| case-05 | ✗→✓ | ▲ Improved | 72% | 0% |
| case-09 | ✗→✓ | ▲ Improved | 221% | 0% |
| case-18 | ✗→✓ | ▲ Improved | 70% | 0% |
| case-01 | ✓→✓ | = Same ✓ | 49% | 0% |
Use these pitfalls as preflight checks for AI-assisted work: context leakage, over-broad edits, stale rules, unsupported assumptions, and misplaced trust in generated output.
| Condition | Safe response | |---|---| | AI output is plausible but unverified | Treat it as a proposal and run normal review/tests. | | Context contains excluded material | Stop, remove it, and follow exposure policy. | | Rule causes repeated wrong output | Revise it through review and test on a fixture. |
Before accepting a multi-file refactor, check that it has an explicit file list, does not include secret/generated paths, and has tests. Reject broad changes and split the request when any of those checks fail.
Common Cursor IDE pitfalls and their solutions. Organized by category: AI behavior, security, configuration, performance, and team collaboration.
Problem: Clicking "Apply All" without reviewing diffs. Composer can generate code with wrong imports, hallucinated APIs, or logic errors.
Solution:
1. Click each file in the Changes panel to review its diff
2. Check imports: are they real packages in your project?
3. Check function calls: do the methods actually exist?
4. Run build after applying: npm run build
5. Run tests: npm test
6. Commit BEFORE running Composer (easy rollback with git checkout .)Problem: Adding too many @Files, @Folders, and @Codebase references. The model silently drops information, leading to:
Solution:
- Use @Files (specific) over @Folders (broad) over @Codebase (broadest)
- Limit to 3-5 file references per prompt
- Start new chats for new topics
- Remove stale context pills by clicking XProblem: Reusing a 20+ turn conversation for a new task. The conversation history fills context, leaving no room for your new request.
Solution: Cmd+N to start a new chat for each distinct task.
Problem: AI uses old APIs (React class components, Express 4 syntax, CommonJS require).
Solution: Pin versions in project rules:
yaml# .cursor/rules/stack.mdc --- description: "Tech stack versions" globs: "" alwaysApply: true --- ALWAYS use these versions: - React 19 with Server Components (NOT class components) - Next.js 15 App Router (NOT Pages Router) - TypeScript 5.7 strict (NOT any casts) - ESM imports (NOT CommonJS require)
Problem: Tab suggests text you do not want, and you accidentally accept it while pressing Tab for indentation.
Solution:
Esc to dismiss before pressing Tab for indentationCmd+K Cmd+S > search acceptCursorTabSuggestion > assign different keyProblem: Copying an error message that includes an API key, database URL, or token and pasting it into Chat.
Solution:
NEVER paste:
- .env file contents
- Error logs containing credentials
- Database connection strings
- API response headers with auth tokens
INSTEAD:
- Redact secrets before pasting: "API key sk-...XXXX returned 401"
- Describe the error without the sensitive values
- Use @Files to reference the code, not copy-pasteProblem: Without .cursorignore, sensitive files (.env, credentials, PII) may be included in AI context via @Codebase search or automatic context.
Solution: Create .cursorignore in every project:
gitignore.env* **/secrets/ **/credentials/ **/*.pem **/*.key
Problem: Without Privacy Mode, code may be retained by model providers for training.
Solution:
Cursor Settings > General > Privacy Mode > ONProblem: AI generates authentication, encryption, or authorization code that looks correct but has subtle vulnerabilities (timing attacks, SQL injection via string concatenation, missing CSRF protection).
Solution:
- Security-critical code ALWAYS needs human expert review
- Run SAST tools (Semgrep, Snyk) on AI-generated code
- Never deploy AI-generated auth code without penetration testing
- Add security rules in .cursor/rules/security.mdcProblem: Without .cursor/rules/, the AI generates code without knowing your conventions, stack, or patterns. Result: inconsistent code that does not match your project.
Solution: Create at minimum:
project.mdc (stack, conventions, alwaysApply: true)security.mdc (security constraints, alwaysApply: true)Problem: Multiple .mdc rules with contradictory instructions (one says "use classes", another says "use functions").
Solution:
@Cursor Rules in Chat to see which rules are active for a given fileProblem: GitHub Copilot + Cursor Tab both enabled. Double ghost text, conflicting suggestions, UI glitches.
Solution: Disable all other inline completion extensions:
Only one inline completion provider should be active.
Problem: Opening a monorepo root with 200K files. Indexing takes hours, @Codebase returns noise, editor is sluggish.
Solution: Open specific packages: cursor packages/api/
Problem: Cursor watches every file for changes, including node_modules/, dist/, and .git/objects/. Causes high CPU and memory.
Solution:
json// settings.json { "files.watcherExclude": { "**/node_modules/**": true, "**/.git/objects/**": true, "**/dist/**": true, "**/build/**": true } }
Problem: Running Cursor for weeks with dozens of open chat tabs. Memory grows, editor slows.
Solution: Close old chat tabs. Start new conversations. Restart Cursor weekly during heavy use.
Problem: .cursor/rules/ not committed to git. Each developer has different (or no) AI behavior rules.
Solution: Commit .cursor/rules/ and .cursorignore to git. PR-review rule changes like any other configuration.
Problem: Developers commit AI-generated code without review. Bugs, wrong patterns, and security issues reach main branch.
Solution:
Problem: Some developers use Opus for everything (consuming quota fast), others use cursor-small (poor quality).
Solution:
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | pass→pass | 13,421 | 8,070 | -40% | 1 | 1 | 0% | 2,179 | 3,247 | +49% | 0 | 0 | — |
case-02 | pass→pass | 14,808 | 10,792 | -27% | 1 | 1 | 0% | 2,433 | 3,608 | +48% | 0 | 0 | — |
case-03 | pass→pass | 7,894 | 4,968 | -37% | 1 | 1 | 0% | 1,318 | 2,697 | +105% | 0 | 0 | — |
case-04 | fail→pass | 11,628 | 6,806 | -41% | 1 | 1 | 0% | 2,028 | 3,068 | +51% | 0 | 0 | — |
case-05 | fail→pass | 9,545 | 13,130 | +38% | 1 | 1 | 0% | 1,719 | 2,961 | +72% | 0 | 0 | — |
case-06 | pass→pass | 7,662 | 5,921 | -23% | 1 | 1 | 0% | 1,369 | 2,832 | +107% | 0 | 0 | — |
case-07 | pass→pass | 11,175 | 10,254 | -8% | 1 | 1 | 0% | 1,777 | 3,598 | +102% | 0 | 0 | — |
case-08 | pass→pass | 18,285 | 11,458 | -37% | 1 | 1 | 0% | 1,580 | 2,818 | +78% | 0 | 0 | — |
case-09 | fail→pass | 16,357 | 18,861 | +15% | 1 | 1 | 0% | 837 | 2,686 | +221% | 0 | 0 | — |
case-10 | pass→pass | 9,351 | 7,308 | -22% | 1 | 1 | 0% | 1,678 | 3,152 | +88% | 0 | 0 | — |
case-11 | pass→pass | 14,018 | 9,605 | -31% | 1 | 1 | 0% | 2,348 | 3,431 | +46% | 0 | 0 | — |
case-12 | pass→pass | 8,956 | 5,170 | -42% | 1 | 1 | 0% | 1,475 | 2,724 | +85% | 0 | 0 | — |
case-13 | pass→pass | 12,086 | 7,154 | -41% | 1 | 1 | 0% | 2,051 | 3,208 | +56% | 0 | 0 | — |
case-14 | pass→pass | 10,436 | 7,025 | -33% | 1 | 1 | 0% | 2,031 | 3,169 | +56% | 0 | 0 | — |
case-15 | pass→pass | 6,819 | 3,708 | -46% | 1 | 1 | 0% | 1,326 | 2,585 | +95% | 0 | 0 | — |
case-16 | pass→pass | 11,101 | 7,637 | -31% | 1 | 1 | 0% | 1,845 | 3,050 | +65% | 0 | 0 | — |
case-17 | pass→pass | 7,045 | 5,228 | -26% | 1 | 1 | 0% | 1,303 | 2,741 | +110% | 0 | 0 | — |
case-18 | fail→pass | 13,935 | 12,123 | -13% | 1 | 1 | 0% | 2,311 | 3,934 | +70% | 0 | 0 | — |
case-19 | pass→pass | 6,121 | 4,957 | -19% | 1 | 1 | 0% | 1,103 | 2,671 | +142% | 0 | 0 | — |
case-20 | pass→pass | 7,245 | 4,780 | -34% | 1 | 1 | 0% | 1,387 | 2,759 | +99% | 0 | 0 | — |
case-21 | pass→pass | 9,055 | 6,114 | -32% | 1 | 1 | 0% | 1,819 | 2,967 | +63% | 0 | 0 | — |
case-22 | pass→pass | 9,014 | 6,507 | -28% | 1 | 1 | 0% | 1,818 | 3,052 | +68% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +18 percentage points is the difference between those two pass rates over the 22 comparable cases.
The publisher has shipped newer versions since this run, so these numbers describe v1, not the version currently listed.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.