Cursor 2.5 Brings Plugin Marketplace, Sandbox Network Controls, and Async Subagents
Cursor releases version 2.5 with a plugin marketplace for extensibility, granular network access controls for sandboxed environments, and asynchronous subagent execution for parallel processing.
Cursor has released version 2.5, introducing a plugin marketplace for extensibility, enhanced security controls for sandboxed environments, and performance improvements to its agent capabilities.
Plugin Marketplace Launches
The newly launched Cursor Marketplace allows developers to discover and install plugins that package skills, subagents, MCP servers, hooks, and rules into a single installation.
Initial partners include Amplitude, AWS, Figma, Linear, and Stripe. These plugins cover workflows spanning design, databases, payments, analytics, and deployment.
Plugins can be browsed at cursor.com/marketplace or installed directly in the editor using the /add-plugin command.
More details are available in the official announcement.
Granular Sandbox Network Controls
The sandbox environment now supports granular network access controls alongside existing directory and file access controls. Developers can define precisely which domains the agent can reach while executing sandboxed commands.
Three control levels are available:
- User config only: Restricted to domains defined in
sandbox.json - User config with defaults: Restricted to user allowlist plus Cursorβs built-in defaults
- Allow all: Unrestricted network access within the sandbox
Enterprise plan administrators can enforce network allowlists and denylists from the admin dashboard, ensuring organization-wide egress policies apply to all agent sandbox sessions.
Asynchronous Subagent Execution
Previously, all subagents ran synchronously, blocking the parent agent until completion. Version 2.5 enables asynchronous subagent execution, allowing the parent agent to continue working while subagents run in the background.
Subagents can now spawn their own subagents, creating a tree of coordinated work. This enables Cursor to tackle larger tasks such as multi-file features, extensive refactors, and complex bugs.
Performance improvements to subagents have also been implemented since the previous release, including lower latency, better streaming feedback, and more responsive parallel execution.
Technical Context
The AI coding assistant market is experiencing a shift from single-agent systems to multi-agent architectures. The combination of parallel processing and specialized subagents represents a promising approach for efficiently handling complex coding tasks.
Network controls for sandboxed environments address a critical balance between AI agent autonomy and security. In enterprise settings, controlling AI agent external communications has become an integral part of zero-trust security strategies.
Availability
Cursor 2.5 is available now. Full details can be found in the official changelog.
Related Articles
Claude Code's 28 Official Plugins Revealed - Undocumented Feature Extensions
Reddit user discovers 28 official Claude Code plugins, most undocumented. Includes TypeScript LSP, security scanning, context7 documentation search, and Playwright automation.
Cursor Adds Subagents, Skills, and Image Generation - Major Agent Enhancements
Cursor implements subagents, agent skills, and image generation. Parallel execution, improved context management, and dynamic skill application enable handling of more complex, long-running tasks.
Cursor Launches Long-Running Agents in Research Preview - Autonomous Execution for Complex Tasks
Cursor introduces long-running agents capable of autonomous planning and execution without human intervention. Available for Ultra, Teams, and Enterprise plans.
Popular Articles
Claude Code v2.1.93 Released - Deferred Permission Decisions, Flicker-Free Rendering, and More
Anthropic releases Claude Code v2.1.93 with deferred permission decisions for PreToolUse hooks, flicker-free rendering option, PermissionDenied hook, and named subagent typeahead support.
Claude Code v2.1.92 Released - forceRemoteSettingsRefresh, Bedrock Setup Wizard, and More
Anthropic releases Claude Code v2.1.92 with forceRemoteSettingsRefresh policy setting, AWS Bedrock setup wizard, /cost command improvements, and numerous bug fixes.
Claude Code v2.1.84 Release - PowerShell Tool Preview and Environment Configuration Enhancements
Claude Code v2.1.84 introduces PowerShell tool for Windows, new environment variable overrides for model selection, idle session handling improvements, and various stability fixes.
Latest Articles
Claude Code v2.1.93 Released - Deferred Permission Decisions, Flicker-Free Rendering, and More
Anthropic releases Claude Code v2.1.93 with deferred permission decisions for PreToolUse hooks, flicker-free rendering option, PermissionDenied hook, and named subagent typeahead support.
Claude Code v2.1.92 Released - forceRemoteSettingsRefresh, Bedrock Setup Wizard, and More
Anthropic releases Claude Code v2.1.92 with forceRemoteSettingsRefresh policy setting, AWS Bedrock setup wizard, /cost command improvements, and numerous bug fixes.
Claude Code v2.1.91 Released - MCP Tool Result Persistence and Improved Edit Tool
Claude Code v2.1.91 introduces MCP tool result persistence override, improved shell execution controls, and enhanced Edit tool efficiency.