Cursor 3.6 released May 29 introduces Auto-review, a new run mode where allowlisted Shell/MCP/Fetch calls run immediately, sandboxable calls execute in the sandbox, and everything else goes through a classifier subagent that decides allow/retry/ask. Users configure the run mode in Settings > Agents > Run Mode and can steer the classifier with custom instructions. This positions Cursor as having the same classifier-based autonomy pattern Claude Code adopted, creating an industry convergence on gated auto-execution.