Maya: Cursor spent the past few months rebuilding the harness behind its coding agent, and it announced on September twenty third that the agent now burns about seven percent fewer tokens per task without making its output worse. James: The harness is the layer of code Cursor writes around the model, deciding what goes into each request. Since tokens are what providers bill for, fewer tokens per task means a cheaper run for the same work. Maya: The biggest single cut came from the system prompt, which Cursor trimmed by roughly sixty six percent. Older models needed long lists of do-not rules, but newer ones comply once a tool's behavior is simply described. James: They also stopped listing every built-in tool on every request, since most tools get used in fewer than twenty percent of conversations. Dynamic loading cut the tokens in tool descriptions by sixty percent, and moving the prompt ahead of new cache breakpoints cut cold cache misses by twenty percent. Maya: On the security side, Manifold Security disclosed GitSpawn on September first, a flaw that lets a malicious project hijack the background git commands Cursor and six other coding agents run. James: That is unsettling, Maya. Every one of these agents runs git the instant you open a folder, gathering commit history. A poisoned dot-git-slash-config can set values like core.fsmonitor to run arbitrary commands, with no warning dialog and access to SSH keys. Maya: The danger depends on how the project arrives. Cloning through git builds a fresh config, so it is safe. But a project handed over as a zip file, shared folder or USB drive copies the exact config, malicious entries included. James: That handoff is common in consultancies and technical interviews. By the September twenty first interview, Hermes and Grok Build had patched, but at least four of eight findings were still unpatched. The advice is simple: inspect that config before pointing an agent at it. Maya: On a lighter note, a recent walkthrough pairs Blender, a 3D modeling program, with an MCP server so Cursor, Codex or Claude Code can drive it directly. The goal is stopping AI-built pages from looking generic. James: The MCP server stands in for Blender knowledge the builder does not have. They also install two taste skills, small instruction files giving the agent design guidance, including one built by Emil Kowalski, a former Vercel engineer. Maya: A key step is picking a coding tool with a built-in browser, because the agent needs to screenshot its own output and compare it against saved reference images. A vague brief like cinematic means little without a picture showing what it looks like. James: The walkthrough stresses model choice matters more here, naming Fable five point one, GPT-6 and Opus as strong, and warning against GPT-5.5 and 5.6. It is framed for sites with custom 3D assets or layered scroll, not flat landing pages. Maya: If you are watching your spend, CodeBurn is a free Mac app that reads the local session files Cursor, Claude Code and roughly thirty five other tools already save, then breaks your spending down by project, model and branch. James: No API keys, no sign-up, nothing leaves the Mac. Today's spend sits in the menu bar, and a Capacity Dock shows one ring per provider filling toward your five-hour and weekly limits before a long session rather than after. Maya: There is also an Optimize scan that hunts for token waste: MCP servers installed months ago and never called, or a bloated CLAUDE.md file. Each finding comes with a grade, a suggested fix and estimated savings. James: CodeBurn can apply a fix, back up the file first, and undo with one command. It rechecks your sessions against the estimate later, and if a fix did not help, it says so. The waste detection is built around Claude Code right now, so a Cursor-only user gets the breakdown but not the same scanning depth. Maya: Last one, James. A billing-data comparison of Composer 2.5's two speed settings found Fast finishes the same task in roughly half the time, but charges about two point three times more per token. James: The tester ran the identical task repeatedly, wiping context between runs. Fast averaged thirty six seconds against sixty two for Normal, a forty two percent cut. Token counts stayed roughly the same, so the cost gap is the effective price. One post floats that these may be two priority levels, but calls that a hypothesis. Maya: That is your Cursor HQ rundown. Go check that config before you open the next zip.