AgentSkills.site

Cursor Skills: The Practical Guide

Cursor loads skills from eight directories, and half of them belong to other agents. Here is how Cursor skills work, how they differ from rules and plugins, and what to verify before trusting them in your workspace.

Published

Updated

AgentSkills.site editorial

What Cursor skills are: the 30-second mental model

Cursor is an AI-powered code editor and agentic development environment. A skill is a directory containing a SKILL.md file: YAML frontmatter defining when the skill applies, followed by step-by-step markdown instructions the agent executes once triggered.

Cursor implemented the open Agent Skills specification in Cursor 2.4 (released 22 January 2026). The core SKILL.md format is shared across agents like Claude Code, Codex, and OpenClaw, though discovery paths, frontmatter extensions, and runtime behavior differ across environments.

Three principles govern how Cursor skills operate:

  1. On-demand execution, not standing prompt bloat. Unlike Cursor rules (which inject standing guidance directly into context), skills load only when needed—keeping baseline prompt usage efficient.
  2. Three trigger mechanisms. A skill can load automatically via semantic relevance matching, conditionally via file-scoped paths globs, or manually when invoked by name with /.
  3. Automatic cross-agent reuse. Cursor scans eight separate directories, including existing Claude Code and Codex locations. If you already have skills installed for Claude Code, Cursor picks them up with zero conversion.

The four Cursor skills tasks

This guide covers the core architecture, trigger mechanics, and directory structure of Cursor skills. For adjacent tasks in this cluster, use the dedicated guides:

What you want to do Where to go Searcher job answered
Understand the system This guide What are Cursor skills, how do they work, and what should I know first?
Pick skills for your work The Best Cursor Skills Which specific skills or plugins should I use for code review, testing, or security?
Install and test a skill How to Install Cursor Skills How do I install a skill into Cursor and verify that it actually triggers?
Choose between skills and rules Cursor Skills vs Rules Should this specific instruction be a .cursor/rules/*.mdc rule or a SKILL.md skill?

How Cursor skills work: the 3 trigger paths

Cursor evaluates and loads skills through three distinct activation paths:

Activation path Mechanism How it works Best used for
Automatic (Semantic) description frontmatter The agent reads the name and description of all available skills and selects the skill when relevant to your prompt. General procedures, code reviews, and tasks where phrasing varies.
File-Scoped paths frontmatter Cursor evaluates matching globs. The skill is surfaced to the agent only when reading or editing matching files. Migrations, schema updates, and framework-specific file patterns (db/migrations/**).
Explicit (Manual) /skill-name invocation You type / in Agent chat and select the skill directly. Model auto-selection can be disabled with disable-model-invocation: true. High-impact actions, production releases, destructive operations, or personal workflows.

1. Automatic relevance matching

By default, Cursor presents available skill summaries to the model. The model decides when a skill is relevant based on the user's prompt and ongoing session context.

Because the model only sees the name and description during this initial evaluation, the description carries almost the entire discovery burden. A vague description leads to false triggers or complete omission.

2. File-scoped execution (paths)

paths is a Cursor-exclusive addition to the Agent Skills format:

---
name: migration-guard
description: Audits database schema migrations for destructive statements and missing down-migrations.
paths: "db/migrations/**/*.sql, prisma/migrations/**"
---

While other agents only match skills to user prompt phrasing, paths scopes eligibility to the files currently being read or modified. If Cursor touches a file matching the pattern, the skill is surfaced for execution.

3. Explicit invocation and slash commands

Typing / in Cursor Agent chat displays an autocomplete list of all installed skills.

To prevent the agent from triggering a skill automatically without your explicit consent, add disable-model-invocation: true to the frontmatter:

---
name: deploy-staging
description: Triggers a deployment run to the staging cluster.
disable-model-invocation: true
---

This transforms the skill into a deterministic slash command: Cursor will never invoke it autonomously based on chat context, but you can run it deliberately with /deploy-staging.


Where Cursor scans for skills: all 8 directories

Cursor looks for skills in eight predefined locations across project and personal scopes. Four are native to Cursor, and four are compatibility paths for Claude Code and Codex:

Scope Directory path Origin / Status Shared with other agents?
Project .cursor/skills/ Cursor native Cursor only
Project .agents/skills/ Cross-agent standard Shared with Codex, OpenClaw, and tooling
Personal ~/.cursor/skills/ Cursor native Cursor only
Personal ~/.agents/skills/ Cross-agent standard Shared with Codex and OpenClaw
Project .claude/skills/ Compatibility path Claude Code project skills
Personal ~/.claude/skills/ Compatibility path Claude Code personal skills
Project .codex/skills/ Compatibility path Codex project skills
Personal ~/.codex/skills/ Compatibility path Codex personal skills

Per official documentation: "For compatibility, Cursor also loads skills from Claude and Codex directories."

Why this directory list matters

  1. Zero-effort cross-agent reuse: If you already maintain skills in ~/.claude/skills/, Cursor loads them automatically with no symlinking, manual copying, or reconfiguration.
  2. Cross-agent sharing nuances: Cursor reads compatibility directories for Claude Code (.claude/skills/) and Codex (.codex/skills/), alongside .agents/skills/. However, Claude Code's official documentation only documents reading .claude/skills/ and ~/.claude/skills/—it does not scan .agents/skills/ or .cursor/skills/. To share skills between Cursor and Claude Code without duplicating files, place them in .claude/skills/ so Cursor can discover them via compatibility scanning. For tools that support the Agent Skills standard (Cursor, Codex, OpenClaw), .agents/skills/ is the standard project location.
  3. Codex deprecation note: The directory Cursor checks for Codex (~/.codex/skills) was deprecated in Codex in favor of ~/.agents/skills. Because Cursor checks both, skills in either folder will load.

Monorepo and nested subfolder discovery

Skills do not have to live at the workspace root. Cursor discovers .cursor/skills/ and .agents/skills/ folders nested anywhere inside your repository tree.

For example, a skill located at:

packages/billing-service/.cursor/skills/stripe-sync/SKILL.md

is discovered automatically and colocated with the package it governs.


The anatomy of a Cursor skill

A minimal skill requires a folder and a SKILL.md file:

.cursor/skills/deploy-staging/
├── SKILL.md         # Required: frontmatter + prompt instructions
├── scripts/         # Optional: bash/node/python utilities the agent can run
├── references/      # Optional: reference docs, API specs, schemas loaded on demand
└── assets/          # Optional: starter templates, icons, boilerplate

Frontmatter specification

Field Required? Type Purpose Portability
name Yes String Skill identifier. Must exactly match the parent folder name using lowercase letters, numbers, and hyphens. Standard (Cross-agent)
description Yes String Explains what the skill accomplishes and when to invoke it. Used by Cursor for semantic relevance matching. Standard (Cross-agent)
paths No String Comma-separated glob patterns. Surfaces the skill only when matching files are read or modified. Cursor-only
disable-model-invocation No Boolean If true, hides the skill from autonomous model selection. Can only be triggered manually via /skill-name. Cursor-only (shared by convention)
metadata No Object Arbitrary key-value dictionary for supplementary configuration. Standard (Cross-agent)
globs No String Legacy predecessor to paths. Supported for backwards compatibility; new skills should use paths. Legacy

name, description, and metadata conform to the Agent Skills open specification. paths and disable-model-invocation are Cursor-specific extensions that are ignored by runtimes adhering strictly to the base standard.

paths vs rule globs

paths on a skill and globs on a rule look similar, but their behavior is fundamentally different:

  • A rule's globs injects the rule text directly into the prompt whenever matching files are open or touched.
  • A skill's paths makes the skill eligible for consideration, but the body of the skill only loads if the model decides to run the procedure.

For a complete breakdown of when to choose each mechanism, see Cursor Skills vs Rules.


Cursor extensibility: skills, rules, commands, plugins, and MCP

Cursor supports five distinct extension mechanisms that are frequently confused:

Mechanism Configuration file Primary purpose When it loads Portable?
Skill SKILL.md in 8 scan directories Modular, on-demand procedure with optional scripts and references When description matches, paths match, or invoked via / Yes (Agent Skills standard)
Rule .cursor/rules/*.mdc or AGENTS.md Standing repository constraints, architectural invariants, code style Injected always, on matching globs, or via manual @ mention No (Cursor proprietary .mdc)
Command User-defined slash commands Explicit prompt shortcuts Only when typed by user; converted to skills with disable-model-invocation: true Replaced by skills
Plugin .cursor-plugin/plugin.json or root plugin.json Distributable packaging format containing skills, rules, hooks, and MCP configs When installed from Marketplace or local directory Follows Agent Plugins standard
MCP Server Configured via mcp.json or plugin External process providing executable tools and resources Maintained as an active RPC tool bridge Standard MCP protocol

Understanding the plugin container layer

A Cursor Plugin is not an alternative to a skill—it is a distribution container. A single plugin can bundle multiple skills, rules, subagent definitions, and MCP servers:

my-team-plugin/
├── .cursor-plugin/
│   └── plugin.json       # Manifest metadata
├── skills/
│   └── code-reviewer/
│       └── SKILL.md      # Skill component
├── rules/
│   └── conventions.mdc   # Rule component
└── mcp.json              # MCP tool configuration

Marketplace plugins in the official cursor/plugins repository vary widely in content. Third-party integrations (such as Gmail, Slack, and Salesforce) frequently package only an mcp.json without any skills. In contrast, first-party plugins (like cursor-team-kit and thermos) package multi-skill suites and subagents. For a component-by-component audit of the marketplace, see Cursor Plugins.


What you must know before using Cursor skills: 4 critical caveats

Before deploying skills in production workspaces, keep these verified technical boundaries in mind:

1. Context budget is unquantified

Cursor states that skills "load resources on demand, keeping context usage efficient," but publishes no fixed character or token budget.

By comparison, Codex caps its skill catalog index at 2% of the context window or 8,000 characters, and OpenClaw allocates roughly 97 characters per skill plus field lengths. While Cursor gives no exact budget figure, concise and specific descriptions remain critical: every loaded skill consumes context that would otherwise be available for code and conversation history.

2. Duplicate name collisions are undefined

Cursor does not document a formal precedence hierarchy when the same skill name exists in multiple scan directories (e.g., identical skill names in .cursor/skills/ and ~/.claude/skills/).

In contrast, Claude Code documents a strict precedence order and Codex surfaces both without merging. To avoid non-deterministic behavior in Cursor, give custom skills unique names across project and personal scopes.

3. Folder and name alignment is mandatory

The name attribute in SKILL.md frontmatter must match the directory name exactly. If .cursor/skills/audit-tool/SKILL.md specifies name: audit_tool, Cursor will fail to register the skill correctly.

4. No install-time security scanning

Cursor does not statically audit or vet third-party skills at install time. Bundled scripts in a skill's scripts/ directory are executable code. When run via the terminal, command execution is governed by Cursor's Run Modes (Auto-review, Allowlist, or Ask before running) and terminal command sandboxing (via sandbox.json). However, commands can request approvals or run outside the sandbox for full machine access. Always inspect third-party skill files and scripts before adding them to your workspace.


Sources