Cursor Remote Control Is On by Default. Claude Code’s UNC Fix Is Not on Stable.

At a glance

  • Cursor's new Remote Control lets the iOS app see and message the local agents on your computer, and it is on by default for every plan except Enterprise.
  • Claude Code's newest build closes a hole where hook approvals and auto mode skipped the prompt for file reads from network paths, but machines pinned to the stable channel do not have it.
  • Gemini CLI's new stable release lets non-interactive runs carry out multi-step plans without stopping for confirmation.
  • A Copilot CLI pre-release says command sandboxing is now available to all users, while GitHub's docs still describe it as experimental.

The common thread this Wednesday is control, because two of today’s changes decide what can reach or drive an agent while nobody is watching. Cursor opened a phone path to local agents and left it on for most plans, while Claude Code shipped a batch of permission fixes that only reach machines on the faster channel. Treat today as the day to decide where Cursor Remote Control should stay on, check which Claude Code channel each machine follows, and review any headless Gemini job before it upgrades.

Top Stories

1. Cursor Remote Control is on by default unless you are on Enterprise

The top entry on Cursor’s changelog introduces Remote Control for local agents. You sign in to the Cursor iOS app, your computers appear automatically, and once you approve the pairing request in the Cursor desktop app you can open any local agent to see what it is doing or send it a message. The agents keep running on your computer rather than moving to the cloud, so the computer must stay on and online, and cloud agents are not required. Cursor says the feature is on by default for everyone except Enterprise organizations, where admins turn it on under Org settings, then Security and identity, then Remote control. A separate “Keep this computer awake” switch in the Remote Control section of desktop settings stops sleep, but only while the machine is plugged in with the lid open.

Practical dev impact: On any non-Enterprise account, the pairing approval on the desktop is what stands between a phone signed in to your Cursor account and a running agent, so treat that prompt as a real access decision rather than a formality. Review the Remote Control section of desktop settings on shared or travel machines, and leave keep-awake off on any laptop you do not mean to leave reachable, while Enterprise orgs stay off until an admin opts in.

2. Claude Code v2.1.292 closes several permission gaps, but only on latest

Anthropic published v2.1.292 to npm at 1:10 PM ET on Tuesday 6 Oct, and as of 6:04 AM ET today both latest and next point to it while stable is still v2.1.285. The changelog marks one fix as security, because PreToolUse hook approvals and auto mode were bypassing the permission prompt for file reads from network (UNC) paths. Several neighbors tighten the same boundary. Sandboxed commands could read staged copies of /ultrareview uploads under ~/.claude/seed-admin, a notebook or PDF read on macOS and Windows could return a file outside what was approved through a link swapped in mid-read, and a tampered on-disk cache of server-managed settings could switch off the built-in policy plugin while the settings fetch failed. On Windows, rm -rf aimed at the 8.3 short name or another alternate spelling of the home folder or a drive is now treated as removing it. The release also adds --marketplace to claude plugin install, under the same policy checks as claude plugin marketplace add.

Practical dev impact: If your agents run in auto mode or behind a hook that answers allow, and they can see network shares, the UNC fix is the one to care about, because those reads went through without a prompt. None of these fixes is on stable, so a version check decides your exposure, and a machine printing v2.1.285 has none of them until Anthropic moves that pointer or you canary v2.1.292.

3. Gemini CLI v0.63.0 runs the plan when nobody is at the prompt

Google released Gemini CLI v0.63.0 as stable on Tuesday 6 Oct, with the npm publish at 4:58 PM ET. Its lead highlight is autonomous plan execution in non-interactive mode, which the changelog says lets automated agent workflows run multi-step plans without requiring interactive confirmation. The same release bounds tool output in long-running agent loops and stops infinite authentication loops caused by file contention, headless keyrings and supervisor state drops. Preview v0.64.0-preview.0 landed 27 minutes earlier and makes file tool writes atomic, but that change is not in stable yet.

Practical dev impact: A cron or CI job that used to pause at a plan confirmation can now carry on through every step, so before a headless job picks up v0.63.0, constrain its tools and point it at a checkout you can throw away. Interactive users mostly get the auth and memory fixes.

4. Copilot CLI’s sandbox for all users is still a pre-release

GitHub published Copilot CLI v1.0.93-4 as a pre-release at 1:34 AM ET today, and its one improvement line says command sandboxing is available to all users via /sandbox and --sandbox, while the local sandboxing docs still call it experimental and npm latest remains v1.0.92.

Practical dev impact: Keep fleets on v1.0.92 and try the pre-release only on a test machine, where /sandbox status shows what the session really enforces.

Codex did not ship a release in this window, and its npm latest is still v0.160.1.

Practical Impact Analysis

Only one of today’s changes is something you install on purpose, because the others arrive as defaults or channel moves. Cursor Remote Control is a product default rather than a version, so it is already live on non-Enterprise accounts, and the review work is deciding which machines should be reachable from a phone at all. Enterprise admins have the opposite job, since nothing changes until they flip the org switch.

Claude Code’s fixes split along channels, so the same team can be protected on one laptop and exposed on the next, which makes claude --version the real decision, especially on Windows machines with network shares and anywhere auto mode or allow hooks are in use. Gemini CLI’s change is the one stable upgrade with a workflow side effect, because headless runs now proceed where they used to stop, while interactive sessions behave much as before. Copilot’s sandbox line is worth watching rather than acting on until the docs and the latest tag agree.

Tutorial

Check the channels first, since these tags move without notice, then canary Claude Code on one npm-installed machine that uses auto mode or allow hooks and pin any headless Gemini job before it upgrades. The install lines are commented out so you can run the checks safely and uncomment them on purpose.

bash Tutorial
#!/usr/bin/env bash
# 1. Read the channel pointers and local versions.
npm view @anthropic-ai/claude-code dist-tags --json
npm view @github/copilot dist-tags --json
npm view @google/gemini-cli dist-tags --json
claude --version
gemini --version

# 2. If claude prints 2.1.285, the UNC fix is not on this machine.
#    Canary on one machine, then restart open sessions so the new binary loads.
# npm install -g @anthropic-ai/claude-code@2.1.292

# 3. Pin headless Gemini jobs and run once against a scratch branch first.
# npm install -g @google/gemini-cli@0.63.0
▸ Show full code (14 lines)
#!/usr/bin/env bash
# 1. Read the channel pointers and local versions.
npm view @anthropic-ai/claude-code dist-tags --json
npm view @github/copilot dist-tags --json
npm view @google/gemini-cli dist-tags --json
claude --version
gemini --version

# 2. If claude prints 2.1.285, the UNC fix is not on this machine.
#    Canary on one machine, then restart open sessions so the new binary loads.
# npm install -g @anthropic-ai/claude-code@2.1.292

# 3. Pin headless Gemini jobs and run once against a scratch branch first.
# npm install -g @google/gemini-cli@0.63.0

At 6:04 AM ET today Claude Code showed stable v2.1.285 with latest and next v2.1.292. On each non-Enterprise Cursor install, open the Remote Control section of desktop settings, confirm whether that machine should be reachable from the iOS app, and leave “Keep this computer awake” off on shared or travel laptops.

Recommended AI prompt

Copy this paragraph into ChatGPT, Claude, Gemini, Grok, or whatever AI you use.

I run a small team that uses Cursor, Claude Code, Gemini CLI and GitHub Copilot CLI. Cursor Remote Control now lets the iOS app see and message local agents after a desktop pairing approval, and it is on by default for every plan except Enterprise. Claude Code v2.1.292 fixes hook approvals and auto mode skipping the prompt for file reads from network (UNC) paths, along with other permission fixes, but npm stable was still v2.1.285 at 6:04 AM ET on 7 October 2026. Gemini CLI v0.63.0 lets non-interactive runs execute multi-step plans without confirmation, and Copilot CLI v1.0.93-4 is a pre-release that says sandboxing is available to all users while the docs still call it experimental. Using our Cursor plan, the output of claude --version and gemini --version from each machine, and a list of our headless jobs that I will paste, write a short checklist that says which machines should keep Remote Control on, which Claude Code machines need a canary of v2.1.292, which Gemini jobs need tighter tools or a throwaway checkout before upgrading, and whether anyone should touch the Copilot pre-release. Do not invent settings or versions I did not give you, and ask me for anything you need instead of guessing.

Go deeper in Grok

Explore each Top Story in Grok. Links open in a new tab. On phones, the same link may open the Grok app if you have it installed (via your device's normal link handling).

Article: Cursor Remote Control Is On by Default. Claude Code's UNC Fix Is Not on Stable.

Privacy: links open grok.com in your session only. AIDevPulse does not run your prompts through our API.

Leave a Comment