Best Practices, Pitfalls, and Pro Tips
Cursor can make you much more productive, but it can also introduce new failure modes if you're not thoughtful about how you use it. This lesson is about using AI assistance wisely: getting the most out of it while protecting yourself from its risks.
What You'll Learn
- Why reviewing AI-generated code is non-negotiable
- How to write prompts that get better results
- The common pitfalls that trip up developers new to AI coding tools
- Privacy considerations when working with Cursor
- When AI assistance is the wrong tool for the job
- How Cursor fits into a broader developer toolkit
- How to keep up as Cursor changes
Always Review AI-Generated Code
This is the most important principle in this lesson: never merge AI-generated code you haven't read and understood.
Why Reviewing Matters
AI-generated code looks correct far more often than it is correct. The formatting is clean, the naming conventions are reasonable, and it compiles without errors. But it may:
- Introduce subtle logic bugs that only manifest in edge cases
- Use an API incorrectly (e.g., calling a function with arguments in the wrong order)
- Silently handle errors in ways you didn't intend (swallowing exceptions, returning wrong defaults)
- Add security vulnerabilities (SQL injection, XSS, improperly validated input)
- Duplicate logic that already exists elsewhere in your codebase
- Make assumptions about your data model that are slightly wrong
How to Review AI Code Effectively
Read the diff as if a junior developer wrote it. Ask yourself:
- Does each line do what I think it does?
- Are edge cases handled? What happens with null, empty array, zero, or very large input?
- Is error handling appropriate, or is the function silently failing?
- Does this fit the existing patterns and conventions in the codebase?
- Would I be able to maintain and debug this code a year from now?
If you can't answer these questions confidently, you need to understand the code better before accepting it.
Don't Blindly Accept Suggestions
Tab completion and inline suggestions are frictionless. That's their strength and their danger. It's easy to get into a rhythm of pressing Tab without fully reading what you're accepting.
The Complacency Trap
When suggestions are right 90% of the time, you start trusting them by default. But the 10% of cases where they're wrong can introduce bugs that are hard to find precisely because the code looks so natural.
Breaking the Habit
- Slow down when accepting multi-line suggestions
- Read every line of a generated function before pressing Tab or accepting a diff
- Use Cmd+→ to accept a suggestion one word at a time when you only want part of it
- If you're not sure what a suggestion does, ask the agent to explain it before accepting
- Use Cmd+Z freely. It's much faster to undo a bad suggestion right away than to debug it later
- Be careful with Cmd+Return (accept all). Use it only after you've read the changes
Keep Prompts Specific and Contextual
Vague prompts produce vague results. The quality of what Cursor produces is directly proportional to the quality of the context you provide.
What Makes a Prompt Specific
A weak prompt: "Fix this function."
A strong prompt: "This function is supposed to return the total price of a cart, including tax. It's currently returning the pre-tax total. The tax rate is stored in cart.taxRate as a decimal (e.g., 0.08 for 8%). Fix the calculation and make sure the return value is rounded to 2 decimal places."
The strong prompt includes:
- What the function is supposed to do
- What it's currently doing wrong
- The specific data format involved
- The exact expected output format
Add Architectural Context When Relevant
For larger changes, help Cursor understand the surrounding system:
This is an Express.js REST API. We use Zod for input validation, Prisma for database access, and we throw
HttpErrorinstances for 4xx responses. Update this handler to follow those patterns.
With this context, Cursor will produce code that fits your stack rather than a generic implementation that you'd need to adapt.
Put Repeated Context in Rules
If you find yourself typing the same stack details into every prompt, move them into a project rule (a file in .cursor/rules/) or an AGENTS.md file at the root of your project. The agent then picks up that context automatically. Older projects may still have a .cursorrules file; move its contents to .cursor/rules or AGENTS.md.
Constraints Are Your Friend
Telling Cursor what not to do is as useful as telling it what to do:
Refactor this function without changing its public interface. Don't add any new dependencies. Keep the logic in a single file.
Use Version Control as a Safety Net
Version control is your most important protection when working with AI-generated code at speed.
Commit Before You Let AI Make Changes
Before starting an Agent mode session or a large Cmd+K refactor, commit your current working state. If the AI goes off the rails, you can revert cleanly. Cursor's checkpoints (click one in the chat timeline to restore files to that point) are a handy extra undo, but git is the safety net you can always rely on.
git add -A && git commit -m "checkpoint before AI refactor"
Review Diffs Before Every Commit
Make it a rule: never commit without reviewing what you're committing. Use git diff --staged or your editor's diff view to read every change, even if you watched Cursor generate it.
Use Branches for Larger AI-Assisted Features
If you're using Agent mode to scaffold a significant new feature, do it on a branch. This lets you:
- Keep a clean main branch
- Review the full diff of the AI's work before merging
- Revert the entire feature if something turns out to be fundamentally wrong
Iterate Rather Than Expecting Perfection
AI assistance is a back-and-forth process, not a vending machine. The first output is almost never the final output.
One Prompt Is Rarely Enough
If the first response isn't right, don't start over. Iterate:
- "Close, but the error handling is missing. Add try/catch around the database call."
- "This works, but it's not handling the case where the array is empty. Fix that."
- "The logic is correct but the naming is confusing. Rename
xtopendingTransactions."
Each iteration costs seconds. Getting a function right through three rounds of follow-up messages is usually faster than writing it from scratch.
Don't Over-Prompt
At the same time, don't write a prompt so long that it becomes harder to write the code yourself. If you're spending more time explaining the requirements than it would take to implement them, just write the code.
Common Pitfalls
Over-Reliance
Using Cursor for everything, even things you can easily write yourself, can erode your skills over time. Keep writing straightforward code by hand. AI assistance should augment your capabilities, not replace them.
Accepting Bugs
The most dangerous AI-generated code is code that almost works. A function that handles 95% of cases correctly but silently fails on 5% is worse than a function that throws an obvious error. The silent failure can corrupt data or cause security issues without any visible symptom.
Ignoring Context Limits
Every model has a context window limit. In very long conversations, earlier details can get summarized or lost. If you notice the agent giving advice that contradicts something it said earlier, or ignoring a constraint you mentioned, context is likely the issue. Start a new chat (Cmd+N) for each new task and restate the key details, or reference an earlier conversation with @Chats.
Not Reading Diffs
Agent mode can change many files in one run, and parallel or cloud agents can hand you even bigger changes at once. Each change appears as a diff. Developers who don't read these diffs are accepting a black box into their codebase. Make it a non-negotiable practice to read every file that was modified and understand every change.
Using the Wrong Mode
Agent mode is not always the right choice. Use Ask mode when you only want answers (it can't edit files), Plan mode when the task is large or unclear, and Agent mode when you're ready for changes. Picking the right mode up front prevents a lot of unwanted edits.
Accepting Outdated Patterns
AI models have training cutoffs. They may suggest deprecated APIs, outdated security practices, or patterns that have been superseded in newer versions of a library. When in doubt, cross-check with the official documentation, or ask the agent to look up the current docs.
Privacy Considerations
Cursor sends your code and prompts to AI model providers. This has implications depending on your work context.
What Gets Sent
- Code from your open files and files you've @-mentioned
- Files the agent reads on its own while searching your codebase
- Content you paste into the chat
- Terminal output when you use @Terminals or when the agent runs commands
What to Consider
- Proprietary code: Check your company's policy on using AI coding tools with internal codebases. Some organizations restrict this entirely.
- Secrets and credentials: Never paste API keys, passwords, database connection strings, or private keys into the chat. Never hard-code them either. Because the agent can read files on its own, list files like
.envin.cursorignore. Treat that as best-effort, not a hard wall: the agent can still run a terminal command such ascat .env, so read terminal commands before you approve them. - PII (Personally Identifiable Information): Avoid pasting real user data, customer records, or other PII into the chat. Use anonymized or synthetic data when debugging data-related issues.
- Cursor's privacy settings: Cursor offers privacy options that control whether your code can be stored or used for training. Review them in Cursor Settings, and check whether your team admin has already set them for you. Settings and names can change, so check Cursor's docs.
When NOT to Use AI Assistance
AI is a powerful tool but not always the right one. Knowing when to reach for it and when to work without it is a sign of maturity as a developer who uses AI.
Avoid AI When:
- You're learning something new: If you're deliberately learning a new concept, writing the code yourself (even slowly) builds understanding that copying AI output does not. Use AI to explain concepts, but write the code yourself.
- Security-critical code: Cryptographic implementations, authentication logic, and authorization checks deserve your full manual attention. AI can introduce subtle vulnerabilities that are easy to miss on casual review.
- You can write it in 30 seconds: Not every function needs AI. If you can type it faster than you can explain it, just type it.
- The requirements are unclear: AI is good at implementing clear requirements. If you don't know what you need, decide that first. Plan mode can help by asking clarifying questions, but the decisions are yours to make.
- You're deep in a complex debugging session: Once you're in the mental flow of tracing through a system, AI context-switching can break your concentration. Some bugs are best solved by steady human reasoning.
Combining Cursor with Other Tools
Cursor works best as part of a broader developer toolkit, not as a replacement for it.
The Terminal
Your terminal remains essential. Use it for version control, running scripts, managing environments, and anything that doesn't have good editor integration. Cursor also has a CLI, so you can run the same agent from the terminal when that fits your workflow better.
Parallel Agents, Cloud Agents, and Other AI Tools
Cursor's agents don't only run in the editor side panel. The Agents Window can run several agents in parallel, Cloud Agents can work in the background and return a pull request, and Bugbot can review your PRs. These are covered in their own lesson. Other AI tools, such as Claude Code, can also complement Cursor. Use the right tool for the task.
Documentation
AI cannot replace reading documentation for a library you're learning. It can synthesize and summarize docs, but building a real understanding of a technology still requires engaging with the official source. Use Cursor to help you apply what you've read, not as a substitute for reading it.
Code Search and Static Analysis
Tools like grep, your IDE's find-in-files, and static analysis linters catch issues that AI misses. Don't let AI assistance reduce your use of these tools. They complement each other.
Staying Up to Date with Cursor
Cursor is updated often. New features, new models, changed behavior, and new integrations ship regularly, and the names of panels and shortcuts sometimes change too.
How to Stay Current
- Follow the Cursor changelog: The official changelog (cursor.com/changelog) is the most reliable source for what's new
- Check the Cursor forum and community: Other developers surface useful tips and workflows that often aren't in the docs
- Revisit your habits from time to time: A workflow you've used for months might have a better alternative now. Check whether new features change your approach
- Update Cursor regularly: New versions often include meaningfully better AI behavior, not just UI changes
Feature Discovery
Cursor regularly ships features that aren't widely advertised. Browse Cursor Settings, the Customize page (where rules, skills, MCP servers, subagents, commands, and hooks live), and the docs now and then. You'll often find features you didn't know existed.
Key Takeaways
- Always review AI-generated code: Clean, compiling code is not the same as correct code. Read every diff with the same critical eye you'd apply to a junior developer's PR
- Specificity pays off: Vague prompts produce vague results; include what the code should do, what it currently does wrong, and any relevant constraints. Put repeated context in project rules or AGENTS.md
- Version control is your safety net: Commit before large AI operations and review every change before staging it; checkpoints are a bonus, not a replacement
- Iterate, don't perfect the prompt: Several short rounds of follow-ups beat one long, exhaustive prompt
- Know the pitfalls: Over-reliance, accepting bugs, ignoring context limits, not reading diffs, and using the wrong mode are the failure modes to watch for
- Privacy matters: Never paste secrets, credentials, or PII into the chat; check your organization's policies on AI tools
- Know when not to use AI: Security-critical code, genuine learning moments, and clear-headed debugging sessions are better done without AI assistance
- Cursor is one tool in the kit: Use it alongside your terminal, documentation, static analysis, and other AI tools, since each has its own strengths

