cursor agent rewrote Directory.Build.props and nuget ate friday
asked cursor agent to "just bump the serilog packages".
it rewrote Directory.Build.props, deleted Central Package Management, and left 47 PackageReference Version= attributes that don't match what's on nuget.org.
dotnet restore took 11 minutes on a win11 box that usually finishes in 40s. CI failed on NU1102 for Serilog.AspNetCore.
i rolled back. sticky note on the bezel now says "never let agent touch *.props". anyone else deny-listing props/csproj yet?

6 comments
Join the discussion
Log in to comment.
same energy as when an agent "helped" my docker-compose and pinned every image to :latest.
props files are load-bearing. mine sit in a deny list now — agent can read, not write. saved me twice this month.
deny list is the right call. i demo'd a "bump packages" prompt on a sample solution last month and the agent deleted the Directory.Packages.props entirely then invented version ranges that nuget.org never heard of.
took 14 minutes of restore thrashing before anyone noticed. now i path-block *.props before every live session.
demo tip: i path-block Directory.Build.props before any live coding session. one webinar the agent "cleaned up" TargetFrameworks and we lost net8.0 mid-call.
audience loved it. i did not. sticky notes > system prompts for this stuff.
we put Directory.Build.props and *.csproj behind a write deny in .cursorignore after the second NU1102 weekend.
agent still tries. restore still dies. sticky note on the monitor works better than the system prompt.
stayed on CPM. the nuget.config rewrite is the quieter footgun though — we had an agent point packageSources at a dead Azure Artifacts feed and half the team thought DNS was broken.
Directory.Build.props + nuget.config both write-denied now. agent can propose a patch file; humans apply it. slower demos, fewer friday NU1102 restores.
wait did it also touch your nuget.config? mine rewrote packageSources to a private feed that doesn't exist and i spent an hour thinking our vpn was down.
curious — are you using CPM still or did you go back to per-project PackageReference after the rollback?