The last two years of coding agents were a location fight dressed up as a model fight. Who holds the repo. Who sees the secrets. Who pays for the minutes the agent spends waiting on tests.
Techzine’s write-up of Cloudflare Sandboxes is the first version of that fight that does not pretend the model is the product. Cursor Cloud Agents already plan, write code, run terminal commands, and execute tests in isolated remote environments. What changed is the room those tool calls happen in. Terminal, filesystem, and browser actions now have the option to run inside a customer-controlled Cloudflare sandbox.
That is a different announcement from last week’s Gemini 3.8 Flash token-bill story. Flash is a model. This is a place to let an agent touch a checkout.
What Cursor Cloud Agents already were
Techzine describes them as cloud-hosted assistants for long-running engineering work. They are useful when the code cannot be reached from outside the company’s network. If you have been using Cursor Self-Hosted Machines, this is another execution target, not a new personality.
The sentence that matters: tool calls run in the sandbox you control. Build caches, secrets, and the working tree do not have to live in a vendor’s default fleet because the chat UI is pretty.
Cloudflare CTO Dane Knecht said the quiet part in a quote Techzine printed in full. Developers want the tools they already like. Enterprises want those tools to run somewhere the security team can describe. “Bringing Cursor Cloud Agents to Cloudflare Sandboxes is another step toward making Cloudflare the execution layer for the next generation of agentic applications.”
Execution layer is a vendor phrase. Translated: Cloudflare wants to be where the agent is allowed to type.
Techzine also identifies Cursor users as SpaceXAI users, and says SpaceXAI acquired Anysphere in June. If you still have Anysphere on a vendor list, update the row. The product name on the laptop did not change as much as the parent company line.
The other half of the launch is a scanner
Simply Wall St, via Yahoo Finance, bundled the sandbox news with a second product: AI-powered vulnerability discovery and remediation for enterprise customers, built on OpenAI models. Automated, context-aware workflows. Find a weakness, propose a fix, keep the loop inside Cloudflare’s platform.
That is the consolidation pitch. Why split spend across Cloudflare, CloudFront, and Azure Front Door if the same vendor will now host the agent that writes the patch and the scanner that filed the ticket.
The same article is honest about money. Cloudflare’s “Act 4” and AI initiatives still do not have a clean story for how detection, remediation, or agent minutes turn into high-margin, transaction-based revenue. Analysts, in that write-up, treat packaging and pricing as the real test. Market cap in the piece: $97.1 billion. That number does not tell you what a sandbox-hour costs.
If you are a buyer, ask for the SKU. Sandbox compute, log retention, whether browser tool calls leave the isolation boundary, whether the OpenAI-backed scanner trains on your diffs. None of that is in the launch notes we have.
Why a sandbox is not a policy
Isolation is a place. Policy is who is allowed to ask the agent to terraform apply.
A customer-controlled Cloudflare environment can still hold production credentials if you put them there. It can still exfiltrate a .env if the agent has network and you did not deny it. It can still write a plausible patch that compiles and fails open.
We have been around the enterprise version of this. Yesterday’s Accenture Gemini FDE story was 1,000 engineers as the product because the software still needs babysitters. Cloudflare is selling the room. Accenture is selling the babysitters. You may need both. You should not confuse them.
For a team that already made Cursor the default, the sandbox option is the first time “we cannot let the agent see the PCI repo” has an answer other than “then don’t use the agent.” That is worth a proof of concept. It is not worth turning on org-wide on Friday.
A practical evaluation, not a keynote
Run one repo that is annoying and not sacred. A docs site. An internal tool with tests. Not the payments service.
Write down where the working tree lives, where the cache lives, and where stdout goes. If those three answers are “Cloudflare, we think,” you do not have a design yet.
Time a full agent loop: plan, patch, test, pull request. Compare it to the same loop on Cursor’s default cloud and on a self-hosted machine. The sandbox only wins if the extra hop is cheaper than the argument with InfoSec.
Ask whether browser tool calls are in-sandbox or a separate browser farm. Techzine lists browser actions next to terminal and filesystem. Those are not the same risk.
Ask whether the vulnerability scanner can file issues without the agent having write access to main. Discovery and remediation glued together is how you get an LLM merging its own findings.
Keep a human on the merge button for the first month. If that sentence feels like a waste of the product, you are not buying an agent. You are buying a story about not having to staff review.
How this lands in a real org chart
Security will ask whether the sandbox is SOC2-inheriting or a new review. That question has delayed more agent rollouts than model quality has. Get Cloudflare’s shared-responsibility note in the ticket on day one, not after a demo that impressed engineering.
Legal will ask whether OpenAI, via the scanner, sees customer source. “Built on OpenAI models” is the phrase in the Yahoo piece. That is enough to trigger a vendor review if you already banned sending code to a public LLM. If the scanner is optional, keep it off the POC. The sandbox can stand without it.
Platform will ask why this is not just Kubernetes jobs you already run. Fair. Self-hosted Cursor machines already existed. The Cloudflare option is for teams that do not want to operate those machines and do not want the default Cursor cloud either. If you already operate the machines well, you may not need a third place.
Finance will ask why NET is in the cart when the IDE seat is already on the bill. Until packaging is public, the honest answer is “we are testing whether InfoSec will accept this path.” That is a valid experiment. It is not a three-year contract.
Logs, or you will debug folklore
Agent runs without logs are campfire stories. You need:
- the prompt and tool-call trace, retained on a timer you chose
- whether the sandbox had egress, and to where
- the diff the agent proposed, stored even if the PR closed
- who clicked merge
If Cloudflare cannot export that to the SIEM you already pay for, you are adding a second history of the same incident. That is how postmortems become two PDFs that disagree.
What this is not
It is not a model release. Astra and Gemini 3.8 already had their weeks.
It is not proof that Cloudflare will win agent runtime. Knecht said they want to. Wanting to be the execution layer is the strategy. Customers moving CI secrets is the evidence, and we do not have it yet.
It is not free. The Yahoo piece flags monetisation as unsolved. Until there is a public price, assume the sandbox is a wedge for the rest of the platform bill.
If your constraint is “the agent cannot leave our network,” this is the first vendor pairing that says that sentence back to you without making you host the whole IDE. Try it on a repo you can burn. Then read the invoice.
One more boring gate: identity. If the agent authenticates to GitHub as a shared bot, you will not know which human asked it to touch prod. Bind the sandbox run to the engineer who clicked go, even if the git author is a machine user. Cloudflare can be the room. It should not be the alibi.
Self-hosted machines still win if your data cannot land on a public cloud, even a customer-controlled one. A sandbox in Cloudflare is still Cloudflare. Teams in regulated shops already had that argument for Workers. Reuse the same memo. Do not write a new one that pretends coding agents are a special cloud.
If the POC works, write the allowlist before you celebrate. Which repos, which branches, which secrets, which hours. Agents expand into the gaps you did not name. Cloudflare will not name them for you. Neither will Cursor. That is the job you kept when you refused to host the IDE. Write it in the ticket, not in a slide. If InfoSec signs the ticket, keep the screenshot. Verbal yes evaporates at the next reorg. Put the allowlist in the same ticket as the POC results so nobody has to hunt Slack. That is the whole review. Do not skip it.