What I Learned at the Cursor MeetupЧто я вынес с Cursor meetup

My AI bot found an official Cursor meetup
And added it to my calendar. Twice, though — the dedup still needs fixing 😅
In Da Nang, this was the first interesting AI event I’d seen in four months. What I wanted from the meetup wasn’t primarily the talks, but people who are just as deeply immersed in AI development: testing different approaches, building products, and able to discuss how agents work for hours.
The official Cursor meetup in Da Nang.
I don’t have enough people like that around me. So I’d happily attend meetups and hackathons hosted by Anthropic, OpenAI, ElevenLabs, and other LLM teams.
The talk itself turned out to be too basic for me
When one developer asked why anyone should use Cursor’s ready-made harness instead of building their own, it turned out that most of the room didn’t know what a harness was. That was when I realized there wouldn’t be a deep dive that day.
No complaints about the audience — I’d just expected more practical cases and details about the tool. I recently completed Claude Code in Action by Anthropic: it seems like a basic course, but it contains lots of useful, concrete advice on organizing your workflow (recommended). That’s the layer I felt was missing from the meetup.
Participants at the Cursor meetup in Da Nang.
In the end, the most interesting part started after the talk, when we could actually speak with people.
Networking after the talk. P.S. The protein bars being promoted turned out to have a high fat content :( And I’d already taken a photo with them… 😅
What I still took away from it
Once you have several agents, the problem is no longer whether they can write code. The problem is how to organize their work so they don’t break one another’s changes and actually bring a task to a finished result.
I haven’t used conventional PR processes much for this yet. I want to try a setup where agents work independently, submit changes for review, address feedback, and have tests automatically verify the result before merge.
Technically, it’s just the usual branches, PRs, and CI — except the participants are now agents rather than people.
At this point, my wife said it was getting harder to follow. How about you? Still with me, shall we keep going? 😅
One more takeaway: an agent should be able to test the entire product — open the interface, go through a user flow, and make sure everything works. In other words, you need proper E2E, not just backend unit tests.
This continues my previous takeaway about 11 AI agents needing a manager too.
The most interesting case was about security
During an internal cyber test, an agent using a combination of OpenAI models, including GPT-5.6 Sol and a private prerelease model, was running with weakened restrictions. To find answers to a benchmark, it escaped the sandbox and hacked Hugging Face. Meanwhile, HF couldn’t run the same model in response because of its built-in restrictions. Over several days, the agent performed around 17,600 actions 🤯😱
What interests me most here isn’t the exploit itself, but the asymmetry of access: one team can run frontier models with weakened restrictions, while another gets a refusal when trying to investigate their actions.
This case probably deserves a separate post.

Мой AI-бот нашёл официальный Cursor meetup
И добавил его в календарь. Правда, дважды — dedup ещё нужно чинить 😅
В Дананге это первый интересный AI-ивент, который я увидел за четыре месяца. От встречи мне в первую очередь были нужны не доклады, а люди, которые так же глубоко погружены в AI-разработку: тестируют разные подходы, собирают продукты и могут часами обсуждать работу агентов.
Официальный Cursor meetup в Дананге.
Мне таких людей вокруг не хватает. Поэтому я с удовольствием ходил бы на встречи и хакатоны от Anthropic, OpenAI, ElevenLabs и других LLM-команд.
Само выступление оказалось для меня слишком базовым
Когда один разработчик спросил, зачем вообще использовать готовый harness Cursor, если можно собрать свой, оказалось, что большая часть зала не знает, что такое harness. В этот момент я понял, что deep dive сегодня не будет.
К аудитории вопросов нет, просто я ожидал больше прикладных кейсов и особенностей инструмента. Недавно я прошёл Claude Code in Action от Anthropic: вроде базовый курс, а внутри много полезной конкретики по организации работы (рекомендую). Вот такого слоя мне на митапе не хватило.
Участники Cursor meetup в Дананге.
В итоге самое интересное началось уже после выступления, когда можно было поговорить с людьми.
Нетворкинг после выступления. P.S. Промотируемые протеиновые батончики оказались с высоким процентом жира в составе :( А я уже с ними сфоткался… 😅
Что я всё-таки забрал себе
Когда агентов становится несколько, проблема уже не в том, умеют ли они писать код. Проблема в том, как организовать их работу, чтобы они не ломали изменения друг друга и доводили задачу до готового результата.
Я пока мало использую для этого привычные PR-процессы. Хочу попробовать схему, где агенты работают независимо, отправляют изменения на review, исправляют замечания, а тесты автоматически проверяют результат перед merge.
Технически это обычные ветки, PR и CI — только участники процесса теперь не люди, а агенты.
На этом моменте жена сказала, что стало сложнее понимать. А вам как? Нормально, читаем дальше? 😅
И ещё один вывод: агент должен уметь проверить продукт целиком — открыть интерфейс, пройти пользовательский сценарий и убедиться, что всё работает. То есть нужен нормальный E2E, а не только backend unit-тесты.
Это продолжение моего прошлого вывода про 11 AI-агентов, которым тоже нужен менеджер.
Самый интересный кейс был про security
Во время внутреннего cyber-теста агент на связке моделей OpenAI, включая GPT-5.6 Sol и закрытую prerelease-модель, работал с ослабленными ограничениями. Чтобы найти ответы к бенчмарку, он вышел из sandbox и взломал Hugging Face. При этом HF не могли в ответ запустить такую же модель из-за встроенных в неё ограничений. За несколько дней агент совершил около 17 600 действий 🤯😱
Для меня здесь интереснее всего не сам exploit, а асимметрия доступа: одна команда может запускать frontier-модели с ослабленными ограничениями, а другая — получать refusal при расследовании их действий.
Про этот кейс, пожалуй, стоит написать отдельно.