Skip to main content
The hook payloads Cursor, Claude Code and Codex hand to the endpoint agent contain source code, prompts, model output, file contents and tool arguments. None of that leaves the machine. The agent applies an explicit allowlist: only the fields below are ever written to the buffer, and the ingest endpoint rejects any event carrying a field not in the schema.

Never leaves the device

What is sent

MCP server identity

To answer “is this MCP server what it claims to be”, the agent reports each configured server’s command and URL rather than a hash, since a hash cannot be triaged. Before they leave the device, credential-shaped flags and values in the command (--token=..., KEY=value, the value after --header) are replaced with <redacted>, and every query-string value in the URL is stripped, keeping only the scheme, host, path and parameter names.

Configuration snapshot

Periodically the agent reports how each coding agent is configured so misconfigurations can be flagged: the permission mode, counts of additional directories and MCP servers, the names (never values) of environment variables and headers each MCP server is given, which hook events have handlers and how many, the number of rules files per scope (never their contents or paths), and aggregate project trust levels for Codex (never project paths).

Enforcement on both ends

The allowlist is a closed schema. The hook can only serialize the declared fields, and the ingest endpoint validates every event against the same schema with unknown fields rejected. An event that somehow carried a prompt or file contents would be refused, not stored.

Verify it yourself

The buffer is a readable text file at ~/.cimento/telemetry.ndjson on every device. Open it to see exactly what will be sent on the next drain. Setting CIMENTO_TELEMETRY_DISABLED=1 in the environment stops all collection on that device.