> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cimento.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# What data Agent Hub collects

> The exact allowlist of fields the Cimento endpoint agent sends, what never leaves the device, and how to verify it yourself.

The hook payloads Cursor, Claude Code and Codex hand to the endpoint agent contain source code, prompts, model output, file contents and tool arguments. None of that leaves the machine. The agent applies an explicit allowlist: only the fields below are ever written to the buffer, and the ingest endpoint rejects any event carrying a field not in the schema.

## Never leaves the device

| Data | Why it is dropped |
| - | - |
| Prompts and model output | Verbatim conversation content. |
| Source code, file contents, diffs | Includes the before and after text of every edit. |
| Tool inputs and outputs | Raw tool arguments and results can contain secrets and source. |
| Terminal output, MCP request and response bodies | Raw I/O. |
| Raw shell command lines | Only the binary name is kept, for example `git`, never its arguments. |
| Full filesystem paths | Only the last segment of the workspace folder is kept. |
| Conversation transcript paths | Point at the full local transcript. |

## What is sent

| Field | Description |
| - | - |
| `event_id` | Time-ordered UUID minted on the device. Used to de-duplicate. |
| `schema_version` | Version of this contract. |
| `hook_event_name` | Which hook fired, for example a tool call, a file edit, or a prompt submission. Names only. |
| `agent_kind` | `cursor`, `claude_code` or `codex`. |
| `user_email` | Resolved by the drain from the MDM-managed source, or the device serial when unattributed. |
| `occurred_at` | Timestamp. |
| `agent_version` | Version of the coding agent. |
| Tool name | Which built-in or MCP tool was called. |
| `command_prefix` | The binary name from a shell command, with arguments removed. |
| `workspace_root_basename` | The last path segment of the project folder. |
| MCP server identity | The server's command and URL, secret-scrubbed as described below. |
| Configuration snapshot | Facts about how the agent is configured, described below. |

### MCP server identity

To answer "is this MCP server what it claims to be", the agent reports each configured server's command and URL rather than a hash, since a hash cannot be triaged. Before they leave the device, credential-shaped flags and values in the command (`--token=...`, `KEY=value`, the value after `--header`) are replaced with `<redacted>`, and every query-string value in the URL is stripped, keeping only the scheme, host, path and parameter names.

### Configuration snapshot

Periodically the agent reports how each coding agent is configured so misconfigurations can be flagged: the permission mode, counts of additional directories and MCP servers, the names (never values) of environment variables and headers each MCP server is given, which hook events have handlers and how many, the number of rules files per scope (never their contents or paths), and aggregate project trust levels for Codex (never project paths).

## Enforcement on both ends

The allowlist is a closed schema. The hook can only serialize the declared fields, and the ingest endpoint validates every event against the same schema with unknown fields rejected. An event that somehow carried a prompt or file contents would be refused, not stored.

## Verify it yourself

The buffer is a readable text file at `~/.cimento/telemetry.ndjson` on every device. Open it to see exactly what will be sent on the next drain. Setting `CIMENTO_TELEMETRY_DISABLED=1` in the environment stops all collection on that device.
