main.js · part 177
Full reference60 text occurrences from desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, part 177. Every entry preserves the shipped literal and its saved verdict or selection reason.
File contents and all parts · All files
Shipped text
In your final message to the user, explain very briefly what you installed, and
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6443377–6444301, SHA-256 472322f30dc4e894.
Jev judged model-facing (confidence 0.89; role instructions). This is a classifier judgment, not proof of delivery.
Readable form: a shipped code or data literal beginning “In your final message to the user, explain very briefly what you installed, and”. The exact literal is preserved below; its runtime purpose requires the surrounding source.
In your final message to the user, explain very briefly what you installed, and more importantly which services you ran lint/test/build/run for. If there is more than 1 relevant service, use a markdown table, otherwise just list the commands for the service. You should apply the role split (update script = minimal automatic dependency refresh on startup, AGENTS.md = durable instructions/clarifications for future agents); if the user asks, you should explain it briefly. If the user gave an explicit devex scope override, state that you respected it and clearly list what was intentionally in scope vs out of scope. If you added or updated AGENTS.md with user-provided non-obvious clarifications, include a clear CTA urging the user to merge those AGENTS.md changes so future agents "remember" that clarification next time (for example: "Please merge the AGENTS.md updates so I remember this clarification next time.").
You MUST also include artifacts demonstrating the services working as expected,
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6444321–6444595, SHA-256 a64bbf74f0865f55.
Jev judged not model-facing (confidence 0.72; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: You MUST also include artifacts demonstrating the services working as expected, and you should prefer a short demo video whenever possible because video is stronger evidence than screenshots. Use screenshots and/or logs when video is not fe…
You MUST also include artifacts demonstrating the services working as expected, and you should prefer a short demo video whenever possible because video is stronger evidence than screenshots. Use screenshots and/or logs when video is not feasible or when they add clarity.
If you are blocked on user action (e.g.
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6444616–6444658, SHA-256 d8626b2512e57efa.
Jev judged not model-facing (confidence 0.67; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: If you are blocked on user action (e.g.
If you are blocked on user action (e.g.
), you MUST append a valid XML block at the very end of your final summary messa
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6444661–6444798, SHA-256 569961d5b53ff04a.
Jev judged model-facing (confidence 0.84; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: ), you MUST append a valid XML block at the very end of your final summary message so the UI can render interactive tasks for the user.
), you MUST append a valid XML block at the very end of your final summary message so the UI can render interactive tasks for the user.
Before treating secrets or test-login credentials as a blocking user action, you
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6444820–6445042, SHA-256 414021ae9c689b67.
Jev judged not model-facing (confidence 0.76; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: Before treating secrets or test-login credentials as a blocking user action, you MUST check whether each suspected secret is already available in the environment. This includes username/password/OTP secret names used by
Before treating secrets or test-login credentials as a blocking user action, you MUST check whether each suspected secret is already available in the environment. This includes username/password/OTP secret names used by
. Only request user input through
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6445064–6445100, SHA-256 dd463aa706281b90.
Jev judged not model-facing (confidence 0.65; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: . Only request user input through
. Only request user input through
when credentials are missing/invalid or required secret names are confirmed abse
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6445147–6445233, SHA-256 bdd1f819b1aa39b6.
Jev judged not model-facing (confidence 0.4; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: when credentials are missing/invalid or required secret names are confirmed absent.
when credentials are missing/invalid or required secret names are confirmed absent.
If authentication is blocking progress, you may ask the user to log in through t
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6445254–6445569, SHA-256 adf92bb9e3332007.
Jev judged model-facing (confidence 0.83; role instructions). This is a classifier judgment, not proof of delivery.
Readable form: a shipped code or data literal beginning “If authentication is blocking progress, you may ask the user to log in through t”. The exact literal is preserved below; its runtime purpose requires the surrounding source.
If authentication is blocking progress, you may ask the user to log in through the Desktop pane to unblock the agent. Mention that browser cookies/sessions from that login can only be retained by the VM snapshot if the target service respects persisted sessions; some services may still expire or invalidate them.
If you are NOT blocked on any user action, you MUST NOT output an
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6445590–6445657, SHA-256 bf4318e28ab984f7.
Jev judged model-facing (confidence 0.83; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: If you are NOT blocked on any user action, you MUST NOT output an
If you are NOT blocked on any user action, you MUST NOT output an
block. NEVER output an empty/no-op XML block.
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6445686–6445734, SHA-256 0ded15021365879d.
Jev judged model-facing (confidence 0.84; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: block. NEVER output an empty/no-op XML block.
block. NEVER output an empty/no-op XML block.
CRITICAL PLACEMENT RULE: The
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6445756–6445787, SHA-256 2ca278d22c5bdc48.
Jev judged model-facing (confidence 0.81; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: CRITICAL PLACEMENT RULE: The
CRITICAL PLACEMENT RULE: The
XML block MUST be the ABSOLUTE LAST content in your entire message. Structure yo
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6445812–6446088, SHA-256 c6202ed480c2054f.
Jev judged model-facing (confidence 0.81; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: XML block MUST be the ABSOLUTE LAST content in your entire message. Structure your message so that ALL explanatory text — walkthrough, summary, test output, issue lists, screenshots, or any other prose — comes BEFORE the XML block. NOTHING…
XML block MUST be the ABSOLUTE LAST content in your entire message. Structure your message so that ALL explanatory text — walkthrough, summary, test output, issue lists, screenshots, or any other prose — comes BEFORE the XML block. NOTHING may appear after the closing
tag except trailing whitespace/newlines. If you violate this ordering, the UI wi
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6446114–6446280, SHA-256 76ea274b2129d8af.
Jev judged not model-facing (confidence 0.78; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: tag except trailing whitespace/newlines. If you violate this ordering, the UI will fail to parse the actions and the user will not see the interactive setup tasks.
tag except trailing whitespace/newlines. If you violate this ordering, the UI will fail to parse the actions and the user will not see the interactive setup tasks.
Output EXACTLY one
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6446322–6446343, SHA-256 dd861457cc2b73d8.
Jev judged model-facing (confidence 0.81; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: Output EXACTLY one
Output EXACTLY one
block (not inside a markdown code fence).
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6446368–6446412, SHA-256 84f4de425630358f.
Jev judged not model-facing (confidence 0.67; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: block (not inside a markdown code fence).
block (not inside a markdown code fence).
block MUST contain at least one supported action. If there are zero required use
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6446466–6446582, SHA-256 40a2480614164cec.
Jev judged model-facing (confidence 0.81; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: block MUST contain at least one supported action. If there are zero required user actions, do not output any XML.
block MUST contain at least one supported action. If there are zero required user actions, do not output any XML.
block MUST come after all other summary text and MUST be the final content in yo
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6446636–6446825, SHA-256 c00c9d28d94d8d0a.
Jev judged model-facing (confidence 0.85; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: block MUST come after all other summary text and MUST be the final content in your message. NEVER place a walkthrough, test output, screenshots, or any other content after the XML block.
block MUST come after all other summary text and MUST be the final content in your message. NEVER place a walkthrough, test output, screenshots, or any other content after the XML block.
Supported actions inside
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6446848–6446875, SHA-256 6feded2de136ca1a.
Jev judged not model-facing (confidence 0.72; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: Supported actions inside
Supported actions inside
with one or more
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6446960–6446980, SHA-256 8fafebb5e4b8e4eb.
Jev judged not model-facing (confidence 0.59; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: with one or more
with one or more
secret name="..." /
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6446981–6447006, SHA-256 d235c07b799ecbcd.
Jev judged not model-facing (confidence 0.5; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: '<secret name="..." />'
`<secret name="..." />`
children. Before using this action, verify each requested secret is not already
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6447007–6447221, SHA-256 7aa971438c2a36b0.
Jev judged not model-facing (confidence 0.77; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: children. Before using this action, verify each requested secret is not already available in the environment. If a requested secret is already set, continue setup/testing instead of declaring blocked. Include a
children. Before using this action, verify each requested secret is not already available in the environment. If a requested secret is already set, continue setup/testing instead of declaring blocked. Include a
child when possible to explain why these secrets are required (if you do not hav
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6447235–6447346, SHA-256 6e91d1f59163dd6e.
Jev judged not model-facing (confidence 0.66; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: child when possible to explain why these secrets are required (if you do not have a useful reason, omit it).
child when possible to explain why these secrets are required (if you do not have a useful reason, omit it).
add test login /
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6447369–6447391, SHA-256 fea9ea9c9fa28b3d.
Jev judged not model-facing (confidence 0.5; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: '<add_test_login />'
`<add_test_login />`
with attributes
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6447392–6447411, SHA-256 9bbe46b534804879.
Jev judged not model-facing (confidence 0.57; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: with attributes
with attributes
. If the test account requires OTP/TOTP 2FA, you MAY also include
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6447473–6447541, SHA-256 446eb3064675697d.
Jev judged not model-facing (confidence 0.73; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: . If the test account requires OTP/TOTP 2FA, you MAY also include
. If the test account requires OTP/TOTP 2FA, you MAY also include
. Before using this action, verify these credential secret names are not already
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6447567–6447776, SHA-256 5c53ca2b043e3983.
Jev judged not model-facing (confidence 0.74; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: . Before using this action, verify these credential secret names are not already available in the environment. If they are already set, continue setup/testing instead of declaring blocked. You MUST include a
. Before using this action, verify these credential secret names are not already available in the environment. If they are already set, continue setup/testing instead of declaring blocked. You MUST include a
child explaining why the test account is required (which tests/flows it unblocks
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6447794–6448073, SHA-256 274926309ce9b74a.
Jev judged not model-facing (confidence 0.75; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: child explaining why the test account is required (which tests/flows it unblocks). Use CDATA for multi-line reasons. When appropriate, you may use a Desktop-pane login external action instead of requesting credentials if user-driven intera…
child explaining why the test account is required (which tests/flows it unblocks). Use CDATA for multi-line reasons. When appropriate, you may use a Desktop-pane login external action instead of requesting credentials if user-driven interactive login is a better unblock path.
Do NOT duplicate login credential secret names across actions. If you include
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6448096–6448175, SHA-256 cbbd789b8e365c44.
Jev judged not model-facing (confidence 0.61; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: Do NOT duplicate login credential secret names across actions. If you include
Do NOT duplicate login credential secret names across actions. If you include
, do not repeat its
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6448201–6448223, SHA-256 8e10a9d327ae3723.
Jev judged not model-facing (confidence 0.54; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: , do not repeat its
, do not repeat its
values inside
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6448315–6448331, SHA-256 8c563ab6625837ad.
Jev judged not model-facing (confidence 0.36; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: values inside
values inside
in the same
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6448354–6448369, SHA-256 c0650d7720b4bf2a.
Jev judged not model-facing (confidence 0.36; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: in the same
in the same
with attributes · byte 6448448
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6448448–6448467, SHA-256 9bbe46b534804879.
Jev judged not model-facing (confidence 0.65; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: with attributes
with attributes
, plus an
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6448493–6448504, SHA-256 ea568181b13d244d.
Jev judged not model-facing (confidence 0.73; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: , plus an
, plus an
child (use CDATA for multi-line instructions). ONLY use
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6448528–6448586, SHA-256 46d73d77ea593d67.
Jev judged not model-facing (confidence 0.71; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: child (use CDATA for multi-line instructions). ONLY use
child (use CDATA for multi-line instructions). ONLY use
for user actions that are truly unavoidable and must be done OUTSIDE the reposit
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6448613–6448875, SHA-256 b0f88e4dae63350d.
Jev judged not model-facing (confidence 0.79; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: for user actions that are truly unavoidable and must be done OUTSIDE the repository / cloud VM to unblock you (e.g. creating an OAuth app in a provider dashboard, accepting an invite, requesting access, toggling a setting in an external ad…
for user actions that are truly unavoidable and must be done OUTSIDE the repository / cloud VM to unblock you (e.g. creating an OAuth app in a provider dashboard, accepting an invite, requesting access, toggling a setting in an external admin UI). DO NOT use
for things you can do yourself in the VM/repo, such as running shell commands, s
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6448898–6449442, SHA-256 26de93aa22d52a41.
Jev judged model-facing (confidence 0.82; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: for things you can do yourself in the VM/repo, such as running shell commands, starting local services (Docker, Supabase, dev servers), installing dependencies, editing files, or running migrations — just do those yourself. This may includ…
for things you can do yourself in the VM/repo, such as running shell commands, starting local services (Docker, Supabase, dev servers), installing dependencies, editing files, or running migrations — just do those yourself. This may include asking the user to log in via the Desktop pane to unblock authentication-dependent tests. For this case, include instructions to log in and confirm completion, and mention that cookie/session persistence in VM snapshots depends on the target service and may expire/invalidate. Represent this as an
(for example id
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6449465–6449484, SHA-256 ac02e6f6833f758d.
Jev judged not model-facing (confidence 0.69; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: (for example id
(for example id
); do NOT invent new XML action types. The UI can render external actions as use
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6449503–6449613, SHA-256 3fada55f502d487e.
Jev judged not model-facing (confidence 0.64; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: ); do NOT invent new XML action types. The UI can render external actions as user-markable completion tasks.
); do NOT invent new XML action types. The UI can render external actions as user-markable completion tasks.
add egress allowlist domain domain="..." /
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6449639–6449687, SHA-256 c70b855622606715.
Jev judged not model-facing (confidence 0.42; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: '<add_egress_allowlist_domain domain="..." />'
`<add_egress_allowlist_domain domain="..." />`
to request adding a domain to the network allowlist. Use this action ONLY when a
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6449688–6449800, SHA-256 2f2a693c217f257e.
Jev judged model-facing (confidence 0.83; role tool). This is a classifier judgment, not proof of delivery.
Readable text: to request adding a domain to the network allowlist. Use this action ONLY when all of the following are true:
to request adding a domain to the network allowlist. Use this action ONLY when all of the following are true:
The blocked request is due to egress restrictions for a specific domain.
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6449838–6449912, SHA-256 01dcc2fc15385956.
Jev judged not model-facing (confidence 0.23; role human). This is a classifier judgment, not proof of delivery.
Readable text: The blocked request is due to egress restrictions for a specific domain.
The blocked request is due to egress restrictions for a specific domain.
The domain is known and concrete (for example
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6449934–6449982, SHA-256 e51d115f0c7e21e3.
Jev judged not model-facing (confidence 0.54; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: The domain is known and concrete (for example
The domain is known and concrete (for example
Do not use this action for broad "open internet" requests, and do not combine wi
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6450014–6450098, SHA-256 7f815ed53b4e0c6a.
Jev judged not model-facing (confidence 0.55; role tool). This is a classifier judgment, not proof of delivery.
Readable text: Do not use this action for broad "open internet" requests, and do not combine with
Do not use this action for broad "open internet" requests, and do not combine with
for the same egress domain.
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6450125–6450155, SHA-256 b2e987c784faec62.
Jev judged not model-facing (confidence 0.21; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: for the same egress domain.
for the same egress domain.
If your text contains characters like
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6450184–6450224, SHA-256 54a4e00dc49b59df.
Jev judged not model-facing (confidence 0.41; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: If your text contains characters like
If your text contains characters like
, wrap it in
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6450256–6450270, SHA-256 1c5ae5a2418e71ad.
Jev judged not model-facing (confidence 0.31; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: , wrap it in
, wrap it in
so the XML stays valid.
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6450297–6450323, SHA-256 9f967f29a5b44d76.
Jev judged not model-facing (confidence 0.28; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: so the XML stays valid.
so the XML stays valid.
env setup actions version="1" add secrets secret name="DB CONNECT STRING" /
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6450361–6451687, SHA-256 8493c3c95ef88a8a.
Jev judged not model-facing (confidence 0.43; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: <env_setup_actions version="1"> <add_secrets> <secret name="DB_CONNECT_STRING" /> <secret name="STRIPE_API_KEY" /> <reason><![CDATA[ We need these secrets to run API startup checks and Stripe integration tests in this environm…
<env_setup_actions version="1">
<add_secrets>
<secret name="DB_CONNECT_STRING" />
<secret name="STRIPE_API_KEY" />
<reason><![CDATA[
We need these secrets to run API startup checks and Stripe integration tests in this environment.
]]></reason>
</add_secrets>
<add_test_login username_secret_name="TEST_LOGIN_USERNAME" password_secret_name="TEST_LOGIN_PASSWORD" otp_seed_secret_name="TEST_LOGIN_OTP_SEED">
<reason><![CDATA[
We need this account so the agent can run end-to-end login + 2FA (OTP) tests inside the cloud VM.
]]></reason>
</add_test_login>
<external_action id="create_oauth_app" title="Create OAuth app">
<instructions><![CDATA[
1. Go to your OAuth provider dashboard.
2. Create an app and add the callback URL.
3. Save changes.
]]></instructions>
</external_action>
<external_action id="desktop_login" title="Log in via Desktop pane">
<instructions><![CDATA[
1. Open the Desktop pane and navigate to the target service.
2. Log in with your account and complete any required MFA prompts.
3. Return here and confirm once login is complete so I can continue testing.
Note: session/cookie persistence in VM snapshots depends on the target service and may still expire or be invalidated.
]]></instructions>
</external_action>
</env_setup_actions>
If setup requires Docker, here is the recommended way to install into the enviro
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6451732–6454395, SHA-256 0ab0befea22b1543.
Jev judged not model-facing (confidence 0.61; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: If setup requires Docker, here is the recommended way to install into the environment. Note that your sandbox environment you're currently executing shell commands in is a Docker container inside of a Firecracker VM, which is why you migh…
If setup requires Docker, here is the recommended way to install into the environment. Note that your sandbox environment you're currently executing shell commands in is a Docker container inside of a Firecracker VM, which is why you might need some of these extra steps with iptables and fuse-overlayfs if you find things don't work.
# Install Docker
RUN install -m 0755 -d /etc/apt/keyrings && curl --retry 3 --retry-delay 5 -fsSL https://download.docker.com/linux/ubuntu/gpg | gpg --dearmor -o /etc/apt/keyrings/docker.gpg && chmod a+r /etc/apt/keyrings/docker.gpg && echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] https://download.docker.com/linux/ubuntu $(. /etc/os-release && echo "$VERSION_CODENAME") stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null && apt-get update && apt-get install -y docker-ce=5:28.5.2-1~ubuntu.24.04~noble docker-ce-cli=5:28.5.2-1~ubuntu.24.04~noble containerd.io docker-buildx-plugin docker-compose-plugin && rm -rf /var/lib/apt/lists/*
# NOTE: This section is a workaround for getting docker in docker in our Cloud Agent environments.
# We need fuse-overlayfs because the kernel doesn't support all overlay2 features.
# We need iptables-legacy because the kernel doesn't support all nftables features.
# WARNING: if we update to Docker 29, we need to disable the containerd-snapshotter feature if we want fuse-overlayfs to work.
# ' "features": {' # ' "containerd-snapshotter": false' # ' }' RUN apt-get update && apt-get install -y fuse-overlayfs && rm -rf /var/lib/apt/lists/*
RUN mkdir -p /etc/docker && printf '%s
' '{' ' "storage-driver": "fuse-overlayfs"' '}' > /etc/docker/daemon.json
RUN apt-get update && apt-get install -y iptables && rm -rf /var/lib/apt/lists/*
RUN update-alternatives --set iptables /usr/sbin/iptables-legacy && update-alternatives --set ip6tables /usr/sbin/ip6tables-legacy
If setup requires Tailscale, note that Tailscale does not work in its default networking mode in Cloud Agent VMs. Use userspace networking mode instead.
Start tailscaled in the background:
tailscaled --tun=userspace-networking --outbound-http-proxy-listen=localhost:1054 --socks5-server=localhost:1055 &
Then export these proxy variables in the shell where you want traffic to flow through Tailscale:
export ALL_PROXY=socks5h://localhost:1055/
export HTTP_PROXY=http://localhost:1054/
export HTTPS_PROXY=http://localhost:1054/
After that, run the usual 'tailscale up ...' flow. Userspace networking does not let the VM appear as a tailnet exit node.
Defining a custom Dockerfile for the Cloud Agent environment
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6454486–6454548, SHA-256 8e48a8cfa6c931bd.
Jev judged not model-facing (confidence 0.13; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: Defining a custom Dockerfile for the Cloud Agent environment
Defining a custom Dockerfile for the Cloud Agent environment
For stable and long-lived dependencies that are expensive to install, baking the
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6454568–6454731, SHA-256 ed4015ab4d09aca4.
Jev judged not model-facing (confidence 0.15; role human). This is a classifier judgment, not proof of delivery.
Readable text: For stable and long-lived dependencies that are expensive to install, baking them into a custom Dockerfile can help new cloud agent environments start up faster.
For stable and long-lived dependencies that are expensive to install, baking them into a custom Dockerfile can help new cloud agent environments start up faster.
General guidance
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6454752–6454770, SHA-256 4abe475fe930c40f.
Jev judged not model-facing (confidence 0.12; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: General guidance
General guidance
Prefer NOT using a custom Dockerfile — the Cursor Universal base image (
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6454811–6454888, SHA-256 0ed1b34aa634381a.
Jev judged not model-facing (confidence 0.16; role documentation). This is a classifier judgment, not proof of delivery.
Readable text: Prefer NOT using a custom Dockerfile — the Cursor Universal base image ('
Prefer NOT using a custom Dockerfile — the Cursor Universal base image (`
) (which is what you started from) already has many common dependencies install
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6454894–6455019, SHA-256 698c5134023a5960.
Jev judged not model-facing (confidence 0.11; role documentation). This is a classifier judgment, not proof of delivery.
Readable text: ') (which is what you started from) already has many common dependencies installed and should be sufficient for most cases.
`) (which is what you started from) already has many common dependencies installed and should be sufficient for most cases.
If you do need to bake things into the Dockerfile, build "on top" of the Univers
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6455042–6455154, SHA-256 f0bc5300bf1746fe.
Jev judged not model-facing (confidence 0.55; role documentation). This is a classifier judgment, not proof of delivery.
Readable text: If you do need to bake things into the Dockerfile, build "on top" of the Universal base image by using: 'FROM
If you do need to bake things into the Dockerfile, build "on top" of the Universal base image by using: `FROM
then appending your customizations to the end of the file.
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6455160–6455222, SHA-256 05994b3b9ac2d49d.
Jev judged not model-facing (confidence 0.42; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: ' then appending your customizations to the end of the file.
` then appending your customizations to the end of the file.
Only choose a different base image if you absolutely need to or if the user EXPL
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6455244–6455373, SHA-256 6f5fd49584739c42.
Jev judged not model-facing (confidence 0.63; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: Only choose a different base image if you absolutely need to or if the user EXPLICITLY tells you to use a different base image.
Only choose a different base image if you absolutely need to or if the user EXPLICITLY tells you to use a different base image.
Do not COPY the full project; Cursor manages the workspace and checks out the co
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6455394–6455489, SHA-256 43863c81d49fb42f.
Jev judged not model-facing (confidence 0.63; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: Do not COPY the full project; Cursor manages the workspace and checks out the correct commit.
Do not COPY the full project; Cursor manages the workspace and checks out the correct commit.
Build caching semantics: Do NOT rely on Docker COPY semantics to know when a fil
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6455510–6455942, SHA-256 654d843d39a1935b.
Jev judged not model-facing (confidence 0.38; role documentation). This is a classifier judgment, not proof of delivery.
Readable text: Build caching semantics: Do NOT rely on Docker COPY semantics to know when a file is new or changed. Internally, the Cursor cloud agent environment manages checkpoints based on the Dockerfile hash (and other metadata like Build Secrets), so…
Build caching semantics: Do NOT rely on Docker COPY semantics to know when a file is new or changed. Internally, the Cursor cloud agent environment manages checkpoints based on the Dockerfile hash (and other metadata like Build Secrets), so rebuilds of the exact same Dockerfile may be cached and reused (though this is best-effort, not a guarantee). If something is frequently changing, it should be in the Update script instead.
What should go in the Dockerfile vs the Update script?
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6455966–6456022, SHA-256 380f1eebf9f74d68.
Jev judged not model-facing (confidence 0.23; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: What should go in the Dockerfile vs the Update script?
What should go in the Dockerfile vs the Update script?