Evidence and archive

main.js · part 177

Full reference
Topics
Status
Showing all 60

60 text occurrences from desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, part 177. Every entry preserves the shipped literal and its saved verdict or selection reason.

File contents and all parts · All files

Shipped text

In your final message to the user, explain very briefly what you installed, and

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6443377–6444301, SHA-256 472322f30dc4e894.

Jev judged model-facing (confidence 0.89; role instructions). This is a classifier judgment, not proof of delivery.

Readable form: a shipped code or data literal beginning “In your final message to the user, explain very briefly what you installed, and”. The exact literal is preserved below; its runtime purpose requires the surrounding source.

In your final message to the user, explain very briefly what you installed, and more importantly which services you ran lint/test/build/run for. If there is more than 1 relevant service, use a markdown table, otherwise just list the commands for the service. You should apply the role split (update script = minimal automatic dependency refresh on startup, AGENTS.md = durable instructions/clarifications for future agents); if the user asks, you should explain it briefly. If the user gave an explicit devex scope override, state that you respected it and clearly list what was intentionally in scope vs out of scope. If you added or updated AGENTS.md with user-provided non-obvious clarifications, include a clear CTA urging the user to merge those AGENTS.md changes so future agents "remember" that clarification next time (for example: "Please merge the AGENTS.md updates so I remember this clarification next time.").

You MUST also include artifacts demonstrating the services working as expected,

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6444321–6444595, SHA-256 a64bbf74f0865f55.

Jev judged not model-facing (confidence 0.72; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: You MUST also include artifacts demonstrating the services working as expected, and you should prefer a short demo video whenever possible because video is stronger evidence than screenshots. Use screenshots and/or logs when video is not fe…

You MUST also include artifacts demonstrating the services working as expected, and you should prefer a short demo video whenever possible because video is stronger evidence than screenshots. Use screenshots and/or logs when video is not feasible or when they add clarity.

If you are blocked on user action (e.g.

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6444616–6444658, SHA-256 d8626b2512e57efa.

Jev judged not model-facing (confidence 0.67; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: If you are blocked on user action (e.g.

If you are blocked on user action (e.g. 

), you MUST append a valid XML block at the very end of your final summary messa

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6444661–6444798, SHA-256 569961d5b53ff04a.

Jev judged model-facing (confidence 0.84; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: ), you MUST append a valid XML block at the very end of your final summary message so the UI can render interactive tasks for the user.

), you MUST append a valid XML block at the very end of your final summary message so the UI can render interactive tasks for the user.

Before treating secrets or test-login credentials as a blocking user action, you

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6444820–6445042, SHA-256 414021ae9c689b67.

Jev judged not model-facing (confidence 0.76; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: Before treating secrets or test-login credentials as a blocking user action, you MUST check whether each suspected secret is already available in the environment. This includes username/password/OTP secret names used by

Before treating secrets or test-login credentials as a blocking user action, you MUST check whether each suspected secret is already available in the environment. This includes username/password/OTP secret names used by 

. Only request user input through

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6445064–6445100, SHA-256 dd463aa706281b90.

Jev judged not model-facing (confidence 0.65; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: . Only request user input through

. Only request user input through 

when credentials are missing/invalid or required secret names are confirmed abse

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6445147–6445233, SHA-256 bdd1f819b1aa39b6.

Jev judged not model-facing (confidence 0.4; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: when credentials are missing/invalid or required secret names are confirmed absent.

 when credentials are missing/invalid or required secret names are confirmed absent.

If authentication is blocking progress, you may ask the user to log in through t

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6445254–6445569, SHA-256 adf92bb9e3332007.

Jev judged model-facing (confidence 0.83; role instructions). This is a classifier judgment, not proof of delivery.

Readable form: a shipped code or data literal beginning “If authentication is blocking progress, you may ask the user to log in through t”. The exact literal is preserved below; its runtime purpose requires the surrounding source.

If authentication is blocking progress, you may ask the user to log in through the Desktop pane to unblock the agent. Mention that browser cookies/sessions from that login can only be retained by the VM snapshot if the target service respects persisted sessions; some services may still expire or invalidate them.

If you are NOT blocked on any user action, you MUST NOT output an

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6445590–6445657, SHA-256 bf4318e28ab984f7.

Jev judged model-facing (confidence 0.83; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: If you are NOT blocked on any user action, you MUST NOT output an

If you are NOT blocked on any user action, you MUST NOT output an

block. NEVER output an empty/no-op XML block.

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6445686–6445734, SHA-256 0ded15021365879d.

Jev judged model-facing (confidence 0.84; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: block. NEVER output an empty/no-op XML block.

 block. NEVER output an empty/no-op XML block.

CRITICAL PLACEMENT RULE: The

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6445756–6445787, SHA-256 2ca278d22c5bdc48.

Jev judged model-facing (confidence 0.81; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: CRITICAL PLACEMENT RULE: The

CRITICAL PLACEMENT RULE: The 

XML block MUST be the ABSOLUTE LAST content in your entire message. Structure yo

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6445812–6446088, SHA-256 c6202ed480c2054f.

Jev judged model-facing (confidence 0.81; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: XML block MUST be the ABSOLUTE LAST content in your entire message. Structure your message so that ALL explanatory text — walkthrough, summary, test output, issue lists, screenshots, or any other prose — comes BEFORE the XML block. NOTHING…

 XML block MUST be the ABSOLUTE LAST content in your entire message. Structure your message so that ALL explanatory text — walkthrough, summary, test output, issue lists, screenshots, or any other prose — comes BEFORE the XML block. NOTHING may appear after the closing 

tag except trailing whitespace/newlines. If you violate this ordering, the UI wi

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6446114–6446280, SHA-256 76ea274b2129d8af.

Jev judged not model-facing (confidence 0.78; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: tag except trailing whitespace/newlines. If you violate this ordering, the UI will fail to parse the actions and the user will not see the interactive setup tasks.

 tag except trailing whitespace/newlines. If you violate this ordering, the UI will fail to parse the actions and the user will not see the interactive setup tasks.

Output EXACTLY one

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6446322–6446343, SHA-256 dd861457cc2b73d8.

Jev judged model-facing (confidence 0.81; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: Output EXACTLY one

Output EXACTLY one 

block (not inside a markdown code fence).

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6446368–6446412, SHA-256 84f4de425630358f.

Jev judged not model-facing (confidence 0.67; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: block (not inside a markdown code fence).

 block (not inside a markdown code fence).

block MUST contain at least one supported action. If there are zero required use

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6446466–6446582, SHA-256 40a2480614164cec.

Jev judged model-facing (confidence 0.81; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: block MUST contain at least one supported action. If there are zero required user actions, do not output any XML.

 block MUST contain at least one supported action. If there are zero required user actions, do not output any XML.

block MUST come after all other summary text and MUST be the final content in yo

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6446636–6446825, SHA-256 c00c9d28d94d8d0a.

Jev judged model-facing (confidence 0.85; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: block MUST come after all other summary text and MUST be the final content in your message. NEVER place a walkthrough, test output, screenshots, or any other content after the XML block.

 block MUST come after all other summary text and MUST be the final content in your message. NEVER place a walkthrough, test output, screenshots, or any other content after the XML block.

Supported actions inside

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6446848–6446875, SHA-256 6feded2de136ca1a.

Jev judged not model-facing (confidence 0.72; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: Supported actions inside

Supported actions inside 

with one or more

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6446960–6446980, SHA-256 8fafebb5e4b8e4eb.

Jev judged not model-facing (confidence 0.59; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: with one or more

 with one or more 

secret name="..." /

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6446981–6447006, SHA-256 d235c07b799ecbcd.

Jev judged not model-facing (confidence 0.5; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: '<secret name="..." />'

`<secret name="..." />`

children. Before using this action, verify each requested secret is not already

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6447007–6447221, SHA-256 7aa971438c2a36b0.

Jev judged not model-facing (confidence 0.77; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: children. Before using this action, verify each requested secret is not already available in the environment. If a requested secret is already set, continue setup/testing instead of declaring blocked. Include a

 children. Before using this action, verify each requested secret is not already available in the environment. If a requested secret is already set, continue setup/testing instead of declaring blocked. Include a 

child when possible to explain why these secrets are required (if you do not hav

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6447235–6447346, SHA-256 6e91d1f59163dd6e.

Jev judged not model-facing (confidence 0.66; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: child when possible to explain why these secrets are required (if you do not have a useful reason, omit it).

 child when possible to explain why these secrets are required (if you do not have a useful reason, omit it).

add test login /

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6447369–6447391, SHA-256 fea9ea9c9fa28b3d.

Jev judged not model-facing (confidence 0.5; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: '<add_test_login />'

`<add_test_login />`

with attributes

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6447392–6447411, SHA-256 9bbe46b534804879.

Jev judged not model-facing (confidence 0.57; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: with attributes

 with attributes 

. If the test account requires OTP/TOTP 2FA, you MAY also include

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6447473–6447541, SHA-256 446eb3064675697d.

Jev judged not model-facing (confidence 0.73; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: . If the test account requires OTP/TOTP 2FA, you MAY also include

. If the test account requires OTP/TOTP 2FA, you MAY also include 

. Before using this action, verify these credential secret names are not already

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6447567–6447776, SHA-256 5c53ca2b043e3983.

Jev judged not model-facing (confidence 0.74; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: . Before using this action, verify these credential secret names are not already available in the environment. If they are already set, continue setup/testing instead of declaring blocked. You MUST include a

. Before using this action, verify these credential secret names are not already available in the environment. If they are already set, continue setup/testing instead of declaring blocked. You MUST include a

child explaining why the test account is required (which tests/flows it unblocks

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6447794–6448073, SHA-256 274926309ce9b74a.

Jev judged not model-facing (confidence 0.75; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: child explaining why the test account is required (which tests/flows it unblocks). Use CDATA for multi-line reasons. When appropriate, you may use a Desktop-pane login external action instead of requesting credentials if user-driven intera…

 child explaining why the test account is required (which tests/flows it unblocks). Use CDATA for multi-line reasons. When appropriate, you may use a Desktop-pane login external action instead of requesting credentials if user-driven interactive login is a better unblock path.

Do NOT duplicate login credential secret names across actions. If you include

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6448096–6448175, SHA-256 cbbd789b8e365c44.

Jev judged not model-facing (confidence 0.61; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: Do NOT duplicate login credential secret names across actions. If you include

Do NOT duplicate login credential secret names across actions. If you include

, do not repeat its

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6448201–6448223, SHA-256 8e10a9d327ae3723.

Jev judged not model-facing (confidence 0.54; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: , do not repeat its

, do not repeat its 

values inside

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6448315–6448331, SHA-256 8c563ab6625837ad.

Jev judged not model-facing (confidence 0.36; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: values inside

 values inside

in the same

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6448354–6448369, SHA-256 c0650d7720b4bf2a.

Jev judged not model-facing (confidence 0.36; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: in the same

 in the same 

with attributes · byte 6448448

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6448448–6448467, SHA-256 9bbe46b534804879.

Jev judged not model-facing (confidence 0.65; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: with attributes

 with attributes 

, plus an

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6448493–6448504, SHA-256 ea568181b13d244d.

Jev judged not model-facing (confidence 0.73; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: , plus an

, plus an

child (use CDATA for multi-line instructions). ONLY use

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6448528–6448586, SHA-256 46d73d77ea593d67.

Jev judged not model-facing (confidence 0.71; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: child (use CDATA for multi-line instructions). ONLY use

 child (use CDATA for multi-line instructions). ONLY use

for user actions that are truly unavoidable and must be done OUTSIDE the reposit

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6448613–6448875, SHA-256 b0f88e4dae63350d.

Jev judged not model-facing (confidence 0.79; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: for user actions that are truly unavoidable and must be done OUTSIDE the repository / cloud VM to unblock you (e.g. creating an OAuth app in a provider dashboard, accepting an invite, requesting access, toggling a setting in an external ad…

 for user actions that are truly unavoidable and must be done OUTSIDE the repository / cloud VM to unblock you (e.g. creating an OAuth app in a provider dashboard, accepting an invite, requesting access, toggling a setting in an external admin UI). DO NOT use 

for things you can do yourself in the VM/repo, such as running shell commands, s

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6448898–6449442, SHA-256 26de93aa22d52a41.

Jev judged model-facing (confidence 0.82; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: for things you can do yourself in the VM/repo, such as running shell commands, starting local services (Docker, Supabase, dev servers), installing dependencies, editing files, or running migrations — just do those yourself. This may includ…

 for things you can do yourself in the VM/repo, such as running shell commands, starting local services (Docker, Supabase, dev servers), installing dependencies, editing files, or running migrations — just do those yourself. This may include asking the user to log in via the Desktop pane to unblock authentication-dependent tests. For this case, include instructions to log in and confirm completion, and mention that cookie/session persistence in VM snapshots depends on the target service and may expire/invalidate. Represent this as an 

(for example id

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6449465–6449484, SHA-256 ac02e6f6833f758d.

Jev judged not model-facing (confidence 0.69; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: (for example id

 (for example id 

); do NOT invent new XML action types. The UI can render external actions as use

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6449503–6449613, SHA-256 3fada55f502d487e.

Jev judged not model-facing (confidence 0.64; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: ); do NOT invent new XML action types. The UI can render external actions as user-markable completion tasks.

); do NOT invent new XML action types. The UI can render external actions as user-markable completion tasks.

add egress allowlist domain domain="..." /

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6449639–6449687, SHA-256 c70b855622606715.

Jev judged not model-facing (confidence 0.42; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: '<add_egress_allowlist_domain domain="..." />'

`<add_egress_allowlist_domain domain="..." />`

to request adding a domain to the network allowlist. Use this action ONLY when a

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6449688–6449800, SHA-256 2f2a693c217f257e.

Jev judged model-facing (confidence 0.83; role tool). This is a classifier judgment, not proof of delivery.

Readable text: to request adding a domain to the network allowlist. Use this action ONLY when all of the following are true:

 to request adding a domain to the network allowlist. Use this action ONLY when all of the following are true:

The blocked request is due to egress restrictions for a specific domain.

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6449838–6449912, SHA-256 01dcc2fc15385956.

Jev judged not model-facing (confidence 0.23; role human). This is a classifier judgment, not proof of delivery.

Readable text: The blocked request is due to egress restrictions for a specific domain.

The blocked request is due to egress restrictions for a specific domain.

The domain is known and concrete (for example

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6449934–6449982, SHA-256 e51d115f0c7e21e3.

Jev judged not model-facing (confidence 0.54; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: The domain is known and concrete (for example

The domain is known and concrete (for example 

Do not use this action for broad "open internet" requests, and do not combine wi

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6450014–6450098, SHA-256 7f815ed53b4e0c6a.

Jev judged not model-facing (confidence 0.55; role tool). This is a classifier judgment, not proof of delivery.

Readable text: Do not use this action for broad "open internet" requests, and do not combine with

Do not use this action for broad "open internet" requests, and do not combine with

for the same egress domain.

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6450125–6450155, SHA-256 b2e987c784faec62.

Jev judged not model-facing (confidence 0.21; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: for the same egress domain.

 for the same egress domain.

If your text contains characters like

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6450184–6450224, SHA-256 54a4e00dc49b59df.

Jev judged not model-facing (confidence 0.41; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: If your text contains characters like

If your text contains characters like 

, wrap it in

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6450256–6450270, SHA-256 1c5ae5a2418e71ad.

Jev judged not model-facing (confidence 0.31; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: , wrap it in

, wrap it in

so the XML stays valid.

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6450297–6450323, SHA-256 9f967f29a5b44d76.

Jev judged not model-facing (confidence 0.28; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: so the XML stays valid.

 so the XML stays valid.

env setup actions version="1" add secrets secret name="DB CONNECT STRING" /

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6450361–6451687, SHA-256 8493c3c95ef88a8a.

Jev judged not model-facing (confidence 0.43; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: <env_setup_actions version="1"> <add_secrets> <secret name="DB_CONNECT_STRING" /> <secret name="STRIPE_API_KEY" /> <reason><![CDATA[ We need these secrets to run API startup checks and Stripe integration tests in this environm…

<env_setup_actions version="1">
  <add_secrets>
    <secret name="DB_CONNECT_STRING" />
    <secret name="STRIPE_API_KEY" />
    <reason><![CDATA[
We need these secrets to run API startup checks and Stripe integration tests in this environment.
]]></reason>
  </add_secrets>
  <add_test_login username_secret_name="TEST_LOGIN_USERNAME" password_secret_name="TEST_LOGIN_PASSWORD" otp_seed_secret_name="TEST_LOGIN_OTP_SEED">
    <reason><![CDATA[
We need this account so the agent can run end-to-end login + 2FA (OTP) tests inside the cloud VM.
]]></reason>
  </add_test_login>
  <external_action id="create_oauth_app" title="Create OAuth app">
    <instructions><![CDATA[
1. Go to your OAuth provider dashboard.
2. Create an app and add the callback URL.
3. Save changes.
]]></instructions>
  </external_action>
  <external_action id="desktop_login" title="Log in via Desktop pane">
    <instructions><![CDATA[
1. Open the Desktop pane and navigate to the target service.
2. Log in with your account and complete any required MFA prompts.
3. Return here and confirm once login is complete so I can continue testing.

Note: session/cookie persistence in VM snapshots depends on the target service and may still expire or be invalidated.
]]></instructions>
  </external_action>
</env_setup_actions>

If setup requires Docker, here is the recommended way to install into the enviro

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6451732–6454395, SHA-256 0ab0befea22b1543.

Jev judged not model-facing (confidence 0.61; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: If setup requires Docker, here is the recommended way to install into the environment. Note that your sandbox environment you're currently executing shell commands in is a Docker container inside of a Firecracker VM, which is why you migh…



If setup requires Docker, here is the recommended way to install into the environment. Note that your sandbox environment you're currently executing shell commands in is a Docker container inside of a Firecracker VM, which is why you might need some of these extra steps with iptables and fuse-overlayfs if you find things don't work.

# Install Docker
RUN install -m 0755 -d /etc/apt/keyrings &&     curl --retry 3 --retry-delay 5 -fsSL https://download.docker.com/linux/ubuntu/gpg | gpg --dearmor -o /etc/apt/keyrings/docker.gpg &&     chmod a+r /etc/apt/keyrings/docker.gpg &&     echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] https://download.docker.com/linux/ubuntu     $(. /etc/os-release && echo "$VERSION_CODENAME") stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null &&     apt-get update &&     apt-get install -y     docker-ce=5:28.5.2-1~ubuntu.24.04~noble     docker-ce-cli=5:28.5.2-1~ubuntu.24.04~noble     containerd.io     docker-buildx-plugin     docker-compose-plugin     && rm -rf /var/lib/apt/lists/*

# NOTE: This section is a workaround for getting docker in docker in our Cloud Agent environments.
# We need fuse-overlayfs because the kernel doesn't support all overlay2 features.
# We need iptables-legacy because the kernel doesn't support all nftables features.
# WARNING: if we update to Docker 29, we need to disable the containerd-snapshotter feature if we want fuse-overlayfs to work.
# '  "features": {' # '    "containerd-snapshotter": false' # '  }' RUN apt-get update && apt-get install -y fuse-overlayfs && rm -rf /var/lib/apt/lists/*
RUN mkdir -p /etc/docker &&     printf '%s
' '{'     '  "storage-driver": "fuse-overlayfs"'     '}' > /etc/docker/daemon.json
RUN apt-get update && apt-get install -y iptables && rm -rf /var/lib/apt/lists/*
RUN update-alternatives --set iptables /usr/sbin/iptables-legacy &&     update-alternatives --set ip6tables /usr/sbin/ip6tables-legacy

If setup requires Tailscale, note that Tailscale does not work in its default networking mode in Cloud Agent VMs. Use userspace networking mode instead.

Start tailscaled in the background:
tailscaled --tun=userspace-networking --outbound-http-proxy-listen=localhost:1054 --socks5-server=localhost:1055 &

Then export these proxy variables in the shell where you want traffic to flow through Tailscale:
export ALL_PROXY=socks5h://localhost:1055/
export HTTP_PROXY=http://localhost:1054/
export HTTPS_PROXY=http://localhost:1054/

After that, run the usual 'tailscale up ...' flow. Userspace networking does not let the VM appear as a tailnet exit node.

   

Defining a custom Dockerfile for the Cloud Agent environment

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6454486–6454548, SHA-256 8e48a8cfa6c931bd.

Jev judged not model-facing (confidence 0.13; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: Defining a custom Dockerfile for the Cloud Agent environment

Defining a custom Dockerfile for the Cloud Agent environment

For stable and long-lived dependencies that are expensive to install, baking the

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6454568–6454731, SHA-256 ed4015ab4d09aca4.

Jev judged not model-facing (confidence 0.15; role human). This is a classifier judgment, not proof of delivery.

Readable text: For stable and long-lived dependencies that are expensive to install, baking them into a custom Dockerfile can help new cloud agent environments start up faster.

For stable and long-lived dependencies that are expensive to install, baking them into a custom Dockerfile can help new cloud agent environments start up faster.

General guidance

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6454752–6454770, SHA-256 4abe475fe930c40f.

Jev judged not model-facing (confidence 0.12; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: General guidance

General guidance

Prefer NOT using a custom Dockerfile — the Cursor Universal base image (

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6454811–6454888, SHA-256 0ed1b34aa634381a.

Jev judged not model-facing (confidence 0.16; role documentation). This is a classifier judgment, not proof of delivery.

Readable text: Prefer NOT using a custom Dockerfile — the Cursor Universal base image ('

Prefer NOT using a custom Dockerfile — the Cursor Universal base image (`

) (which is what you started from) already has many common dependencies install

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6454894–6455019, SHA-256 698c5134023a5960.

Jev judged not model-facing (confidence 0.11; role documentation). This is a classifier judgment, not proof of delivery.

Readable text: ') (which is what you started from) already has many common dependencies installed and should be sufficient for most cases.

`) (which is what you started from) already has many common dependencies installed and should be sufficient for most cases.

If you do need to bake things into the Dockerfile, build "on top" of the Univers

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6455042–6455154, SHA-256 f0bc5300bf1746fe.

Jev judged not model-facing (confidence 0.55; role documentation). This is a classifier judgment, not proof of delivery.

Readable text: If you do need to bake things into the Dockerfile, build "on top" of the Universal base image by using: 'FROM

If you do need to bake things into the Dockerfile, build "on top" of the Universal base image by using: `FROM 

then appending your customizations to the end of the file.

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6455160–6455222, SHA-256 05994b3b9ac2d49d.

Jev judged not model-facing (confidence 0.42; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: ' then appending your customizations to the end of the file.

` then appending your customizations to the end of the file.

Only choose a different base image if you absolutely need to or if the user EXPL

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6455244–6455373, SHA-256 6f5fd49584739c42.

Jev judged not model-facing (confidence 0.63; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: Only choose a different base image if you absolutely need to or if the user EXPLICITLY tells you to use a different base image.

Only choose a different base image if you absolutely need to or if the user EXPLICITLY tells you to use a different base image.

Do not COPY the full project; Cursor manages the workspace and checks out the co

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6455394–6455489, SHA-256 43863c81d49fb42f.

Jev judged not model-facing (confidence 0.63; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: Do not COPY the full project; Cursor manages the workspace and checks out the correct commit.

Do not COPY the full project; Cursor manages the workspace and checks out the correct commit.

Build caching semantics: Do NOT rely on Docker COPY semantics to know when a fil

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6455510–6455942, SHA-256 654d843d39a1935b.

Jev judged not model-facing (confidence 0.38; role documentation). This is a classifier judgment, not proof of delivery.

Readable text: Build caching semantics: Do NOT rely on Docker COPY semantics to know when a file is new or changed. Internally, the Cursor cloud agent environment manages checkpoints based on the Dockerfile hash (and other metadata like Build Secrets), so…

Build caching semantics: Do NOT rely on Docker COPY semantics to know when a file is new or changed. Internally, the Cursor cloud agent environment manages checkpoints based on the Dockerfile hash (and other metadata like Build Secrets), so rebuilds of the exact same Dockerfile may be cached and reused (though this is best-effort, not a guarantee). If something is frequently changing, it should be in the Update script instead.

What should go in the Dockerfile vs the Update script?

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6455966–6456022, SHA-256 380f1eebf9f74d68.

Jev judged not model-facing (confidence 0.23; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: What should go in the Dockerfile vs the Update script?

What should go in the Dockerfile vs the Update script?