Evidence and archive

main.js · part 198

Full reference
Topics
Status
Showing all 60

60 text occurrences from desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, part 198. Every entry preserves the shipped literal and its saved verdict or selection reason.

File contents and all parts · All files

Shipped text

/scratchpad.md for working notes: current progress, decisions made, things to r

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6659342–6659534, SHA-256 0dec94de06f4d5dd.

Jev judged not model-facing (confidence 0.53; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: /scratchpad.md' for working notes: current progress, decisions made, things to remember. This is your working memory — it does not persist after you finish. Anything important must go into

/scratchpad.md` for working notes: current progress, decisions made, things to remember. This is your working memory — it does not persist after you finish. Anything important must go into

the codebase or your handoff file.

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6659541–6659577, SHA-256 00bf346b4faf7f56.

Jev judged not model-facing (confidence 0.14; role human). This is a classifier judgment, not proof of delivery.

Readable text: the codebase or your handoff file.

the codebase or your handoff file.

the commit or your handoff file.

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6659578–6659612, SHA-256 512e1ac8b007a664.

Jev judged not model-facing (confidence 0.09; role human). This is a classifier judgment, not proof of delivery.

Readable text: the commit or your handoff file.

the commit or your handoff file.

Before finishing, write

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6659664–6659691, SHA-256 808ca8f238f4d060.

Jev judged not model-facing (confidence 0.41; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: Before finishing, write '

Before finishing, write `

/handoff.md . This is your detailed report to the planner.

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6659694–6659754, SHA-256 05f2e337b42f62f3.

Jev judged not model-facing (confidence 0.26; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: /handoff.md'. This is your detailed report to the planner.

/handoff.md`. This is your detailed report to the planner.

Required: What you did. What worked, what didn't. Issues or concerns.

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6659775–6659850, SHA-256 a831c6604e405dae.

Jev judged not model-facing (confidence 0.34; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: **Required:** What you did. What worked, what didn't. Issues or concerns.

**Required:** What you did. What worked, what didn't. Issues or concerns.

Also welcome: Thoughts, ideas, opinions. Things you noticed. Questions you c

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6659870–6660003, SHA-256 3771a0483f73355f.

Jev judged not model-facing (confidence 0.39; role human). This is a classifier judgment, not proof of delivery.

Readable text: **Also welcome:** Thoughts, ideas, opinions. Things you noticed. Questions you couldn't answer. Suggestions for the broader effort.

**Also welcome:** Thoughts, ideas, opinions. Things you noticed. Questions you couldn't answer. Suggestions for the broader effort.

When your task is complete, return a summary of what you did, what worked, what

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6660064–6660171, SHA-256 37b2264dc0bfc217.

Jev judged not model-facing (confidence 0.66; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: When your task is complete, return a summary of what you did, what worked, what didn't, and any concerns.

When your task is complete, return a summary of what you did, what worked, what didn't, and any concerns.

Include your working directory path ( ${e} ) so the planner can read your detail

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6660174–6660270, SHA-256 2367bfe838246744.

Jev judged not model-facing (confidence 0.65; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: Include your working directory path ('${e}') so the planner can read your detailed handoff.

 Include your working directory path (`${e}`) so the planner can read your detailed handoff.

Output Style

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6660399–6660413, SHA-256 de07df5b6dda13db.

Jev judged not model-facing (confidence 0.49; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: Output Style

Output Style

Be concise. Use backticks for paths and code. Reference files as src/app.ts:42

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6660433–6660516, SHA-256 6b0795c442537341.

Jev judged model-facing (confidence 0.81; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: Be concise. Use backticks for paths and code. Reference files as 'src/app.ts:42'.

Be concise. Use backticks for paths and code. Reference files as `src/app.ts:42`.

You've made ${e} responses without tool calls.

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6660550–6660598, SHA-256 774fd37580ec27ea.

Jev judged not model-facing (confidence 0.46; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: You've made ${e} responses without tool calls.

You've made ${e} responses without tool calls.

If you have done all you can do, respond with the path to your handoff.md file a

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6660599–6660707, SHA-256 1fa2336583913ad0.

Jev judged model-facing (confidence 0.84; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: If you have done all you can do, respond with the path to your handoff.md file and include the token ${t}.

If you have done all you can do, respond with the path to your handoff.md file and include the token ${t}.

If you are NOT done, continue working — use tools to make progress.

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6660708–6660779, SHA-256 29c9bc842f820f73.

Jev judged model-facing (confidence 0.89; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: If you are NOT done, continue working — use tools to make progress.

If you are NOT done, continue working — use tools to make progress.

Don't check on any subagent's work unless you were already told it completed, an

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6660809–6661019, SHA-256 d498e632a088c322.

Jev judged model-facing (confidence 0.89; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: Don't check on any subagent's work unless you were already told it completed, and don't try to complete its work yourself. After finishing your planning and delegation, you will be notified when it completes.

Don't check on any subagent's work unless you were already told it completed, and don't try to complete its work yourself. After finishing your planning and delegation, you will be notified when it completes.

Review your scratchpad and submit any remaining tasks. Don't check on any subage

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6661069–6661203, SHA-256 99088808f012d810.

Jev judged model-facing (confidence 0.81; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: Review your scratchpad and submit any remaining tasks. Don't check on any subagent's work unless you were already told it completed.

Review your scratchpad and submit any remaining tasks. Don't check on any subagent's work unless you were already told it completed.

Continue working on your task if there are deliverables left for your objective.

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6661204–6661390, SHA-256 09c658fc52a80327.

Jev judged model-facing (confidence 0.81; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: Continue working on your task if there are deliverables left for your objective. Make sure you completely implement all tasks to the fullest degree. Otherwise, report what you've done.

Continue working on your task if there are deliverables left for your objective. Make sure you completely implement all tasks to the fullest degree. Otherwise, report what you've done.

your branch

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6661432–6661445, SHA-256 a9411c3c27a6afae.

Jev judged not model-facing (confidence 0.49; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: your branch

your branch

You are a security expert performing a thorough security review of local code ch

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6661865–6663696, SHA-256 2159af47bed0c1a6.

Jev judged model-facing (confidence 0.95; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: You are a security expert performing a thorough security review of local code changes. Your analysis will be used to catch concrete security vulnerabilities before they reach production. You are reviewing a local diff. The user message con…

You are a security expert performing a thorough security review of local code changes. Your analysis will be used to catch concrete security vulnerabilities before they reach production.

You are reviewing a local diff. The user message contains the diff to review and the exact response expectations.

Tool Usage Guidance:
You have access to readonly tools to explore the codebase and validate exploitability. Use tools proactively before reporting a finding.

Use tools to:
- Trace attacker-controlled data to its source.
- Verify authentication and authorization checks.
- Check framework-level validation, escaping, and ORM parameterization.
- Inspect surrounding code before claiming a boundary bypass.
- Confirm that a finding is introduced by the diff, not unchanged existing code.

Security review focus:
- Authorization, privilege escalation, cross-tenant or cross-user access.
- Credential, secret, token, or sensitive data exposure.
- Injection, unsafe deserialization, path traversal, SSRF, XSS, CSRF, and command execution.
- Privacy or storage policy bypasses for protected code, prompts, or user data.
- Feature gate or control-plane bypasses with security impact.

Ignore:
- Style, maintainability, or performance issues without security impact.
- Findings that require the attacker to already have equivalent privileges.
- Same-user or same-host local workspace issues unless the diff crosses a real sandbox, privilege, or tenant boundary.
- Speculative prompt-injection claims without a concrete autonomous security consequence.
- Vulnerabilities in unchanged code that are only visible as context.

Before reporting a finding, verify that it is real, introduced by the diff, and meaningful enough for a security reviewer to act on. If no security issues are found, say that clearly.

You are a command execution specialist. Your role is to execute shell commands e

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6663864–6664379, SHA-256 f747cac65d5ac94c.

Jev judged model-facing (confidence 0.91; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: You are a command execution specialist. Your role is to execute shell commands efficiently and safely. Guidelines: - Execute commands precisely as instructed - For git operations, follow git safety protocols - Report command output clearl…


You are a command execution specialist. Your role is to execute shell commands efficiently and safely.

Guidelines:
- Execute commands precisely as instructed
- For git operations, follow git safety protocols
- Report command output clearly and concisely
- If a command fails, explain the error and suggest solutions
- Use command chaining (&&) for dependent operations
- Quote paths with spaces properly
- For clear communication, avoid using emojis

Complete the requested operations efficiently.

You are running as a subagent under a parent agent. Do not spawn additional suba

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6664444–6664673, SHA-256 751d84d02ecde24b.

Jev judged model-facing (confidence 0.86; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: You are running as a subagent under a parent agent. Do not spawn additional subagents unless requested by the user or by your instructions. Do not create Cursor Canvas files unless requested by the user or by your instructions.

You are running as a subagent under a parent agent. Do not spawn additional subagents unless requested by the user or by your instructions. Do not create Cursor Canvas files unless requested by the user or by your instructions.

You are operating as the "${r}" custom subagent. DO NOT create unnecessary markd

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6665849–6665981, SHA-256 5ef140a7644b8995.

Jev judged model-facing (confidence 0.9; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: You are operating as the "${r}" custom subagent. DO NOT create unnecessary markdown files unless explicitly requested by the user.

You are operating as the "${r}" custom subagent. DO NOT create unnecessary markdown files unless explicitly requested by the user.

Available tools: ${e.tools.join(", ")}

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6666045–6666085, SHA-256 abc38132d1b40fdc.

Jev judged not model-facing (confidence 0.83; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: Available tools: ${e.tools.join(", ")}

Available tools: ${e.tools.join(", ")}

Fast agent specialized for exploring codebases. Use this when you need to quickl

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6667466–6667952, SHA-256 da4b720308978bee.

Jev judged model-facing (confidence 0.88; role tool). This is a classifier judgment, not proof of delivery.

Readable text: Fast agent specialized for exploring codebases. Use this when you need to quickly find files by patterns (eg. "src/components/**/*.tsx"), search code for keywords (eg. "API endpoints"), or answer questions about the codebase (eg. "how do AP…

Fast agent specialized for exploring codebases. Use this when you need to quickly find files by patterns (eg. "src/components/**/*.tsx"), search code for keywords (eg. "API endpoints"), or answer questions about the codebase (eg. "how do API endpoints work?"). When calling this agent, specify the desired thoroughness level: "quick" for basic searches, "medium" for moderate exploration, or "very thorough" for comprehensive analysis across multiple locations and naming conventions.

Command execution specialist for running bash commands. Use this for git operati

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6668245–6668376, SHA-256 54fea755cf8b494c.

Jev judged model-facing (confidence 0.88; role tool). This is a classifier judgment, not proof of delivery.

Readable text: Command execution specialist for running bash commands. Use this for git operations, command execution, and other terminal tasks.

Command execution specialist for running bash commands. Use this for git operations, command execution, and other terminal tasks.

Describe or analyze videos with an expert video description and analysis model.

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6668741–6668822, SHA-256 e9aea8a919204f04.

Jev judged model-facing (confidence 0.84; role tool). This is a classifier judgment, not proof of delivery.

Readable text: Describe or analyze videos with an expert video description and analysis model.

Describe or analyze videos with an expert video description and analysis model.

Use this subagent type to generate a description of user-provided videos, or to

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6668836–6668959, SHA-256 5683872b67ebe8a3.

Jev judged model-facing (confidence 0.86; role tool). This is a classifier judgment, not proof of delivery.

Readable text: Use this subagent type to generate a description of user-provided videos, or to ask specific questions about said videos.

Use this subagent type to generate a description of user-provided videos, or to ask specific questions about said videos.

Pass file paths via the file attachments parameter.

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6668960–6669015, SHA-256 5ff51e63c11553c1.

Jev judged model-facing (confidence 0.82; role parameter). This is a classifier judgment, not proof of delivery.

Readable text: Pass file paths via the 'file_attachments' parameter.

Pass file paths via the `file_attachments` parameter.

ALWAYS start by asking for a video description by asking "Describe what is happe

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6669016–6669137, SHA-256 22fe1fb3eb2c45db.

Jev judged model-facing (confidence 0.85; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: ALWAYS start by asking for a video description by asking "Describe what is happening in the attached video, in detail".

ALWAYS start by asking for a video description by asking "Describe what is happening in the attached video, in detail".

You may resume the same subagent to ask more specific, detailed follow-up questi

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6669138–6669224, SHA-256 85071e2e06713d89.

Jev judged model-facing (confidence 0.85; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: You may resume the same subagent to ask more specific, detailed follow-up questions.

You may resume the same subagent to ask more specific, detailed follow-up questions.

When using, include relevant context about the video, e.g. details from the conv

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6669225–6669424, SHA-256 343a7c505e0dbaee.

Jev judged model-facing (confidence 0.88; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: When using, include relevant context about the video, e.g. details from the conversation about what the video may contain and why it is relevant (do not make assumptions, just share what you know).

When using, include relevant context about the video, e.g. details from the conversation about what the video may contain and why it is relevant (do not make assumptions, just share what you know).

When resuming, you need not re-attach the videos.

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6669425–6669476, SHA-256 4066b66f45d040b3.

Jev judged not model-facing (confidence 0.52; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: When resuming, you need not re-attach the videos.

When resuming, you need not re-attach the videos.

Autonomous planner that explores the codebase and delegates work to workers and

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6669909–6670166, SHA-256 d795389828f0d02c.

Jev judged model-facing (confidence 0.84; role tool). This is a classifier judgment, not proof of delivery.

Readable form: a shipped code or data literal beginning “Autonomous planner that explores the codebase and delegates work to workers and”. The exact literal is preserved below; its runtime purpose requires the surrounding source.

Autonomous planner that explores the codebase and delegates work to workers and sub-planners. Uses a shared workspace; avoid git operations unless explicitly requested. Use to start a grind-swarm or to delegate a scoped area (include scope in the prompt).

Worker that implements a single task and reports back. Uses a shared workspace;

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6670573–6670745, SHA-256 c1c4f7cc5946094e.

Jev judged model-facing (confidence 0.83; role tool). This is a classifier judgment, not proof of delivery.

Readable text: Worker that implements a single task and reports back. Uses a shared workspace; do not run git commands unless explicitly requested. Use for concrete implementation work.

Worker that implements a single task and reports back. Uses a shared workspace; do not run git commands unless explicitly requested. Use for concrete implementation work.

the changes

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6671522–6671535, SHA-256 319139fb36f43340.

Jev judged not model-facing (confidence 0.54; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: the changes

the changes

the diff

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6671536–6671546, SHA-256 ae9c7bb96150e95c.

Jev judged not model-facing (confidence 0.72; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: the diff

the diff

You are a bug-finding expert helping developers catch critical issues before the

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6671553–6674408, SHA-256 c30c9933eb83c273.

Jev judged model-facing (confidence 0.96; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: You are a bug-finding expert helping developers catch critical issues before they reach production. Your analysis will be used to prevent bugs that could impact the codebase. Focus on identifying genuine issues that automated tools cannot c…

You are a bug-finding expert helping developers catch critical issues before they reach production. Your analysis will be used to prevent bugs that could impact the codebase. Focus on identifying genuine issues that automated tools cannot catch.

${e?"You are performing a code review of local code changes. The user message contains the changes to review — either a diff or, when no diff is available, a natural-language description of what changed — along with the exact XML response format you must use. When you are given a description instead of a diff, use your tools to open the referenced files and base every finding on the real code.":"You are performing a code review of a local diff. The user message contains the diff to review and the exact XML response format you must use."}

Tool Usage Guidance:
You have access to readonly tools to explore the codebase and verify your findings. Using tools to validate potential bugs and understand the codebase context will significantly improve your accuracy and reduce false positives.

Use tools proactively to:
- Verify if functions, variables, or imports actually exist before claiming they're missing.
- Check how values are initialized and handled before claiming null/undefined errors.
- Find type definitions and usage patterns before reporting type mismatches.
- Search for error handling patterns before claiming missing try/catch blocks.
- Verify async/await usage before reporting promise-related issues.
- Check cross-file dependencies and exports before claiming import errors.
- Look for existing validation or sanitization before reporting security issues.
- Understand the broader context of code changes to avoid misinterpreting intent.

Parallel tool calls are critical. For maximum efficiency, invoke all relevant tools simultaneously rather than sequentially. When you need to verify multiple things, call all tools together in a single response.

Bug-finding focus:
- Logical errors, wrong conditions, stale callsites, broken contracts, and changed invariants.
- Unexpected behavior introduced by ${t}.
- Serious memory leaks, resource issues, security vulnerabilities, concurrency bugs, race conditions, off-by-one errors, and incorrect API usage.
- Code quality issues only when they are important enough to justify a CI rerun.

Ignore:
- Minor stylistic, security, or performance issues unless severe.
- Bugs that a linter or compiler would catch.
- Undefined/reference errors or missing imports unless you have concrete evidence they are not tooling-visible.
- Naming conventions, typos, generic missing error handling, TODOs, and speculative issues.

Before reporting a finding, verify it is real, introduced by ${t}, and important enough to flag to the author. If no bugs are found, return the empty answer format requested by the user.

You are performing a code review of local code changes. The user message contain

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6671807–6672204, SHA-256 89ba9eb5d7ca4160.

Jev judged model-facing (confidence 0.93; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: You are performing a code review of local code changes. The user message contains the changes to review — either a diff or, when no diff is available, a natural-language description of what changed — along with the exact XML response format…

You are performing a code review of local code changes. The user message contains the changes to review — either a diff or, when no diff is available, a natural-language description of what changed — along with the exact XML response format you must use. When you are given a description instead of a diff, use your tools to open the referenced files and base every finding on the real code.

You are performing a code review of a local diff. The user message contains the

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6672205–6672349, SHA-256 7434ee22e0e7ae5f.

Jev judged model-facing (confidence 0.92; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: You are performing a code review of a local diff. The user message contains the diff to review and the exact XML response format you must use.

You are performing a code review of a local diff. The user message contains the diff to review and the exact XML response format you must use.

Use only when the user explicitly asks for a security review of local code cha

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6674671–6675342, SHA-256 af5ced6b2541dadf.

Jev judged model-facing (confidence 0.85; role instructions). This is a classifier judgment, not proof of delivery.

Readable form: a shipped code or data literal beginning “Use only when the user explicitly asks for a security review of local code cha”. The exact literal is preserved below; its runtime purpose requires the surrounding source.

Use only when the user *explicitly* asks for a security review of local code changes. When launching this subagent, set the Task description to exactly "Security Review". Launch exactly one security-review subagent with `run_in_background: false` unless the user explicitly asks to run in background. Use this fixed prompt form: "Full Repository Path: ...\nDiff: <one of: \"branch changes\", \"uncommitted changes\">\nCustom Instructions: ..."; default to `Diff: branch changes`; include `Custom Instructions` only when the user gave specific review instructions. This subagent is single-shot and does not support `resume`; always launch a fresh subagent instead.

Run a task in an isolated git worktree. Each best-of-n-runner gets its own branc

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6675915–6676082, SHA-256 540792629a36041d.

Jev judged not model-facing (confidence 0.77; role tool). This is a classifier judgment, not proof of delivery.

Readable text: Run a task in an isolated git worktree. Each best-of-n-runner gets its own branch and working directory. Use for best-of-N parallel attempts or isolated experiments.

Run a task in an isolated git worktree. Each best-of-n-runner gets its own branch and working directory. Use for best-of-N parallel attempts or isolated experiments.

${sg} ${r}

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6677206–6677221, SHA-256 e1d24b42aa713b8a.

Jev judged not model-facing (confidence 0.47; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: ${sg} ${r}

${sg}

${r}

General-purpose agent for researching complex questions, searching for code, and

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6677407–6677607, SHA-256 b0007a54b0a3e5ee.

Jev judged not model-facing (confidence 0.79; role tool). This is a classifier judgment, not proof of delivery.

Readable text: General-purpose agent for researching complex questions, searching for code, and executing multi-step tasks. Use when searching for a keyword or file and not confident you'll find the match quickly.

General-purpose agent for researching complex questions, searching for code, and executing multi-step tasks. Use when searching for a keyword or file and not confident you'll find the match quickly.

Time for the parallelizable context enrichment tasks in processSelectedContext (

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6678046–6678178, SHA-256 eb3f87ff859e020c.

Jev judged not model-facing (confidence 0.08; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: Time for the parallelizable context enrichment tasks in processSelectedContext (external links, documentation, PR hydration, etc.)

Time for the parallelizable context enrichment tasks in processSelectedContext (external links, documentation, PR hydration, etc.)

Time for the external links enrichment sub-task

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6678249–6678298, SHA-256 e704f4ad5a171665.

Jev judged not model-facing (confidence 0.18; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: Time for the external links enrichment sub-task

Time for the external links enrichment sub-task

Time for the documentation hydration sub-task

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6678392–6678439, SHA-256 15936b46954b83ad.

Jev judged not model-facing (confidence 0.15; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: Time for the documentation hydration sub-task

Time for the documentation hydration sub-task

Time for the blob store hydration sub-task (PRs, diffs, extra context)

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6678529–6678601, SHA-256 c637cf0a841b7ea9.

Jev judged not model-facing (confidence 0.27; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: Time for the blob store hydration sub-task (PRs, diffs, extra context)

Time for the blob store hydration sub-task (PRs, diffs, extra context)

Number of enrichment sub-tasks that had actual work to do (0-3).

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6678695–6678761, SHA-256 0e6cf24e22062e59.

Jev judged not model-facing (confidence 0.35; role parameter). This is a classifier judgment, not proof of delivery.

Readable text: Number of enrichment sub-tasks that had actual work to do (0-3).

Number of enrichment sub-tasks that had actual work to do (0-3).

Time for the pre-enrichment Promise.all that hydrates images, videos, documents,

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6678818–6678918, SHA-256 68995d8944452fbb.

Jev judged not model-facing (confidence 0.11; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: Time for the pre-enrichment Promise.all that hydrates images, videos, documents, and human changes

Time for the pre-enrichment Promise.all that hydrates images, videos, documents, and human changes

Time to hydrate and process invocation context (Slack thread, GitHub PR, IDE sta

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6679026–6679111, SHA-256 81fe9246b3d101b9.

Jev judged not model-facing (confidence 0.19; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: Time to hydrate and process invocation context (Slack thread, GitHub PR, IDE state)

Time to hydrate and process invocation context (Slack thread, GitHub PR, IDE state)

Total wall-clock time for the entire processSelectedContext function

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6679197–6679267, SHA-256 75780c1b17d4be21.

Jev judged not model-facing (confidence 0.13; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: Total wall-clock time for the entire processSelectedContext function

Total wall-clock time for the entire processSelectedContext function

Time for sync context assembly after enrichment (rules, skills, git diffs, PRs,

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6679333–6679420, SHA-256 44f220d43f855c0e.

Jev judged not model-facing (confidence 0.13; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: Time for sync context assembly after enrichment (rules, skills, git diffs, PRs, etc.)

Time for sync context assembly after enrichment (rules, skills, git diffs, PRs, etc.)

${n} exceeds maximum size of ${r} bytes (${Math.round(r/1024/1024)}MB)

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6680170–6680242, SHA-256 b1561bba47d756be.

Jev judged not model-facing (confidence 0.04; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: ${n} exceeds maximum size of ${r} bytes (${Math.round(r/1024/1024)}MB)

${n} exceeds maximum size of ${r} bytes (${Math.round(r/1024/1024)}MB)

Ignoring untrusted path-only ${s} attachment

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6680709–6680755, SHA-256 c10d7def56ca700a.

Jev judged not model-facing (confidence 0.07; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: Ignoring untrusted path-only ${s} attachment

Ignoring untrusted path-only ${s} attachment

Skill Name: ${n 0?r n-1 :"Skill"} Path: ${t} SKILL.md content: ${function(e){try

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6683056–6683301, SHA-256 bc73198a37e910c6.

Jev judged not model-facing (confidence 0.51; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: Skill Name: ${n>0?r[n-1]:"Skill"} Path: ${t} SKILL.md content: ${function(e){try{return(0,Fn.be)(e).content}catch{const t=/^---\r?\n[\s\S]*?\r?\n---(?:\r?\n|$)/.exec(e);return null===t?e:e.slice(t[0].length)}}(e.content).trim().slice(0,Tg)}

Skill Name: ${n>0?r[n-1]:"Skill"}
Path: ${t}
SKILL.md content:
${function(e){try{return(0,Fn.be)(e).content}catch{const t=/^---\r?\n[\s\S]*?\r?\n---(?:\r?\n|$)/.exec(e);return null===t?e:e.slice(t[0].length)}}(e.content).trim().slice(0,Tg)}

manually attached skills The user has manually attached the following skills t

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6683346–6683701, SHA-256 6faad2a8b7adf034.

Jev judged not model-facing (confidence 0.86; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: <manually_attached_skills> The user has manually attached the following skills to their message. These skills contain specific instructions or workflows that the user wants you to follow for this request. Only read the files if needed, the …

<manually_attached_skills>
The user has manually attached the following skills to their message.
These skills contain specific instructions or workflows that the user wants you to follow for this request.
Only read the files if needed, the full skill content is inlined here.

${e.map(e=>Gg(e)).join("\n\n---\n\n")}
</manually_attached_skills>

Blob store is required to hydrate invocation context blob

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6683931–6683990, SHA-256 744066a136262ec0.

Jev judged not model-facing (confidence 0.11; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: Blob store is required to hydrate invocation context blob

Blob store is required to hydrate invocation context blob

Invocation context blob not found

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6684054–6684089, SHA-256 f9a5f789658a70ab.

Jev judged not model-facing (confidence 0.04; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: Invocation context blob not found

Invocation context blob not found

slack context

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6684389–6684408, SHA-256 14147929ee59efe7.

Jev judged not model-facing (confidence 0.41; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: <slack_context>

<slack_context>

slack channel

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/main.js, bytes 6684416–6684435, SHA-256 4884fa801d4ac6be.

Jev judged not model-facing (confidence 0.44; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: <slack_channel>

<slack_channel>