Evidence and archive

daemon.cjs · part 247

Full reference
Topics
Status
Showing all 60

60 text occurrences from desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, part 247. Every entry preserves the shipped literal and its saved verdict or selection reason.

File contents and all parts · All files

Shipped text

You called this MCP tool without first reading its schema/descriptor file. For f

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20494668–20494895, SHA-256 7f3fa1c1325ea13d.

Jev judged not model-facing (confidence 0.64; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: You called this MCP tool without first reading its schema/descriptor file. For future calls to this tool, please read the tool definition at "${unreadToolCheck.unreadPath}" first to ensure you're using the correct parameters.

You called this MCP tool without first reading its schema/descriptor file. For future calls to this tool, please read the tool definition at "${unreadToolCheck.unreadPath}" first to ensure you're using the correct parameters.

The ${useDynamicToolNamespaces ? "namespace" : "MCP server"} rejected these argu

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20495241–20495560, SHA-256 4f60954ec7d64baf.

Jev judged not model-facing (confidence 0.54; role human). This is a classifier judgment, not proof of delivery.

Readable form: a shipped code or data literal beginning “The ${useDynamicToolNamespaces ? "namespace" : "MCP server"} rejected these argu”. The exact literal is preserved below; its runtime purpose requires the surrounding source.

The ${useDynamicToolNamespaces ? "namespace" : "MCP server"} rejected these arguments as invalid. Before retrying, call ${resolvedGetMcpToolsToolName} with {"${useDynamicToolNamespaces ? "namespace" : "server"}":"${args.server}","toolName":"${args.toolName}"} and rebuild the arguments from the returned input schema.

MCP server

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20495289–20495301, SHA-256 b57d34d8baa1e848.

Jev judged not model-facing (confidence 0.27; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: MCP server

MCP server

The MCP server rejected these arguments as invalid. Before retrying, read the to

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20495646–20495812, SHA-256 19b17aad00549afa.

Jev judged not model-facing (confidence 0.34; role human). This is a classifier judgment, not proof of delivery.

Readable text: The MCP server rejected these arguments as invalid. Before retrying, read the tool definition at "${toolDefinitionPath}" and rebuild the arguments from that schema.

The MCP server rejected these arguments as invalid. Before retrying, read the tool definition at "${toolDefinitionPath}" and rebuild the arguments from that schema.

The MCP server rejected these arguments as invalid. Before retrying, read the MC

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20495847–20496057, SHA-256 1bca48329aa5a5b5.

Jev judged not model-facing (confidence 0.31; role human). This is a classifier judgment, not proof of delivery.

Readable text: The MCP server rejected these arguments as invalid. Before retrying, read the MCP server descriptor files for "${args.server}" and the tool definition for "${args.toolName}" so the arguments match the schema.

The MCP server rejected these arguments as invalid. Before retrying, read the MCP server descriptor files for "${args.server}" and the tool definition for "${args.toolName}" so the arguments match the schema.

Missing serverIdentifier or toolCallId

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20496725–20496765, SHA-256 ae566d6a85bc2c2f.

Jev judged not model-facing (confidence 0.14; role human). This is a classifier judgment, not proof of delivery.

Readable text: Missing serverIdentifier or toolCallId

Missing serverIdentifier or toolCallId

User rejected MCP authentication

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20498221–20498255, SHA-256 105a680626584da6.

Jev judged not model-facing (confidence 0.07; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: User rejected MCP authentication

User rejected MCP authentication

MCP allowlist precheck failed

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20505342–20505373, SHA-256 63bdfd258cf95c2b.

Jev judged not model-facing (confidence 0.05; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: MCP allowlist precheck failed

MCP allowlist precheck failed

Failed to cancel Smart Mode MCP approval request after steer release

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20514466–20514536, SHA-256 b0abe3a43dc288a2.

Jev judged not model-facing (confidence 0.06; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: Failed to cancel Smart Mode MCP approval request after steer release

Failed to cancel Smart Mode MCP approval request after steer release

Failed to cancel Smart Mode MCP approval request

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20515687–20515737, SHA-256 3148aecd1724dbec.

Jev judged not model-facing (confidence 0.04; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: Failed to cancel Smart Mode MCP approval request

Failed to cancel Smart Mode MCP approval request

Error in call mcp tool

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20516880–20516904, SHA-256 7cc98e34e7295e06.

Jev judged not model-facing (confidence 0.05; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: Error in call_mcp_tool

Error in call_mcp_tool

"description": "Search the public docs for the example API",

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20520573–20520638, SHA-256 78843424bd12016a.

Jev judged not model-facing (confidence 0.6; role tool). This is a classifier judgment, not proof of delivery.

Readable text: "description": "Search the public docs for the example API",

"description": "Search the public docs for the example API",
  

Set "write to file": true to have the result written to a file under agent-tools

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20520700–20521567, SHA-256 6d31d831826f9b04.

Jev judged model-facing (confidence 0.8; role tool). This is a classifier judgment, not proof of delivery.

Readable text: Set "write_to_file": true to have the result written to a file under agent-tools/ in the workspace instead of returned inline, regardless of its size; you then get back the file path, size, and line count. Prefer it for results you expect…



Set "write_to_file": true to have the result written to a file under agent-tools/ in the workspace instead of returned inline, regardless of its size; you then get back the file path, size, and line count. Prefer it for results you expect to be large and want to read selectively or hand to another tool by path.

For tools in external MCP namespaces (not the cursor namespace), any string argument, at any nesting depth, that is exactly "${SYMBOLIC_PATH_ARGUMENT_PREFIX}/absolute/path" is replaced with that file's contents when the call is sent, so a file (for example one produced by write_to_file) can be passed to the server without reading it into the conversation. Text files only, up to a few MiB; if the tool accepts a path, pass the plain path instead. Example: "arguments": { "body": "${SYMBOLIC_PATH_ARGUMENT_PREFIX}/workspace/agent-tools/1f3c.txt" }.

Invoke one tool from a dynamic namespace, e.g. an MCP server. IMPORTANT: Always

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20523106–20523628, SHA-256 feb281232023e82c.

Jev judged model-facing (confidence 0.87; role tool). This is a classifier judgment, not proof of delivery.

Readable text: Invoke one tool from a dynamic namespace, e.g. an MCP server. IMPORTANT: Always call ${getMcpToolsToolName2} for this namespace/tool before calling to ensure correct parameters. Set mcpDetails only for tools from external MCP namespaces; om…

Invoke one tool from a dynamic namespace, e.g. an MCP server. IMPORTANT: Always call ${getMcpToolsToolName2} for this namespace/tool before calling to ensure correct parameters. Set mcpDetails only for tools from external MCP namespaces; omit it for first-party tools in the cursor namespace.

Example:
{
  "namespace": "my-namespace",
  "toolName": "search",
  "mcpDetails": { "description": "Search the public docs for the example API" },
  "arguments": { "query": "example", "limit": 10 }
}${symbolicToolCallGuidance}

Call an MCP tool by server identifier and tool name with arbitrary JSON argument

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20523663–20524030, SHA-256 c71efc743cad56e8.

Jev judged model-facing (confidence 0.8; role tool). This is a classifier judgment, not proof of delivery.

Readable text: Call an MCP tool by server identifier and tool name with arbitrary JSON arguments. IMPORTANT: Always call ${getMcpToolsToolName2} for this server/tool before calling to ensure correct parameters. Example: { "server": "my-mcp-server", "…

Call an MCP tool by server identifier and tool name with arbitrary JSON arguments. IMPORTANT: Always call ${getMcpToolsToolName2} for this server/tool before calling to ensure correct parameters.

Example:
{
  "server": "my-mcp-server",
  "toolName": "search",
  ${exampleDescriptionLine}"arguments": { "query": "example", "limit": 10 }
}${symbolicToolCallGuidance}

Call an MCP tool by server identifier and tool name with arbitrary JSON argument · byte 20524061

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20524061–20524385, SHA-256 448ebe745a05fa92.

Jev judged not model-facing (confidence 0.81; role documentation). This is a classifier judgment, not proof of delivery.

Readable text: Call an MCP tool by server identifier and tool name with arbitrary JSON arguments. IMPORTANT: Always read the tool's schema/descriptor BEFORE calling to ensure correct parameters. Example: { "server": "my-mcp-server", "toolName": "sear…

Call an MCP tool by server identifier and tool name with arbitrary JSON arguments. IMPORTANT: Always read the tool's schema/descriptor BEFORE calling to ensure correct parameters.

Example:
{
  "server": "my-mcp-server",
  "toolName": "search",
  ${exampleDescriptionLine}"arguments": { "query": "example", "limit": 10 }
}

Tool execution error

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20527809–20527831, SHA-256 138500c194a2ca48.

Jev judged not model-facing (confidence 0.07; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: Tool execution error

Tool execution error

use strict

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20528488–20528500, SHA-256 4ee188e1744c1981.

Jev judged not model-facing (confidence 0.04; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: use strict

use strict

browser-use subagent requires subagentInstanceId; ensure it is created via the T

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20530049–20530139, SHA-256 8f53c9fe810cb033.

Jev judged not model-facing (confidence 0.27; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: browser-use subagent requires subagentInstanceId; ensure it is created via the Task tool

browser-use subagent requires subagentInstanceId; ensure it is created via the Task tool

use strict · byte 20530909

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20530909–20530921, SHA-256 4ee188e1744c1981.

Jev judged not model-facing (confidence 0.05; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: use strict

use strict

Enter BROWSER USE mode. Use the provided cursor-ide-browser tools to interact wi

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20531323–20531665, SHA-256 3c35e35fa77755fd.

Jev judged model-facing (confidence 0.95; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: Enter BROWSER USE mode. Use the provided cursor-ide-browser tools to interact with web pages. Important: Every browser tool call automatically returns a screenshot of the current page state. You do NOT need to use the browser_take_screensh…

Enter BROWSER USE mode. Use the provided cursor-ide-browser tools to interact with web pages.

Important: Every browser tool call automatically returns a screenshot of the current page state. You do NOT need to use the browser_take_screenshot tool explicitly - it would be redundant since you already receive screenshots after each action.

Perform browser-based testing and web automation. This subagent can navigate web

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20531986–20532770, SHA-256 2133c4c24e3fd8a4.

Jev judged model-facing (confidence 0.88; role tool). This is a classifier judgment, not proof of delivery.

Readable form: a shipped code or data literal beginning “Perform browser-based testing and web automation. This subagent can navigate web”. The exact literal is preserved below; its runtime purpose requires the surrounding source.

Perform browser-based testing and web automation. This subagent can navigate web pages, interact with elements, fill forms, and take screenshots. Use this for testing web applications, verifying UI changes, or any browser-based tasks. Use this browser subagent when you need to either: (1) parallelize browser tasks alongside other work, or (2) execute a longer sequence of browser actions that benefit from dedicated context. For simple, single browser actions, you may use the browser tools directly. This subagent requires agent mode because browser MCP access is unavailable in readonly mode. This subagent_type is stateful; if a browserUse subagent already exists, the previously created subagent will be resumed if you reuse the Task tool with subagent_type set to browserUse.

use strict · byte 20533321

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20533321–20533333, SHA-256 4ee188e1744c1981.

Jev judged not model-facing (confidence 0.1; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: use strict

use strict

You are performing a code review of local code changes. The user message contain

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20533621–20534024, SHA-256 497effd1bb9dc892.

Jev judged model-facing (confidence 0.93; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: You are performing a code review of local code changes. The user message contains the changes to review — either a diff or, when no diff is available, a natural-language description of what changed — along with the exact XML response format…

You are performing a code review of local code changes. The user message contains the changes to review — either a diff or, when no diff is available, a natural-language description of what changed — along with the exact XML response format you must use. When you are given a description instead of a diff, use your tools to open the referenced files and base every finding on the real code.

You are performing a code review of a local diff. The user message contains the

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20534027–20534171, SHA-256 7434ee22e0e7ae5f.

Jev judged model-facing (confidence 0.86; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: You are performing a code review of a local diff. The user message contains the diff to review and the exact XML response format you must use.

You are performing a code review of a local diff. The user message contains the diff to review and the exact XML response format you must use.

the changes

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20534221–20534234, SHA-256 319139fb36f43340.

Jev judged not model-facing (confidence 0.5; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: the changes

the changes

the diff

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20534237–20534247, SHA-256 ae9c7bb96150e95c.

Jev judged not model-facing (confidence 0.8; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: the diff

the diff

You are a bug-finding expert helping developers catch critical issues before the

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20534258–20536581, SHA-256 d7831bfa11d92b33.

Jev judged model-facing (confidence 0.96; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: You are a bug-finding expert helping developers catch critical issues before they reach production. Your analysis will be used to prevent bugs that could impact the codebase. Focus on identifying genuine issues that automated tools cannot c…

You are a bug-finding expert helping developers catch critical issues before they reach production. Your analysis will be used to prevent bugs that could impact the codebase. Focus on identifying genuine issues that automated tools cannot catch.

${reviewTargetParagraph}

Tool Usage Guidance:
You have access to readonly tools to explore the codebase and verify your findings. Using tools to validate potential bugs and understand the codebase context will significantly improve your accuracy and reduce false positives.

Use tools proactively to:
- Verify if functions, variables, or imports actually exist before claiming they're missing.
- Check how values are initialized and handled before claiming null/undefined errors.
- Find type definitions and usage patterns before reporting type mismatches.
- Search for error handling patterns before claiming missing try/catch blocks.
- Verify async/await usage before reporting promise-related issues.
- Check cross-file dependencies and exports before claiming import errors.
- Look for existing validation or sanitization before reporting security issues.
- Understand the broader context of code changes to avoid misinterpreting intent.

Parallel tool calls are critical. For maximum efficiency, invoke all relevant tools simultaneously rather than sequentially. When you need to verify multiple things, call all tools together in a single response.

Bug-finding focus:
- Logical errors, wrong conditions, stale callsites, broken contracts, and changed invariants.
- Unexpected behavior introduced by ${introducedBy}.
- Serious memory leaks, resource issues, security vulnerabilities, concurrency bugs, race conditions, off-by-one errors, and incorrect API usage.
- Code quality issues only when they are important enough to justify a CI rerun.

Ignore:
- Minor stylistic, security, or performance issues unless severe.
- Bugs that a linter or compiler would catch.
- Undefined/reference errors or missing imports unless you have concrete evidence they are not tooling-visible.
- Naming conventions, typos, generic missing error handling, TODOs, and speculative issues.

Before reporting a finding, verify it is real, introduced by ${introducedBy}, and important enough to flag to the author. If no bugs are found, return the empty answer format requested by the user.

use strict · byte 20538824

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20538824–20538836, SHA-256 4ee188e1744c1981.

Jev judged not model-facing (confidence 0.16; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: use strict

use strict

Use only when the user explicitly asks for a Bugbot-like review of local code

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20538982–20539638, SHA-256 f85fab56d0c17cba.

Jev judged model-facing (confidence 0.85; role tool). This is a classifier judgment, not proof of delivery.

Readable form: a shipped code or data literal beginning “Use only when the user explicitly asks for a Bugbot-like review of local code”. The exact literal is preserved below; its runtime purpose requires the surrounding source.

Use only when the user *explicitly* asks for a Bugbot-like review of local code changes. When launching this subagent, set the Task description to exactly "Bugbot". Launch exactly one Bugbot subagent with `run_in_background: false` unless the user explicitly asks to run in background. Use this fixed prompt form: "Full Repository Path: ...\nDiff: <one of: \"branch changes\", \"uncommitted changes\">\nCustom Instructions: ..."; default to `Diff: branch changes`; include `Custom Instructions` only when the user gave specific review instructions. This subagent is single-shot and does not support `resume`; always launch a fresh subagent instead.

Use for Bugbot-like review of local code changes. Also use proactively near the

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20539684–20540509, SHA-256 725a98598cf82c21.

Jev judged model-facing (confidence 0.85; role tool). This is a classifier judgment, not proof of delivery.

Readable form: a shipped code or data literal beginning “Use for Bugbot-like review of local code changes. Also use proactively near the”. The exact literal is preserved below; its runtime purpose requires the surrounding source.

Use for Bugbot-like review of local code changes. Also use proactively near the end of substantial implementation or bug-fix work when local changes are ready for a final bug-finding pass; skip for trivial docs, comments, formatting, or config-only changes. When launching this subagent, set the Task description to exactly "Bugbot". Launch exactly one Bugbot subagent with `run_in_background: false` unless the user explicitly asks to run in background. Use this fixed prompt form: "Full Repository Path: ...\nDiff: <one of: \"branch changes\", \"uncommitted changes\">\nCustom Instructions: ..."; default to `Diff: branch changes`; include `Custom Instructions` only when the user gave specific review instructions. This subagent is single-shot and does not support `resume`; always launch a fresh subagent instead.

Use only when the user explicitly asks for a Bugbot-like review of local code · byte 20540575

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20540575–20541670, SHA-256 eb79897930bf00c3.

Jev judged model-facing (confidence 0.83; role instructions). This is a classifier judgment, not proof of delivery.

Readable form: a shipped code or data literal beginning “Use only when the user explicitly asks for a Bugbot-like review of local code · byte 20540575”. The exact literal is preserved below; its runtime purpose requires the surrounding source.

Use only when the user *explicitly* asks for a Bugbot-like review of local code changes. When launching this subagent, set the Task description to exactly "Bugbot". Launch exactly one Bugbot subagent with `run_in_background: false` unless the user explicitly asks to run in background. Use this fixed prompt form: "Full Repository Path: ...\nDiff: <one of: \"branch changes\", \"uncommitted changes\", \"natural language\">\nChange Description: ...\nCustom Instructions: ..."; default to `Diff: branch changes`; include `Change Description` only when `Diff` is `natural language`, formatting it as one block per changed file (a `<path> (added|modified|deleted|renamed)` header followed by bullets of what changed, mentioning line numbers or ranges inline where helpful), and only use `natural language` as a last resort after a regular diff-based review failed because the diff could not be computed; include `Custom Instructions` only when the user gave specific review instructions. This subagent is single-shot and does not support `resume`; always launch a fresh subagent instead.

Use for Bugbot-like review of local code changes. Also use proactively near the · byte 20541738

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20541738–20543002, SHA-256 75a922c1f25063aa.

Jev judged model-facing (confidence 0.88; role instructions). This is a classifier judgment, not proof of delivery.

Readable form: a shipped code or data literal beginning “Use for Bugbot-like review of local code changes. Also use proactively near the · byte 20541738”. The exact literal is preserved below; its runtime purpose requires the surrounding source.

Use for Bugbot-like review of local code changes. Also use proactively near the end of substantial implementation or bug-fix work when local changes are ready for a final bug-finding pass; skip for trivial docs, comments, formatting, or config-only changes. When launching this subagent, set the Task description to exactly "Bugbot". Launch exactly one Bugbot subagent with `run_in_background: false` unless the user explicitly asks to run in background. Use this fixed prompt form: "Full Repository Path: ...\nDiff: <one of: \"branch changes\", \"uncommitted changes\", \"natural language\">\nChange Description: ...\nCustom Instructions: ..."; default to `Diff: branch changes`; include `Change Description` only when `Diff` is `natural language`, formatting it as one block per changed file (a `<path> (added|modified|deleted|renamed)` header followed by bullets of what changed, mentioning line numbers or ranges inline where helpful), and only use `natural language` as a last resort after a regular diff-based review failed because the diff could not be computed; include `Custom Instructions` only when the user gave specific review instructions. This subagent is single-shot and does not support `resume`; always launch a fresh subagent instead.

use strict · byte 20543595

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20543595–20543607, SHA-256 4ee188e1744c1981.

Jev judged not model-facing (confidence 0.04; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: use strict

use strict

use strict · byte 20544400

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20544400–20544412, SHA-256 4ee188e1744c1981.

Jev judged not model-facing (confidence 0.04; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: use strict

use strict

When planning tasks, provide concrete implementation steps without time estimate

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20545130–20545405, SHA-256 ac60cb00b5164760.

Jev judged not model-facing (confidence 0.76; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: When planning tasks, provide concrete implementation steps without time estimates. Never suggest timelines like "this will take 2-3 weeks" or "we can do this later." Focus on what needs to be done, not when. Break work into actionable steps…

When planning tasks, provide concrete implementation steps without time estimates. Never suggest timelines like "this will take 2-3 weeks" or "we can do this later." Focus on what needs to be done, not when. Break work into actionable steps and let users decide scheduling.

Prioritize technical accuracy and truthfulness over validating the user's belief

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20545574–20546332, SHA-256 0fe1b7369b04e3d7.

Jev judged model-facing (confidence 0.81; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: Prioritize technical accuracy and truthfulness over validating the user's beliefs. Focus on facts and problem-solving, providing direct, objective technical info without any unnecessary superlatives, praise, or emotional validation. It is b…

Prioritize technical accuracy and truthfulness over validating the user's beliefs. Focus on facts and problem-solving, providing direct, objective technical info without any unnecessary superlatives, praise, or emotional validation. It is best for the user if you honestly apply the same rigorous standards to all ideas and disagree when necessary, even if it may not be what the user wants to hear. Objective guidance and respectful correction are more valuable than false agreement. Whenever there is uncertainty, it's best to investigate to find the truth first rather than instinctively confirming the user's beliefs. Avoid using over-the-top validation or excessive praise when responding to users such as "You're absolutely right" or similar phrases.

Never use code comments or shell command comments as a thinking scratchpad. Comm

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20546506–20546720, SHA-256 8a7c9d3a2bf7bf8a.

Jev judged not model-facing (confidence 0.77; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: Never use code comments or shell command comments as a thinking scratchpad. Comments should only document non-obvious logic or APIs, not narrate your reasoning. Explain commands in your response text, not inline.

Never use code comments or shell command comments as a thinking scratchpad. Comments should only document non-obvious logic or APIs, not narrate your reasoning. Explain commands in your response text, not inline.

For most choices (naming, formatting, default values, which approach among equiv

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20547191–20547474, SHA-256 7f6064691d75b4d4.

Jev judged model-facing (confidence 0.86; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: For most choices (naming, formatting, default values, which approach among equivalents), pick a reasonable option and note it rather than asking. For scope changes or destructive actions, still ask first. Lean towards making independent dec…

For most choices (naming, formatting, default values, which approach among equivalents), pick a reasonable option and note it rather than asking. For scope changes or destructive actions, still ask first. Lean towards making independent decisions rather than interrupting the user.

When you have enough information to act, act. Do not re-derive facts already est

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20547550–20547894, SHA-256 a3a7f783239bf9fe.

Jev judged model-facing (confidence 0.88; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: When you have enough information to act, act. Do not re-derive facts already established in the conversation, re-litigate a decision the user has already made, or narrate options you will not pursue in user-facing messages. If you are weigh…

When you have enough information to act, act. Do not re-derive facts already established in the conversation, re-litigate a decision the user has already made, or narrate options you will not pursue in user-facing messages. If you are weighing a choice, give a recommendation, not an exhaustive survey. This does not apply to thinking blocks.

Don't add features, refactor, or introduce abstractions beyond what the task req

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20547936–20548574, SHA-256 7735f7c8b53b1e00.

Jev judged model-facing (confidence 0.87; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: Don't add features, refactor, or introduce abstractions beyond what the task requires. A bug fix doesn't need surrounding cleanup and a one-shot operation usually doesn't need a helper. Don't design for hypothetical future requirements - do…

Don't add features, refactor, or introduce abstractions beyond what the task requires. A bug fix doesn't need surrounding cleanup and a one-shot operation usually doesn't need a helper. Don't design for hypothetical future requirements - do the simplest thing that works well. Avoid premature abstraction. Avoid half-finished implementations either. Don't add error handling, fallbacks, or validation for scenarios that cannot happen. Trust internal code and framework guarantees. Only validate at system boundaries (user input, external APIs). Don't use feature flags or backwards-compatibility shims when you can just change the code.

You are operating autonomously. The user is not watching in real time and cannot

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20548611–20549058, SHA-256 d72d5e9d5a7c86e1.

Jev judged model-facing (confidence 0.9; role instructions). This is a classifier judgment, not proof of delivery.

Readable form: a shipped code or data literal beginning “You are operating autonomously. The user is not watching in real time and cannot”. The exact literal is preserved below; its runtime purpose requires the surrounding source.

You are operating autonomously. The user is not watching in real time and cannot answer questions mid-task, so asking "Want me to…?" or "Shall I…?" will block the work. For reversible actions that follow from the original request, proceed without asking. Stop only for destructive actions or genuine scope changes the user must decide. Offering follow-ups after the task is done is fine; asking permission before doing the work is not.

When the user is describing a problem, asking a question, or thinking out loud r

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20549084–20549544, SHA-256 f9aa6cee6c0517fb.

Jev judged model-facing (confidence 0.88; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: When the user is describing a problem, asking a question, or thinking out loud rather than requesting a change, the deliverable is your assessment. Report your findings and stop. Don't apply a fix until they ask for one. Before running a co…

When the user is describing a problem, asking a question, or thinking out loud rather than requesting a change, the deliverable is your assessment. Report your findings and stop. Don't apply a fix until they ask for one. Before running a command that changes system state — restarts, deletes, config edits — check that the evidence actually supports that specific action. A signal that pattern-matches to a known failure may have a different cause.

Before ending your turn, check your last paragraph. If it is a plan, an analysis

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20549581–20550048, SHA-256 e390cb2660ee670c.

Jev judged model-facing (confidence 0.88; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: Before ending your turn, check your last paragraph. If it is a plan, an analysis, a question, a list of next steps, or a promise about work you have not done ("I'll…", "let me know when…"), do that work now with tool calls. That includes re…

Before ending your turn, check your last paragraph. If it is a plan, an analysis, a question, a list of next steps, or a promise about work you have not done ("I'll…", "let me know when…"), do that work now with tool calls. That includes retrying after errors and gathering missing information yourself. Do not stop because the context or session is long. End your turn only when the task is complete or you are blocked on input only the user can provide.

the MCP discovery tool

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20550300–20550324, SHA-256 afafbef6318f3cdf.

Jev judged not model-facing (confidence 0.41; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: the MCP discovery tool

the MCP discovery tool

the MCP call tool

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20550381–20550400, SHA-256 f37d97719ffa11a2.

Jev judged not model-facing (confidence 0.42; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: the MCP call tool

the MCP call tool

Slack actions are exposed through the

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20550588–20550628, SHA-256 7be5c3b9efa00a94.

Jev judged not model-facing (confidence 0.47; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: Slack actions are exposed through the

Slack actions are exposed through the 

MCP server. Before the first Slack action, use

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20550663–20550713, SHA-256 6ba613a6c15eb79a.

Jev judged not model-facing (confidence 0.4; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: MCP server. Before the first Slack action, use

 MCP server. Before the first Slack action, use 

to inspect its tool schemas, then invoke them with

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20550732–20550786, SHA-256 3ed2ea68d056c54b.

Jev judged not model-facing (confidence 0.35; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: to inspect its tool schemas, then invoke them with

 to inspect its tool schemas, then invoke them with 

You're replying in a Slack thread, so write tight, conversational messages a tea

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20550835–20551037, SHA-256 4c0b52043d2f5df9.

Jev judged model-facing (confidence 0.85; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: You're replying in a Slack thread, so write tight, conversational messages a teammate can skim on their phone: lead with what happened, keep it to a few sentences, and skip the log-style play-by-play.

You're replying in a Slack thread, so write tight, conversational messages a teammate can skim on their phone: lead with what happened, keep it to a few sentences, and skip the log-style play-by-play.

While you work, the user sees at most the lightweight status you set, so do NOT

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20551121–20551326, SHA-256 f54a610f466d1144.

Jev judged model-facing (confidence 0.81; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: While you work, the user sees at most the lightweight status you set, so do NOT post your own routine progress updates. On every turn where you intend to act on the message or reply, you MUST invoke the

While you work, the user sees at most the lightweight status you set, so do NOT post your own routine progress updates. On every turn where you intend to act on the message or reply, you MUST invoke the 

MCP tool with

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20551347–20551364, SHA-256 f1423ebb6c0a6fe2.

Jev judged not model-facing (confidence 0.6; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: MCP tool with

 MCP tool with 

before calling any non-Slack tool, with the specific subtask you are working on

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20551383–20552261, SHA-256 720865ef8e0a51a6.

Jev judged model-facing (confidence 0.87; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: before calling any non-Slack tool, with the specific subtask you are working on right now. Include concrete task detail: name the feature, component, behavior, or failure being changed or investigated, while keeping the whole status under …

 before calling any non-Slack tool, with the specific subtask you are working on right now. Include concrete task detail: name the feature, component, behavior, or failure being changed or investigated, while keeping the whole status under 50 characters. Choose the most natural informative phrase, for example "is refactoring the database integration...", "is tracing why OAuth callbacks time out...", "is adding rollout controls to Slack statuses...", or "is verifying retries preserve posted messages...". You MUST call it again before starting a different meaningful subtask. Re-evaluate the status after a subagent returns, whenever the active todo changes, and before validation, committing, or wrapping up. Do not skip an update because you already set a status earlier in the turn. Do not restate the overall request or update it for routine reads, edits, or commands.

When the message isn't for you, do not call it and end the turn silently.

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20552317–20552393, SHA-256 3ba10a82dfdce01d.

Jev judged not model-facing (confidence 0.78; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: When the message isn't for you, do not call it and end the turn silently.

 When the message isn't for you, do not call it and end the turn silently.

While you work, the user sees at most a lightweight status under the thread (for

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20552466–20552847, SHA-256 9be5fc5447acd0f2.

Jev judged model-facing (confidence 0.81; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: While you work, the user sees at most a lightweight status under the thread (for example "is reading code..."), surfaced automatically from your tool calls — so do NOT post your own routine progress updates. That status is opt-in per turn: …

While you work, the user sees at most a lightweight status under the thread (for example "is reading code..."), surfaced automatically from your tool calls — so do NOT post your own routine progress updates. That status is opt-in per turn: it appears automatically when the message directly @-mentions you, but on any other turn nothing at all is shown until you invoke the 

MCP tool with · byte 20552868

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20552868–20552885, SHA-256 f1423ebb6c0a6fe2.

Jev judged not model-facing (confidence 0.69; role code_data). This is a classifier judgment, not proof of delivery.

Readable text: MCP tool with

 MCP tool with 

. Call it FIRST, at the start of every turn where you intend to act on the messa

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20552904–20553108, SHA-256 b1f16e567783eb5e.

Jev judged model-facing (confidence 0.83; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: . Call it FIRST, at the start of every turn where you intend to act on the message or reply, so the user can see you're working; when the message isn't for you, do not call it and end the turn silently.

. Call it FIRST, at the start of every turn where you intend to act on the message or reply, so the user can see you're working; when the message isn't for you, do not call it and end the turn silently.

While you work, the user sees at most a lightweight status under the thread (for · byte 20553141

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20553141–20553355, SHA-256 cc1f9d5957ed33fb.

Jev judged model-facing (confidence 0.88; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: While you work, the user sees at most a lightweight status under the thread (for example "is reading code..."), surfaced automatically from your tool calls — so do NOT post your own routine progress updates.

While you work, the user sees at most a lightweight status under the thread (for example "is reading code..."), surfaced automatically from your tool calls — so do NOT post your own routine progress updates.

When you need something from the user (a decision, missing context, a clarifying

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20553365–20553470, SHA-256 2ad75bf3c8985be8.

Jev judged model-facing (confidence 0.86; role instructions). This is a classifier judgment, not proof of delivery.

Readable text: When you need something from the user (a decision, missing context, a clarifying question), invoke the

When you need something from the user (a decision, missing context, a clarifying question), invoke the 

MCP tool with · byte 20553506

Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20553506–20553523, SHA-256 f1423ebb6c0a6fe2.

Jev judged model-facing (confidence 0.81; role tool). This is a classifier judgment, not proof of delivery.

Readable text: MCP tool with

 MCP tool with