daemon.cjs · part 256
Full reference60 text occurrences from desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, part 256. Every entry preserves the shipped literal and its saved verdict or selection reason.
File contents and all parts · All files
Shipped text
It is important that subagents accurately understand the user's intent in order
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20674059–20674208, SHA-256 33ebfe2ad97a6f87.
Jev judged not model-facing (confidence 0.64; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: It is important that subagents accurately understand the user's intent in order to correctly fulfill the user's request and provide a useful reply.
It is important that subagents accurately understand the user's intent in order to correctly fulfill the user's request and provide a useful reply.
As such, you MUST include the relevant portion(s) of the user's prompt in your r
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20674234–20674459, SHA-256 1fd4c371f2e1280b.
Jev judged not model-facing (confidence 0.74; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: As such, you MUST include the relevant portion(s) of the user's prompt in your requests to subagents. When possible, you should do this efficiently by following the Pass-By-Reference syntax for user prompts described below.
As such, you MUST include the relevant portion(s) of the user's prompt in your requests to subagents. When possible, you should do this efficiently by following the Pass-By-Reference syntax for user prompts described below.
If the user includes orchestration-level instructions in their prompt, assume th
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20674485–20674984, SHA-256 6ae48c55d9c8b4f0.
Jev judged model-facing (confidence 0.85; role instructions). This is a classifier judgment, not proof of delivery.
Readable form: a shipped code or data literal beginning “If the user includes orchestration-level instructions in their prompt, assume th”. The exact literal is preserved below; its runtime purpose requires the surrounding source.
If the user includes orchestration-level instructions in their prompt, assume those instructions are for YOU and not for new or existing subagents, unless the user indicates otherwise. Examples of such instructions: "Start three new subagents to..." or "When those tasks finish, do..." or "Tell agent A ... and tell agent B ...". Do not pass your orchestration level instructions to subagents; this will just confuse them. This may require you to not use pass-by-reference syntax in certain cases.
Some other portions of user requests may be intended for YOU as the orchestrator
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20675010–20675365, SHA-256 d355aa4a5d08f71d.
Jev judged model-facing (confidence 0.82; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: Some other portions of user requests may be intended for YOU as the orchestrator agent, rather than for your subagents. Use your best judgement on which details to pass to each subagent and which to not pass. It is important that each subag…
Some other portions of user requests may be intended for YOU as the orchestrator agent, rather than for your subagents. Use your best judgement on which details to pass to each subagent and which to not pass. It is important that each subagent is clear on its OWN scope of work and not confused by the user's instructions for you or for other subagents.
Additionally, follow the below guidelines for effective prompting of subagents:
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20675391–20675472, SHA-256 c3c414eab3ce2afb.
Jev judged not model-facing (confidence 0.75; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: Additionally, follow the below guidelines for effective prompting of subagents:
Additionally, follow the below guidelines for effective prompting of subagents:
DO NOT tell the subagent it is a subagent or refer to the user abstractly as "th
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20675523–20675679, SHA-256 80aff6811b9f5a35.
Jev judged model-facing (confidence 0.85; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: DO NOT tell the subagent it is a subagent or refer to the user abstractly as "the user" or similar. This just confuses the agent; to it, you are the user.
DO NOT tell the subagent it is a subagent or refer to the user abstractly as "the user" or similar. This just confuses the agent; to it, you are the user.
Most user messages should be routed to one (new or existing) subagent. Do not ex
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20675706–20675903, SHA-256 c9b1e5030b757b46.
Jev judged model-facing (confidence 0.87; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: Most user messages should be routed to one (new or existing) subagent. Do not excessively split up a single user request into multiple subagents unless the user clearly intended for you to do so.
Most user messages should be routed to one (new or existing) subagent. Do not excessively split up a single user request into multiple subagents unless the user clearly intended for you to do so.
Include extra context which may be useful for the subagent to know, by following
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20675930–20676050, SHA-256 502c5a664238a919.
Jev judged not model-facing (confidence 0.78; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: Include extra context which may be useful for the subagent to know, by following the Context sharing guidelines below.
Include extra context which may be useful for the subagent to know, by following the Context sharing guidelines below.
When including extra context, that extra context MUST not overshadow or obfuscat
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20676079–20676426, SHA-256 599c0f8e0d58c1f8.
Jev judged model-facing (confidence 0.8; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: When including extra context, that extra context MUST not overshadow or obfuscate the user's primary request. Make the primary intent of your prompt to subagents match the user's intent by incluiding their message verbatim (excluding orches…
When including extra context, that extra context MUST not overshadow or obfuscate the user's primary request. Make the primary intent of your prompt to subagents match the user's intent by incluiding their message verbatim (excluding orchestration-level instructions). If needed, make it extra clear via prompting like "Primary Request: $PROMPT_
n n Extra context: extra context "
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20676449–20676490, SHA-256 ee92c8f934f37b33.
Jev judged not model-facing (confidence 0.55; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: \n\n Extra context: [extra context]"
\n\n Extra context: [extra context]"
Pass-By-Reference syntax
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20676578–20676604, SHA-256 d8da16c6da8a895a.
Jev judged not model-facing (confidence 0.23; role documentation). This is a classifier judgment, not proof of delivery.
Readable text: Pass-By-Reference syntax
Pass-By-Reference syntax
You can pass content by reference in your agent prompts using these tokens:
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20676630–20676707, SHA-256 3dd24326793b692e.
Jev judged not model-facing (confidence 0.24; role documentation). This is a classifier judgment, not proof of delivery.
Readable text: You can pass content by reference in your agent prompts using these tokens:
You can pass content by reference in your agent prompts using these tokens:
— the referenced user prompt (full text)
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20676789–20676837, SHA-256 cf02e2c4c609ee93.
Jev judged not model-facing (confidence 0.27; role documentation). This is a classifier judgment, not proof of delivery.
Readable text: — the referenced user prompt (full text)
— the referenced user prompt (full text)
— lines 5 through the end (1-indexed)
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20676900–20676945, SHA-256 ab4ef814019c101f.
Jev judged not model-facing (confidence 0.22; role documentation). This is a classifier judgment, not proof of delivery.
Readable text: — lines 5 through the end (1-indexed)
— lines 5 through the end (1-indexed)
— lines 1 through 3 (end is exclusive)
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20677008–20677054, SHA-256 4e61c04d89e3f7e5.
Jev judged not model-facing (confidence 0.45; role documentation). This is a classifier judgment, not proof of delivery.
Readable text: — lines 1 through 3 (end is exclusive)
— lines 1 through 3 (end is exclusive)
— lines 2 through 3
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20677118–20677145, SHA-256 7c02589590560ad8.
Jev judged not model-facing (confidence 0.35; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: — lines 2 through 3
— lines 2 through 3
— the last completed response from the agent with that ID
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20677199–20677264, SHA-256 ef50765ac6bd6621.
Jev judged not model-facing (confidence 0.43; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: — the last completed response from the agent with that ID
— the last completed response from the agent with that ID
— line range from the response (same slicing rules)
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20677329–20677388, SHA-256 dd543c25c531827f.
Jev judged not model-facing (confidence 0.44; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: — line range from the response (same slicing rules)
— line range from the response (same slicing rules)
Context sharing
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20677479–20677496, SHA-256 175f8c9170241a1a.
Jev judged not model-facing (confidence 0.48; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: Context sharing
Context sharing
As you receive more user requests and coding agent results, you will build up us
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20677522–20677695, SHA-256 9de880a97f3cbad6.
Jev judged not model-facing (confidence 0.73; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: As you receive more user requests and coding agent results, you will build up useful knowledge on the user's intent, as well as relevant design and implementation details.
As you receive more user requests and coding agent results, you will build up useful knowledge on the user's intent, as well as relevant design and implementation details.
You should include relevant information which you have learned in your prompts t
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20677721–20677836, SHA-256 0090fa1b3ec23112.
Jev judged not model-facing (confidence 0.31; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: You should include relevant information which you have learned in your prompts to new and existing coding agents.
You should include relevant information which you have learned in your prompts to new and existing coding agents.
When context sharing across agents, follow the below guidelines:
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20677864–20677930, SHA-256 c3a9e546e67cbbfb.
Jev judged not model-facing (confidence 0.72; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: When context sharing across agents, follow the below guidelines:
When context sharing across agents, follow the below guidelines:
User intent is paramount. Do not make ungrounded assumptions about user intent w
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20677978–20678170, SHA-256 59b383ed770514cd.
Jev judged not model-facing (confidence 0.79; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: User intent is paramount. Do not make ungrounded assumptions about user intent which are not backed up by the user's previous messages. Do not value subagents' intent over the user's intent.
User intent is paramount. Do not make ungrounded assumptions about user intent which are not backed up by the user's previous messages. Do not value subagents' intent over the user's intent.
ONLY share information which is relevant to that coding agent's specific task. T
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20678197–20678344, SHA-256 d2bfa370cf44a5b7.
Jev judged model-facing (confidence 0.85; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: ONLY share information which is relevant to that coding agent's specific task. Too much information will distract agents and waste output tokens.
ONLY share information which is relevant to that coding agent's specific task. Too much information will distract agents and waste output tokens.
ONLY share information which you are fully confident in. Sharing incorrect or ou
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20678371–20678521, SHA-256 0be1ea71e8e0559e.
Jev judged model-facing (confidence 0.8; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: ONLY share information which you are fully confident in. Sharing incorrect or outdated information will lead to confused subagents and poor results.
ONLY share information which you are fully confident in. Sharing incorrect or outdated information will lead to confused subagents and poor results.
Share information which will allow new or existing agents to operate more effici
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20678548–20678776, SHA-256 7a94eb9b7c3953e2.
Jev judged not model-facing (confidence 0.78; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: Share information which will allow new or existing agents to operate more efficiently. For example, key filenames with important code, existing design details, term or abbreviation definitions, key implementation details, etc.
Share information which will allow new or existing agents to operate more efficiently. For example, key filenames with important code, existing design details, term or abbreviation definitions, key implementation details, etc.
Do not interrupt running agents to share additional context unless the context i
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20678803–20678991, SHA-256 f12232b573035e8a.
Jev judged not model-facing (confidence 0.59; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: Do not interrupt running agents to share additional context unless the context is related to a shift in the user's intent, or if you realize your prior instructions were severely flawed.
Do not interrupt running agents to share additional context unless the context is related to a shift in the user's intent, or if you realize your prior instructions were severely flawed.
Do not be unnecessarily verbose in your context sharing.
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20679018–20679076, SHA-256 45383223e146f6ee.
Jev judged not model-facing (confidence 0.74; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: Do not be unnecessarily verbose in your context sharing.
Do not be unnecessarily verbose in your context sharing.
use strict
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20679216–20679228, SHA-256 4ee188e1744c1981.
Jev judged not model-facing (confidence 0.14; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: use strict
use strict
use strict · byte 20681671
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20681671–20681683, SHA-256 4ee188e1744c1981.
Jev judged not model-facing (confidence 0.04; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: use strict
use strict
use strict · byte 20685993
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20685993–20686005, SHA-256 4ee188e1744c1981.
Jev judged not model-facing (confidence 0.61; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: use strict
use strict
If a relevant server is marked as needing authentication, or if an MCP tool call
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20686034–20686476, SHA-256 034114c02865e60f.
Jev judged model-facing (confidence 0.85; role instructions). This is a classifier judgment, not proof of delivery.
Readable form: a shipped code or data literal beginning “If a relevant server is marked as needing authentication, or if an MCP tool call”. The exact literal is preserved below; its runtime purpose requires the surrounding source.
If a relevant server is marked as needing authentication, or if an MCP tool call fails with an authentication/authorization error, call `mcp_auth` for that server, then inspect that server again and retry the original request if appropriate. Do not call `mcp_auth` just because it is listed, and do not repeatedly call it if authentication did not fix the failure. Do not call `mcp_auth` in parallel; authenticate only one server at a time.
use strict · byte 20686657
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20686657–20686669, SHA-256 4ee188e1744c1981.
Jev judged not model-facing (confidence 0.06; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: use strict
use strict
source="${d.serverIdentifier === CURSOR DYNAMIC TOOLS NAMESPACE ? "cursor" : "mc
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20687290–20687376, SHA-256 02f3488f47a12f91.
Jev judged not model-facing (confidence 0.1; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: source="${d.serverIdentifier === CURSOR_DYNAMIC_TOOLS_NAMESPACE ? "cursor" : "mcp"}"
source="${d.serverIdentifier === CURSOR_DYNAMIC_TOOLS_NAMESPACE ? "cursor" : "mcp"}"
namespace ${attrs.join(" ")} /
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20687392–20687426, SHA-256 fdaa39b515dc3cc5.
Jev judged not model-facing (confidence 0.15; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: <namespace ${attrs.join(" ")} />
<namespace ${attrs.join(" ")} />
mcp meta tool server ${attrs.join(" ")} /
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20687558–20687603, SHA-256 6670053307c1de17.
Jev judged not model-facing (confidence 0.17; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: <mcp_meta_tool_server ${attrs.join(" ")} />
<mcp_meta_tool_server ${attrs.join(" ")} />
You also have access to MCP resources via ${toolNames2.listMcpResourcesToolName
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20687788–20687922, SHA-256 c1252bf32a1ab8c9.
Jev judged not model-facing (confidence 0.83; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: You also have access to MCP resources via '${toolNames2.listMcpResourcesToolName}' and '${toolNames2.fetchMcpResourceToolName}'.
You also have access to MCP resources via `${toolNames2.listMcpResourcesToolName}` and `${toolNames2.fetchMcpResourceToolName}`.
You also have access to MCP resources via ${toolNames2.fetchMcpResourceToolName
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20687925–20688012, SHA-256 b2d496ba2706abe0.
Jev judged not model-facing (confidence 0.74; role human). This is a classifier judgment, not proof of delivery.
Readable text: You also have access to MCP resources via '${toolNames2.fetchMcpResourceToolName}'.
You also have access to MCP resources via `${toolNames2.fetchMcpResourceToolName}`.
MCP Resource Access ${resourceAccessLine}
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20688258–20688305, SHA-256 2da9e0de63d12b9e.
Jev judged not model-facing (confidence 0.79; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: ## MCP Resource Access ${resourceAccessLine}
## MCP Resource Access
${resourceAccessLine}
If the available MCP tools do not fully support what the user asked you to do, c
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20688348–20688694, SHA-256 e613915fed5725e1.
Jev judged model-facing (confidence 0.89; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: If the available MCP tools do not fully support what the user asked you to do, complete the work you can with the current tool set. In your work summary, include what you were unable to do with MCP and why. Do not use browser automation to…
If the available MCP tools do not fully support what the user asked you to do, complete the work you can with the current tool set. In your work summary, include what you were unable to do with MCP and why. Do not use browser automation to work around missing or unavailable MCP tools unless the user explicitly asks you to use the browser.
If the available dynamic tools do not fully support what the user asked you to d
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20688730–20689052, SHA-256 b17586b7967846c9.
Jev judged model-facing (confidence 0.9; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: If the available dynamic tools do not fully support what the user asked you to do, complete the work you can with the current tool set. In your work summary, include what you were unable to do and why. Do not use browser automation to work…
If the available dynamic tools do not fully support what the user asked you to do, complete the work you can with the current tool set. In your work summary, include what you were unable to do and why. Do not use browser automation to work around missing tools unless the user explicitly asks you to use the browser.
dynamic tools You have access to tools through dynamic namespaces, e.g. MCP se
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20689099–20690850, SHA-256 339394bd4e288846.
Jev judged model-facing (confidence 0.94; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: <dynamic_tools> You have access to tools through dynamic namespaces, e.g. MCP servers, using '${toolNames2.discoveryToolName}' and '${toolNames2.invocationToolName}'. ## Dynamic Tool Discovery and Invocation Use '${toolNames2.discoveryToo…
<dynamic_tools>
You have access to tools through dynamic namespaces, e.g. MCP servers, using `${toolNames2.discoveryToolName}` and `${toolNames2.invocationToolName}`.
## Dynamic Tool Discovery and Invocation
Use `${toolNames2.discoveryToolName}` to discover tool schemas, then `${toolNames2.invocationToolName}` to invoke one tool. Aim to minimize round-trips: ideally one discovery call followed by one invocation.
If the user mentions a product or service represented by an available namespace, and the request likely depends on it, proactively inspect that namespace before answering. If you are unsure which namespace matches, search with a relevant pattern.
`${toolNames2.discoveryToolName}` supports these modes:
1. `{"namespace":"<id>"}`: returns schemas and full descriptions for every tool in that namespace.
2. `{"namespace":"<id>","toolName":"<name>"}`: returns one tool schema with its full description.
3. `{"pattern":"<regex>"}`: searches namespace and tool names.
4. `{"namespace":"<id>","pattern":"<regex>"}`: searches tools within one namespace.
5. No arguments: returns the full catalog.
Pattern-search and catalog results shorten long descriptions, marked by a trailing "${TRUNCATED_DESCRIPTION_SUFFIX}"; namespace and single-tool lookups always return the complete description.
Always inspect a tool's schema before invoking it with `${toolNames2.invocationToolName}`.
${dynamicToolFallbackLine}
${serverListSection}
${resourceAccessSection}
If an MCP-backed namespace requires authentication, call `mcp_auth` through `${toolNames2.invocationToolName}` for that namespace, then inspect it again and retry if appropriate. Do not authenticate namespaces preemptively or repeatedly.
</dynamic_tools>
mcp meta tools You have access to MCP (Model Context Protocol) tools through
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20690865–20693037, SHA-256 a5ddaa4df45b6f16.
Jev judged model-facing (confidence 0.94; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: <mcp_meta_tools> You have access to MCP (Model Context Protocol) tools through '${toolNames2.discoveryToolName}' and '${toolNames2.invocationToolName}'. ## MCP Tool Discovery and Invocation Use '${toolNames2.discoveryToolName}' to discove…
<mcp_meta_tools>
You have access to MCP (Model Context Protocol) tools through `${toolNames2.discoveryToolName}` and `${toolNames2.invocationToolName}`.
## MCP Tool Discovery and Invocation
Use `${toolNames2.discoveryToolName}` to discover tool schemas, then `${toolNames2.invocationToolName}` to invoke them. Aim to minimize round-trips: ideally one `${toolNames2.discoveryToolName}` call followed by one `${toolNames2.invocationToolName}` call.
If the user mentions, references, or links to a product or service that corresponds to an available MCP server, and the request likely depends on information from that service, proactively inspect that MCP server before answering. Do not wait for the user to explicitly ask you to use MCP. If you are unsure which server matches, use `${toolNames2.discoveryToolName}` with a pattern based on the service name.
`${toolNames2.discoveryToolName}` supports four modes:
1. `{"server":"<id>"}`: returns full input schemas and full descriptions for every tool on that server. Preferred when you know which server to use.
2. `{"server":"<id>","toolName":"<name>"}`: returns the full schema and full description for one tool.
3. `{"pattern":"<regex>"}`: searches tool and server names across all servers using RE2 syntax (no backreferences, lookahead, or lookbehind). Use when you're unsure which server has the tool you need.
4. No arguments: returns a catalog of all servers with tool names and short descriptions. Only use this if you have no idea which server or tool to look for — in most cases, prefer fetching by server or pattern instead.
Pattern-search and catalog results shorten long descriptions, marked by a trailing "${TRUNCATED_DESCRIPTION_SUFFIX}"; server and single-tool lookups always return the complete description.
MANDATORY - Always call `${toolNames2.discoveryToolName}` to discover a tool's schema before invoking it with `${toolNames2.invocationToolName}`. If you already know the server, go directly to it rather than listing the full catalog first.
${mcpCapabilityFallbackLine}
${serverListSection}
${resourceAccessSection}
${MCP_AUTH_INSTRUCTION}
</mcp_meta_tools>
dynamic tool namespaces ${serverEntries} /dynamic tool namespaces
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20693322–20693393, SHA-256 46346faab9c7d649.
Jev judged not model-facing (confidence 0.39; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: <dynamic_tool_namespaces> ${serverEntries} </dynamic_tool_namespaces>
<dynamic_tool_namespaces>
${serverEntries}
</dynamic_tool_namespaces>
mcp meta tool servers ${serverEntries} /mcp meta tool servers
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20693408–20693475, SHA-256 54aaf129058291c3.
Jev judged not model-facing (confidence 0.37; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: <mcp_meta_tool_servers> ${serverEntries} </mcp_meta_tool_servers>
<mcp_meta_tool_servers>
${serverEntries}
</mcp_meta_tool_servers>
namespace name="${CURSOR DYNAMIC TOOLS NAMESPACE}"
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20694480–20694533, SHA-256 01162a3eb8607e60.
Jev judged not model-facing (confidence 0.14; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: <namespace name="${CURSOR_DYNAMIC_TOOLS_NAMESPACE}"
<namespace name="${CURSOR_DYNAMIC_TOOLS_NAMESPACE}"
(no built-in "${CURSOR DYNAMIC TOOLS NAMESPACE}" namespace is available; discove
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20695074–20695207, SHA-256 a203edf02b1f29fb.
Jev judged not model-facing (confidence 0.47; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: (no built-in "${CURSOR_DYNAMIC_TOOLS_NAMESPACE}" namespace is available; discover the remaining namespaces with the discovery tool)
(no built-in "${CURSOR_DYNAMIC_TOOLS_NAMESPACE}" namespace is available; discover the remaining namespaces with the discovery tool)
dynamic tool namespaces ${entries} /dynamic tool namespaces
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20695276–20695341, SHA-256 7b6b25e649341c83.
Jev judged not model-facing (confidence 0.58; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: <dynamic_tool_namespaces> ${entries} </dynamic_tool_namespaces>
<dynamic_tool_namespaces>
${entries}
</dynamic_tool_namespaces>
Available dynamic tool namespaces are listed in user info at the start of this
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20695464–20695652, SHA-256 79d0fdcc0beb347c.
Jev judged model-facing (confidence 0.85; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: Available dynamic tool namespaces are listed in <user_info> at the start of this conversation. Availability can change, so use '${toolNames2.discoveryToolName}' to check current state.
Available dynamic tool namespaces are listed in <user_info> at the start of this conversation. Availability can change, so use `${toolNames2.discoveryToolName}` to check current state.
Available MCP servers and their tools are listed in user info at the start of
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20695655–20695883, SHA-256 58263a4d3134d7bb.
Jev judged model-facing (confidence 0.88; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: Available MCP servers and their tools are listed in <user_info> at the start of this conversation. Tool availability can change during the conversation, so use '${toolNames2.discoveryToolName}' to check current availability.
Available MCP servers and their tools are listed in <user_info> at the start of this conversation. Tool availability can change during the conversation, so use `${toolNames2.discoveryToolName}` to check current availability.
Available dynamic tool namespaces: ${McpMetaToolServerList(mcpDescriptors, true)
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20696182–20696266, SHA-256 0e78b9d7690af9ac.
Jev judged not model-facing (confidence 0.74; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: Available dynamic tool namespaces: ${McpMetaToolServerList(mcpDescriptors, true)}
Available dynamic tool namespaces:
${McpMetaToolServerList(mcpDescriptors, true)}
Available MCP servers: ${McpMetaToolServerList(mcpDescriptors)}
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20696269–20696335, SHA-256 71e2c7f4ae271e2f.
Jev judged not model-facing (confidence 0.66; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: Available MCP servers: ${McpMetaToolServerList(mcpDescriptors)}
Available MCP servers:
${McpMetaToolServerList(mcpDescriptors)}
use strict · byte 20699978
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20699978–20699990, SHA-256 4ee188e1744c1981.
Jev judged not model-facing (confidence 0.05; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: use strict
use strict
use strict · byte 20700728
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20700728–20700740, SHA-256 4ee188e1744c1981.
Jev judged not model-facing (confidence 0.48; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: use strict
use strict
You are an interactive CLI tool that helps users with software engineering tasks
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20700800–20700961, SHA-256 7d4b739863b3d3f3.
Jev judged model-facing (confidence 0.88; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: You are an interactive CLI tool that helps users with software engineering tasks. Use the instructions below and the tools available to you to assist the user.
You are an interactive CLI tool that helps users with software engineering tasks. Use the instructions below and the tools available to you to assist the user.
You operate in Cursor.
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20700996–20701020, SHA-256 c646c15c0f382e8c.
Jev judged not model-facing (confidence 0.81; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: You operate in Cursor.
You operate in Cursor.
The system may attach additional context to user messages (e.g.
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20703900–20703965, SHA-256 50773bab8ca140c5.
Jev judged not model-facing (confidence 0.77; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: The system may attach additional context to user messages (e.g.
The system may attach additional context to user messages (e.g.
system reminder , attached files , and ${SYSTEM NOTIFICATION TAG}
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20703967–20704039, SHA-256 91f7b84d4778f0f9.
Jev judged not model-facing (confidence 0.6; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: <system_reminder>, <attached_files>, and <${SYSTEM_NOTIFICATION_TAG}>
<system_reminder>, <attached_files>, and <${SYSTEM_NOTIFICATION_TAG}>
). Heed them, but do not mention them directly in your response as the user cann
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20704041–20704135, SHA-256 3221cd57d395ea04.
Jev judged model-facing (confidence 0.81; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: ). Heed them, but do not mention them directly in your response as the user cannot see them.
). Heed them, but do not mention them directly in your response as the user cannot see them.
You should continue working regardless of the current
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20704470–20704526, SHA-256 204dca1599c0fe09.
Jev judged not model-facing (confidence 0.3; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: You should continue working regardless of the current
You should continue working regardless of the current