daemon.cjs · part 268
Full reference60 text occurrences from desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, part 268. Every entry preserves the shipped literal and its saved verdict or selection reason.
File contents and all parts · All files
Shipped text
pip install -r requirements.txt
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20849998–20850035, SHA-256 caa019abde357695.
Jev judged not model-facing (confidence 0.32; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: 'pip install -r requirements.txt'
`pip install -r requirements.txt`
uv sync
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20850043–20850056, SHA-256 b3142ca467cf649b.
Jev judged not model-facing (confidence 0.27; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: 'uv sync'
`uv sync`
, etc. For more complex cases requiring multiple steps, use a multiline script w
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20850058–20850185, SHA-256 62ca55bd01279d93.
Jev judged not model-facing (confidence 0.43; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: , etc. For more complex cases requiring multiple steps, use a multiline script with each command on its own line (do NOT use
, etc. For more complex cases requiring multiple steps, use a multiline script with each command on its own line (do NOT use
to chain commands - use newlines instead). This should not include system depend
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20850193–20850487, SHA-256 917725cdca6af6cf.
Jev judged not model-facing (confidence 0.48; role documentation). This is a classifier judgment, not proof of delivery.
Readable text: to chain commands - use newlines instead). This should not include system dependencies that aren't part of the codebase, and it should NOT include service startup logic, migrations, test commands, build commands, or other brittle steps. Ex…
to chain commands - use newlines instead). This should not include system dependencies that aren't part of the codebase, and it should NOT include service startup logic, migrations, test commands, build commands, or other brittle steps. Examples that MUST NOT be in the update script include
docker compose up
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20850489–20850512, SHA-256 f767fc95713c8129.
Jev judged not model-facing (confidence 0.18; role documentation). This is a classifier judgment, not proof of delivery.
Readable text: 'docker compose up'
`docker compose up`
docker-compose up
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20850520–20850543, SHA-256 b90b1c4c230f8a89.
Jev judged not model-facing (confidence 0.24; role documentation). This is a classifier judgment, not proof of delivery.
Readable text: 'docker-compose up'
`docker-compose up`
pnpm dev
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20850551–20850565, SHA-256 303daf60c1e6ebf3.
Jev judged not model-facing (confidence 0.19; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: 'pnpm dev'
`pnpm dev`
npm run dev
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20850577–20850594, SHA-256 ae7a6c66b0e5cf53.
Jev judged not model-facing (confidence 0.15; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: 'npm run dev'
`npm run dev`
python manage.py runserver
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20850606–20850638, SHA-256 2f50b2c997b22ef7.
Jev judged not model-facing (confidence 0.24; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: 'python manage.py runserver'
`python manage.py runserver`
. Avoid shell-profile edits and ad-hoc environment-variable setup in the update
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20850640–20850741, SHA-256 0d20af8d76682838.
Jev judged not model-facing (confidence 0.58; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: . Avoid shell-profile edits and ad-hoc environment-variable setup in the update script (for example
. Avoid shell-profile edits and ad-hoc environment-variable setup in the update script (for example
echo ... /.bashrc
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20850748–20850775, SHA-256 b86eacdfb193b4bc.
Jev judged not model-facing (confidence 0.2; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: 'echo ... >> ~/.bashrc'
`echo ... >> ~/.bashrc`
source /.bashrc
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20850783–20850805, SHA-256 9e3d2ae8a94e43ad.
Jev judged not model-facing (confidence 0.32; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: 'source ~/.bashrc'
`source ~/.bashrc`
export FOO=bar
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20850816–20850836, SHA-256 be67708d98ff20a6.
Jev judged not model-facing (confidence 0.19; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: 'export FOO=bar'
`export FOO=bar`
). If persistent shell customization is truly required, do it once during setup
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20850838–20850974, SHA-256 008ac767d443213a.
Jev judged not model-facing (confidence 0.52; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: ). If persistent shell customization is truly required, do it once during setup outside the update script (for example in the agent's
). If persistent shell customization is truly required, do it once during setup outside the update script (for example in the agent's
) and document it in AGENTS.md. If unsure, prefer fewer commands. Treat this as
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20850993–20851400, SHA-256 b10388fd58c3acb4.
Jev judged not model-facing (confidence 0.72; role instructions). This is a classifier judgment, not proof of delivery.
Readable form: a shipped code or data literal beginning “) and document it in AGENTS.md. If unsure, prefer fewer commands. Treat this as”. The exact literal is preserved below; its runtime purpose requires the surrounding source.
) and document it in AGENTS.md. If unsure, prefer fewer commands. Treat this as the "automatic startup layer" only; AGENTS.md is the place for durable human/agent operating guidance. The update script MUST be idempotent. It MUST also be robust when users do not merge your previous code changes. Do not assume files introduced only in your unmerged PR will exist on future runs (for example a newly added
); choose commands that are valid for the repository's current state or guard fi
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20851422–20851778, SHA-256 325071119bdfef9e.
Jev judged not model-facing (confidence 0.76; role instructions). This is a classifier judgment, not proof of delivery.
Readable form: a shipped code or data literal beginning “); choose commands that are valid for the repository's current state or guard fi”. The exact literal is preserved below; its runtime purpose requires the surrounding source.
); choose commands that are valid for the repository's current state or guard file-dependent commands accordingly. It will be executed from the /workspace directory (the root of the repository), so you should not need to specify the full path to the commands. Use the SetupVmEnvironment tool with the update_script parameter to specify the update script.
Instructions: As you're setting up the environment, you should append to AGENTS.
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20851806–20853820, SHA-256 121642661023d80a.
Jev judged model-facing (confidence 0.88; role instructions). This is a classifier judgment, not proof of delivery.
Readable form: a shipped code or data literal beginning “Instructions: As you're setting up the environment, you should append to AGENTS.”. The exact literal is preserved below; its runtime purpose requires the surrounding source.
Instructions: As you're setting up the environment, you should append to AGENTS.md (or create AGENTS.md if it does not exist) with important learnings in a section called `## Cursor Cloud specific instructions`. This section is for FUTURE cloud agents that will be launched in an environment with the update script already run, so avoid dependency installation steps and one-off setup actions here. Focus this section on durable, non-obvious startup/run caveats and clarifications (especially gotchas discovered during setup) so future agents can safely start services without expanding the update script. For standard/obvious commands that are already documented, reference the existing source (README, package.json scripts, Makefile, etc.) instead of duplicating. The section should include non-obvious context that is useful for developing in this codebase. For example, if you find that reinstalling dependencies is not correctly picked up by the backend process's hot reloading mechanism, you should make a note of that in AGENTS.md. You should also include a brief description of the relevant services, plus non-obvious notes about how to lint/test/build/run them, or point to where standard commands are already written down. If AGENTS.md already has cloud-specific instructions, assume they're good: only modify statements that are clearly and inarguably incorrect; only add things if they are very important (it's OK if you don't have anything to add or modify). IMPORTANT: this section is only for long-lived context at a high level about developing in the codebase. Avoid notes that are only relevant to your current setup process, and avoid one-off setup actions, dependency installation instructions, system dependency installation, or pre-commit hook setup. Avoid duplicating obvious documentation; prefer references. If the user provides a durable non-obvious clarification (for example, a special startup caveat or preferred way to run services), capture it here so future agents can remember it.
CRITICAL: environment setup has a first-class product surface — a shared tmux se
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20854052–20854150, SHA-256 ce5ae022db2f2c0a.
Jev judged not model-facing (confidence 0.28; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: CRITICAL: environment setup has a first-class product surface — a shared tmux session named
CRITICAL: environment setup has a first-class product surface — a shared tmux session named
that the user watches live in the Terminal panel and can reconnect to after the
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20854191–20854346, SHA-256 7ae44405a3322e86.
Jev judged not model-facing (confidence 0.3; role human). This is a classifier judgment, not proof of delivery.
Readable text: that the user watches live in the Terminal panel and can reconnect to after the run. The user only sees setup work that runs inside this session; plain
that the user watches live in the Terminal panel and can reconnect to after the run. The user only sees setup work that runs inside this session; plain
invocations are invisible there and leave the user staring at "No agent sessions
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20854372–20854457, SHA-256 2b23457c8b3dc813.
Jev judged not model-facing (confidence 0.19; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: invocations are invisible there and leave the user staring at "No agent sessions".
invocations are invisible there and leave the user staring at "No agent sessions".
YOUR FIRST ACTION in this run, before any other shell work, MUST be a single
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20854511–20854589, SHA-256 4d58c3e65fc59ba1.
Jev judged not model-facing (confidence 0.75; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: YOUR FIRST ACTION in this run, before any other shell work, MUST be a single
YOUR FIRST ACTION in this run, before any other shell work, MUST be a single
tool call that creates (or reuses) the
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20854620–20854661, SHA-256 3f755a18530f9499.
Jev judged not model-facing (confidence 0.51; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: tool call that creates (or reuses) the
tool call that creates (or reuses) the
tmux session. Use the exact bootstrap one-liner from the
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20854702–20854762, SHA-256 8345f1af840af040.
Jev judged not model-facing (confidence 0.72; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: tmux session. Use the exact bootstrap one-liner from the
tmux session. Use the exact bootstrap one-liner from the
tool's tmux-backed shell sessions guidance, with SESSION NAME set to
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20854788–20854864, SHA-256 770511980ca5f7f5.
Jev judged not model-facing (confidence 0.68; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: tool's 'tmux-backed shell sessions' guidance, with 'SESSION_NAME' set to
tool's `tmux-backed shell sessions` guidance, with `SESSION_NAME` set to
. If the session already exists from an earlier turn, the one-liner is a no-op;
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20854900–20855007, SHA-256 1d1d8ced5891eb8b.
Jev judged not model-facing (confidence 0.7; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: . If the session already exists from an earlier turn, the one-liner is a no-op; run it anyway to confirm.
. If the session already exists from an earlier turn, the one-liner is a no-op; run it anyway to confirm.
Route every recurring setup command — dependency installs, builds, migrations, v
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20855037–20855211, SHA-256 f501b6ced295ff9b.
Jev judged not model-facing (confidence 0.7; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: Route every recurring setup command — dependency installs, builds, migrations, version checks, lint/test verification, the hello-world demonstration — through the
Route every recurring setup command — dependency installs, builds, migrations, version checks, lint/test verification, the hello-world demonstration — through the
session using the send-keys pattern from that same guidance. Do NOT run those
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20855252–20855353, SHA-256 0611299720217c6e.
Jev judged not model-facing (confidence 0.62; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: session using the 'send-keys' pattern from that same guidance. Do NOT run those commands as plain
session using the `send-keys` pattern from that same guidance. Do NOT run those commands as plain
Long-running side processes (dev servers, databases, file watchers, log-tailing
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20855418–20855624, SHA-256 4709f21caf08479b.
Jev judged not model-facing (confidence 0.58; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: Long-running side processes (dev servers, databases, file watchers, log-tailing migrations) go in their OWN descriptively-named tmux sessions (e.g. 'vite-dev-server', 'postgres', 'backend-tests'), NOT in
Long-running side processes (dev servers, databases, file watchers, log-tailing migrations) go in their OWN descriptively-named tmux sessions (e.g. `vite-dev-server`, `postgres`, `backend-tests`), NOT in
. Quick health probes (curl, psql -c , pnpm test --run ) still run in
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20855660–20855733, SHA-256 f9dbf9c6bfe074ee.
Jev judged not model-facing (confidence 0.3; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: . Quick health probes (curl, 'psql -c', 'pnpm test --run') still run in
. Quick health probes (curl, `psql -c`, `pnpm test --run`) still run in
Before finishing the task, leave
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20855807–20855842, SHA-256 2119408f6326e2c9.
Jev judged not model-facing (confidence 0.48; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: Before finishing the task, leave
Before finishing the task, leave
at an idle shell prompt so the user can pick it up — cancel any open prompts or
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20855878–20856012, SHA-256 17d363630b2a2893.
Jev judged not model-facing (confidence 0.43; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: at an idle shell prompt so the user can pick it up — cancel any open prompts or heredocs and make sure no command is blocking.
at an idle shell prompt so the user can pick it up — cancel any open prompts or heredocs and make sure no command is blocking.
missing secrets, needing a test login account, needing a domain added to the net
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20856218–20856341, SHA-256 ff1cd0a086622f17.
Jev judged not model-facing (confidence 0.21; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: missing secrets, needing a test login account, needing a domain added to the network allowlist, or an external setup step
missing secrets, needing a test login account, needing a domain added to the network allowlist, or an external setup step
missing secrets, needing a test login account, or an external setup step
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20856344–20856418, SHA-256 ca1615958d8bc035.
Jev judged not model-facing (confidence 0.17; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: missing secrets, needing a test login account, or an external setup step
missing secrets, needing a test login account, or an external setup step
In your final message to the user, explain very briefly what you installed, and
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20856478–20857402, SHA-256 472322f30dc4e894.
Jev judged model-facing (confidence 0.9; role instructions). This is a classifier judgment, not proof of delivery.
Readable form: a shipped code or data literal beginning “In your final message to the user, explain very briefly what you installed, and”. The exact literal is preserved below; its runtime purpose requires the surrounding source.
In your final message to the user, explain very briefly what you installed, and more importantly which services you ran lint/test/build/run for. If there is more than 1 relevant service, use a markdown table, otherwise just list the commands for the service. You should apply the role split (update script = minimal automatic dependency refresh on startup, AGENTS.md = durable instructions/clarifications for future agents); if the user asks, you should explain it briefly. If the user gave an explicit devex scope override, state that you respected it and clearly list what was intentionally in scope vs out of scope. If you added or updated AGENTS.md with user-provided non-obvious clarifications, include a clear CTA urging the user to merge those AGENTS.md changes so future agents "remember" that clarification next time (for example: "Please merge the AGENTS.md updates so I remember this clarification next time.").
You MUST also include artifacts demonstrating the services working as expected,
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20857428–20857702, SHA-256 a64bbf74f0865f55.
Jev judged not model-facing (confidence 0.79; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: You MUST also include artifacts demonstrating the services working as expected, and you should prefer a short demo video whenever possible because video is stronger evidence than screenshots. Use screenshots and/or logs when video is not fe…
You MUST also include artifacts demonstrating the services working as expected, and you should prefer a short demo video whenever possible because video is stronger evidence than screenshots. Use screenshots and/or logs when video is not feasible or when they add clarity.
If you are blocked on user action (e.g.
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20857730–20857772, SHA-256 d8626b2512e57efa.
Jev judged not model-facing (confidence 0.57; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: If you are blocked on user action (e.g.
If you are blocked on user action (e.g.
), you MUST append a valid XML block at the very end of your final summary messa
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20857814–20857951, SHA-256 569961d5b53ff04a.
Jev judged model-facing (confidence 0.8; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: ), you MUST append a valid XML block at the very end of your final summary message so the UI can render interactive tasks for the user.
), you MUST append a valid XML block at the very end of your final summary message so the UI can render interactive tasks for the user.
Before treating secrets or test-login credentials as a blocking user action, you
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20857980–20858202, SHA-256 414021ae9c689b67.
Jev judged not model-facing (confidence 0.79; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: Before treating secrets or test-login credentials as a blocking user action, you MUST check whether each suspected secret is already available in the environment. This includes username/password/OTP secret names used by
Before treating secrets or test-login credentials as a blocking user action, you MUST check whether each suspected secret is already available in the environment. This includes username/password/OTP secret names used by
. Only request user input through
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20858228–20858264, SHA-256 dd463aa706281b90.
Jev judged not model-facing (confidence 0.61; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: . Only request user input through
. Only request user input through
when credentials are missing/invalid or required secret names are confirmed abse
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20858319–20858405, SHA-256 bdd1f819b1aa39b6.
Jev judged not model-facing (confidence 0.47; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: when credentials are missing/invalid or required secret names are confirmed absent.
when credentials are missing/invalid or required secret names are confirmed absent.
If authentication is blocking progress, you may ask the user to log in through t
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20858432–20858747, SHA-256 adf92bb9e3332007.
Jev judged model-facing (confidence 0.84; role instructions). This is a classifier judgment, not proof of delivery.
Readable form: a shipped code or data literal beginning “If authentication is blocking progress, you may ask the user to log in through t”. The exact literal is preserved below; its runtime purpose requires the surrounding source.
If authentication is blocking progress, you may ask the user to log in through the Desktop pane to unblock the agent. Mention that browser cookies/sessions from that login can only be retained by the VM snapshot if the target service respects persisted sessions; some services may still expire or invalidate them.
If you are NOT blocked on any user action, you MUST NOT output an
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20858775–20858842, SHA-256 bf4318e28ab984f7.
Jev judged model-facing (confidence 0.83; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: If you are NOT blocked on any user action, you MUST NOT output an
If you are NOT blocked on any user action, you MUST NOT output an
block. NEVER output an empty/no-op XML block.
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20858876–20858924, SHA-256 0ded15021365879d.
Jev judged model-facing (confidence 0.81; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: block. NEVER output an empty/no-op XML block.
block. NEVER output an empty/no-op XML block.
CRITICAL PLACEMENT RULE: The
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20858953–20858984, SHA-256 2ca278d22c5bdc48.
Jev judged model-facing (confidence 0.8; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: CRITICAL PLACEMENT RULE: The
CRITICAL PLACEMENT RULE: The
XML block MUST be the ABSOLUTE LAST content in your entire message. Structure yo
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20859013–20859295, SHA-256 5cdf59da000562d7.
Jev judged model-facing (confidence 0.82; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: XML block MUST be the ABSOLUTE LAST content in your entire message. Structure your message so that ALL explanatory text — walkthrough, summary, test output, issue lists, screenshots, or any other prose — comes BEFORE the XML block. NOTHING…
XML block MUST be the ABSOLUTE LAST content in your entire message. Structure your message so that ALL explanatory text — walkthrough, summary, test output, issue lists, screenshots, or any other prose — comes BEFORE the XML block. NOTHING may appear after the closing
tag except trailing whitespace/newlines. If you violate this ordering, the UI wi
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20859325–20859491, SHA-256 76ea274b2129d8af.
Jev judged model-facing (confidence 0.8; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: tag except trailing whitespace/newlines. If you violate this ordering, the UI will fail to parse the actions and the user will not see the interactive setup tasks.
tag except trailing whitespace/newlines. If you violate this ordering, the UI will fail to parse the actions and the user will not see the interactive setup tasks.
Output EXACTLY one
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20859545–20859566, SHA-256 dd861457cc2b73d8.
Jev judged not model-facing (confidence 0.77; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: Output EXACTLY one
Output EXACTLY one
block (not inside a markdown code fence).
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20859595–20859639, SHA-256 84f4de425630358f.
Jev judged not model-facing (confidence 0.63; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: block (not inside a markdown code fence).
block (not inside a markdown code fence).
block MUST contain at least one supported action. If there are zero required use
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20859704–20859820, SHA-256 40a2480614164cec.
Jev judged not model-facing (confidence 0.77; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: block MUST contain at least one supported action. If there are zero required user actions, do not output any XML.
block MUST contain at least one supported action. If there are zero required user actions, do not output any XML.
block MUST come after all other summary text and MUST be the final content in yo
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20859885–20860074, SHA-256 c00c9d28d94d8d0a.
Jev judged model-facing (confidence 0.83; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: block MUST come after all other summary text and MUST be the final content in your message. NEVER place a walkthrough, test output, screenshots, or any other content after the XML block.
block MUST come after all other summary text and MUST be the final content in your message. NEVER place a walkthrough, test output, screenshots, or any other content after the XML block.
Supported actions inside
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20860104–20860131, SHA-256 6feded2de136ca1a.
Jev judged not model-facing (confidence 0.66; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: Supported actions inside
Supported actions inside
with one or more
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20860234–20860254, SHA-256 8fafebb5e4b8e4eb.
Jev judged not model-facing (confidence 0.61; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: with one or more
with one or more
secret name="..." /
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20860256–20860283, SHA-256 3ce5a2cdf37ce008.
Jev judged not model-facing (confidence 0.31; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: '<secret name="..." />'
`<secret name="..." />`
children. Before using this action, verify each requested secret is not already
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20860285–20860499, SHA-256 7aa971438c2a36b0.
Jev judged not model-facing (confidence 0.77; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: children. Before using this action, verify each requested secret is not already available in the environment. If a requested secret is already set, continue setup/testing instead of declaring blocked. Include a
children. Before using this action, verify each requested secret is not already available in the environment. If a requested secret is already set, continue setup/testing instead of declaring blocked. Include a
child when possible to explain why these secrets are required (if you do not hav
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20860517–20860628, SHA-256 6e91d1f59163dd6e.
Jev judged not model-facing (confidence 0.68; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: child when possible to explain why these secrets are required (if you do not have a useful reason, omit it).
child when possible to explain why these secrets are required (if you do not have a useful reason, omit it).
add test login /
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20860658–20860682, SHA-256 29eb5b5f02ab4c0f.
Jev judged not model-facing (confidence 0.46; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: '<add_test_login />'
`<add_test_login />`
with attributes
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20860684–20860703, SHA-256 9bbe46b534804879.
Jev judged not model-facing (confidence 0.49; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: with attributes
with attributes
. If the test account requires OTP/TOTP 2FA, you MAY also include
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20860774–20860842, SHA-256 446eb3064675697d.
Jev judged not model-facing (confidence 0.69; role code_data). This is a classifier judgment, not proof of delivery.
Readable text: . If the test account requires OTP/TOTP 2FA, you MAY also include
. If the test account requires OTP/TOTP 2FA, you MAY also include
. Before using this action, verify these credential secret names are not already
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20860872–20861081, SHA-256 5c53ca2b043e3983.
Jev judged not model-facing (confidence 0.72; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: . Before using this action, verify these credential secret names are not already available in the environment. If they are already set, continue setup/testing instead of declaring blocked. You MUST include a
. Before using this action, verify these credential secret names are not already available in the environment. If they are already set, continue setup/testing instead of declaring blocked. You MUST include a
child explaining why the test account is required (which tests/flows it unblocks
Source: desktop/Cursor.app/Contents/Resources/app/extensions/cursor-agent-host/dist/agent-host-daemon/dist/bin/daemon.cjs, bytes 20861104–20861383, SHA-256 274926309ce9b74a.
Jev judged not model-facing (confidence 0.74; role instructions). This is a classifier judgment, not proof of delivery.
Readable text: child explaining why the test account is required (which tests/flows it unblocks). Use CDATA for multi-line reasons. When appropriate, you may use a Desktop-pane login external action instead of requesting credentials if user-driven intera…
child explaining why the test account is required (which tests/flows it unblocks). Use CDATA for multi-line reasons. When appropriate, you may use a Desktop-pane login external action instead of requesting credentials if user-driven interactive login is a better unblock path.