You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A discussion dedicated to the Agent Relay Cursor module. Share your thoughts, questions, and feedback here.
Module Scorecard
Presentation & Onboarding
Agent Integration
Credential Hygiene
Restricted-Environment Readiness
Engineering Quality
Overall
6 / 17
5 / 25
20 / 20
12 / 20
10 / 10
58 / 100
Drilldown
Presentation & Onboarding — 6 / 17
Criterion
Max
Score
Notes
Configuration-mode examples
12
6
The README shows one basic example (install_cli = true) and the Requirements section describes computer_use, share_desktop, and cli_binary options, but there are no distinct tf configuration blocks demonstrating each major mode (e.g., a pre-baked-image example with install_cli = false, a computer-use example, a desktop-share example). Parameters are documented in prose and variable descriptions but not as separate mode examples with sensible defaults.
Visual preview
5
0
No image, GIF, or video is embedded in the README. The frontmatter icon field points to a registry listing icon, which does not count.
Agent Integration — 5 / 25
Criterion
Max
Score
Notes
AI governance
10
0
No mention of Coder AI Gateway or Agent Firewall anywhere in the README or source. The credential flow is entirely through Agent Relay's token exchange; no AI Gateway routing or Agent Firewall policy enforcement is documented.
Dashboard entry point
5
5
Two coder_app resources are declared: cursor_web (external, https://cursor.com/agents/<id>) and cursor_desktop (external, cursor:// deeplink). Both are conditionally created when agent_relay_session_id is set. Documented in the README under "When Agent Relay stamps agent_relay_session_id, the module adds two external apps."
Session continuity
5
0
No documentation of resuming an existing Cursor session across reconnects or relaunches. The worker is a single process; if it exits, the session is lost and Cursor re-queues. No mention of tmux, screen, boo, or native session-resume support.
Managed configuration
5
0
No documentation of managed MCP servers, settings, policies, or workdir configuration. The module only runs the Cursor CLI worker with pool/credential arguments.
Credential Hygiene — 20 / 20
Criterion
Max
Score
Notes
Secrets marked sensitive
16
16
agent_relay_credential uses mask_input = true and ephemeral = true in its coder_parameter styling. The README example shows no inline secrets—only agent_id = coder_agent.main.id (a resource reference). The token is passed via coder_env from the parameter, never hardcoded in scripts.
Non-hardcoded auth path
4
4
The README documents that "the pool's service-account API key never leaves Agent Relay" and that the relay mints a per-user sub-token stamped as the ephemeral agent_relay_credential parameter. No user pastes a raw key into the template.
Restricted-Environment Readiness — 12 / 20
Criterion
Max
Score
Notes
Mirrorable artifact source
5
0
The install URL https://cursor.com/install is hardcoded in install.sh.tftpl. No module input variable overrides this download URL. cli_binary changes the binary name/path, not the source URL; install_cli toggles the download on/off but does not redirect it. No variable like install_url or download_endpoint exists.
Bring-your-own binary
10
10
install_cli = false (documented in README: "Bake the CLI into the image and set this to false for faster workspaces") disables the download entirely. The install script checks command -v ${cli_binary} and skips if present. The start script adds ~/.local/bin to PATH unconditionally so a pre-baked CLI is found. Fully documented.
Egress transparency
3
0
No dedicated README section enumerates external endpoints contacted at install and runtime. cursor.com/install appears in the install script, cursor.com/agents/<id> in the app URL, and the worker connects to Cursor's backend, but none of this is collected into a network/air-gapped section with notes for restricted environments.
Runs without sudo
2
2
All scripts (install.sh.tftpl, start.sh.tftpl, status.sh.tftpl) use only user-space commands: curl, mkdir -p, cat, chmod +x, setsid nohup, grep. No sudo invocation anywhere. Install targets ~/.local/bin.
Engineering Quality — 10 / 10
Criterion
Max
Score
Notes
Input quality
6
6
All seven module variables have clear descriptions and sensible defaults. cli_binary has a regex validation rejecting shell metacharacters. share_desktop has a cross-variable validation requiring computer_use. serving_log_pattern has a non-empty validation. The relay-stamped coder_parameter resources also carry descriptions, defaults, and styling.
Test coverage
4
4
main.tftest.hcl (12 test runs) covers the parameter contract, ephemeral flags, styling, script rendering, credential-kind branching, and validation failures. main.test.ts (15+ test cases) runs actual containers with stub binaries, exercising the full worker lifecycle (idle, working, serving, done, failed, orphaned), shell-injection resistance, credential path selection, file layout, and restart idempotency. Clear separation: HCL tests for Terraform logic, TS tests for end-to-end script behavior.
Overall — 58 / 100
Raw 53 / 92 → round(53 / 92 × 100) = 58
Scored against SCORECARD.md on 2026-09-30 with solstice-1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the Agent Relay Cursor module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Presentation & Onboarding — 6 / 17
install_cli = true) and the Requirements section describescomputer_use,share_desktop, andcli_binaryoptions, but there are no distinct tf configuration blocks demonstrating each major mode (e.g., a pre-baked-image example withinstall_cli = false, a computer-use example, a desktop-share example). Parameters are documented in prose and variable descriptions but not as separate mode examples with sensible defaults.iconfield points to a registry listing icon, which does not count.Agent Integration — 5 / 25
coder_appresources are declared:cursor_web(external,https://cursor.com/agents/<id>) andcursor_desktop(external,cursor://deeplink). Both are conditionally created whenagent_relay_session_idis set. Documented in the README under "When Agent Relay stampsagent_relay_session_id, the module adds two external apps."Credential Hygiene — 20 / 20
agent_relay_credentialusesmask_input = trueandephemeral = truein itscoder_parameterstyling. The README example shows no inline secrets—onlyagent_id = coder_agent.main.id(a resource reference). The token is passed viacoder_envfrom the parameter, never hardcoded in scripts.agent_relay_credentialparameter. No user pastes a raw key into the template.Restricted-Environment Readiness — 12 / 20
https://cursor.com/installis hardcoded ininstall.sh.tftpl. No module input variable overrides this download URL.cli_binarychanges the binary name/path, not the source URL;install_clitoggles the download on/off but does not redirect it. No variable likeinstall_urlordownload_endpointexists.install_cli = false(documented in README: "Bake the CLI into the image and set this to false for faster workspaces") disables the download entirely. The install script checkscommand -v ${cli_binary}and skips if present. The start script adds~/.local/binto PATH unconditionally so a pre-baked CLI is found. Fully documented.cursor.com/installappears in the install script,cursor.com/agents/<id>in the app URL, and the worker connects to Cursor's backend, but none of this is collected into a network/air-gapped section with notes for restricted environments.install.sh.tftpl,start.sh.tftpl,status.sh.tftpl) use only user-space commands:curl,mkdir -p,cat,chmod +x,setsid nohup,grep. Nosudoinvocation anywhere. Install targets~/.local/bin.Engineering Quality — 10 / 10
cli_binaryhas a regex validation rejecting shell metacharacters.share_desktophas a cross-variable validation requiringcomputer_use.serving_log_patternhas a non-empty validation. The relay-stampedcoder_parameterresources also carry descriptions, defaults, and styling.main.tftest.hcl(12 test runs) covers the parameter contract, ephemeral flags, styling, script rendering, credential-kind branching, and validation failures.main.test.ts(15+ test cases) runs actual containers with stub binaries, exercising the full worker lifecycle (idle, working, serving, done, failed, orphaned), shell-injection resistance, credential path selection, file layout, and restart idempotency. Clear separation: HCL tests for Terraform logic, TS tests for end-to-end script behavior.Overall — 58 / 100
Raw 53 / 92 → round(53 / 92 × 100) = 58
Scored against SCORECARD.md on 2026-09-30 with
solstice-1.All reactions