* test(#2801): failing-first suite for the hostBehaviors.reviewerCli alias removal Inverts the Phase 5a rows that assert the derived legacy alias still contributes a reviewer slug, and adds the removal-warning coverage the alias's exit needs (ADR-2782 D9). RED against unmodified production code, by design: the six shipped manifests still declare the key and collectReviewerWarnings emits nothing for hostBehaviors. Refs #2801 * chore(#2801): remove the hostBehaviors.reviewerCli deprecated alias ADR-2782 D9, Phase 7 — the final phase of epic #2782. The derived legacy alias survived one release (Phase 5a shipped in 1.9.0; 1.9.1 and 1.10.0 have since gone out), so it goes. A declared reviewer body is now the only route onto the reviewer roster. - deriveReviewerSlugs no longer reads runtime.hostBehaviors.reviewerCli - the key is stripped from the six manifests that carried it; each already declares a reviewer body whose slug equals its capability id, so the derived roster is unchanged at the same twelve slugs - collectReviewerWarnings emits a presence-based, non-fatal removal notice for any manifest still declaring the key, reaching both the build-time registry generation and the third-party overlay load path. The check runs before the reviewer-body early-return, because the manifest it exists for is the alias-only one that has no body. - hostBehaviors stays an open, unvalidated bag for its other 59 keys; this adds one keyed removal notice, not general validation Refs #2801 * refactor(#2801): give the reviewer-warning channel a typed IR Review finding: the new tests asserted with String#includes() on the warning prose, which CONTRIBUTING.md's 'Prohibited: Raw Text Matching on Test Outputs' bans in favor of a typed intermediate representation. Adds the IR beside the renderer rather than replacing it, which is the shape that section prescribes and bin/verify-reapply-patches.cjs already models: - REVIEWER_WARNING, a frozen code enum - REMOVED_REVIEWER_CLI_FIELD, so the emitting site and its test share one symbol instead of duplicating a literal - collectReviewerWarningRecords(cap), returning typed records collectReviewerWarnings(cap) keeps its exact string[] contract as a thin map over the records, so both production consumers are untouched. Every section-K row now asserts on record.code/field/capId and none on the rendered message. Locks the code surface, asserts the renderer stays one-to-one with the records, and migrates the pre-existing Phase 2 test on the same channel off prose matching. Refs #2801 * test(#2801): invert the section F alias fall-through regression row Caught by the remote runner: 2 unique failures on both Node lanes out of 31,692. tests/reviewer-lane-declarations.test.cjs section F — Phase 5a's isolated-security-review regressions — asserted that a blank reviewer.slug falls through to the hostBehaviors.reviewerCli alias rather than dropping the lane. That is the direct inverse of this phase's contract. The original rationale held only while the alias existed. With it gone there is nothing to fall through to: a blank body is not a declaration, and a declaration is the only route onto the roster. Inverted rather than deleted — the row carries the adversarial-review provenance for the slug trim, and removing a security regression guard to make a change pass is backwards. The duplicate row added earlier in section C is dropped instead; section F is its canonical home. Also corrects two count strings Phase 5b left at eleven while asserting twelve, which would misreport on failure. Refs #2801 * docs(#2801): give the removed reviewerCli flag a migration path The Reference edit alone satisfied CI — a file under docs/ moved, so lint-docs-required.cjs was green — while the task-oriented quadrant said nothing about the removal. A maintainer whose lane had just gone silent would have found the field documented as removed and no page telling them what to do about it. Adds a migration section to the how-to: the symptom, the verbatim warning they will see, the before/after manifest, and the note to keep the reviewer slug equal to the capability id so existing review.default_reviewers entries and --<slug> flags survive. Refs #2801 * chore(#2801): backfill changeset pr number to 3272 * feat(#2801): close the runtime.hostBehaviors vocabulary ADR-1016 closes twelve descriptor axes and rejects an open escape hatch in the descriptor. It never mentioned runtime.hostBehaviors, and that silence was read as permission: 59 keys across 18 manifests, 39 of them set by a single capability, validated by nothing. The reference docs went further and attributed the open seam to ADR-1016, which does not mention the field at all. KNOWN_HOST_BEHAVIORS enumerates the vocabulary. An undeclared key yields a non-fatal UNKNOWN_HOST_BEHAVIOR record on the same D4.3 channel as the alias removal notice, reaching both build-time generation and overlay install. Warning, never error, for the reason this phase exists: an error would hard-break an out-of-tree descriptor carrying a bespoke key with no deprecation window, which is what reviewerCli was given a release to avoid. Escalation is a separate decision. reviewerCli is excluded from the unknown-key sweep so it keeps its own notice with the migration pointer rather than drawing two records. A parity test binds the vocabulary to the shipped manifests in both directions, and a second asserts no shipped capability draws a notice, so the closure is provably inert in-tree. Records the decision and the miscitation as an ADR-1016 amendment. Refs #2801 * fix(#2801): bound and sanitize the unknown-key diagnostics Two findings from an isolated adversarial review of the closure commit, both proven by execution rather than asserted. MAJOR, introduced by the closure: the new Object.keys(hostBehaviors) sweep had no ceiling. An installed third-party manifest is bounded only by MANIFEST_MAX_BYTES, and an 8.69MB manifest with 800,000 keys produced 800,000 records and ~139MB of message text, retained for the registry's lifetime in OverlayMeta.diagnostics. Now capped at ten records plus a summary carrying omittedCount, mirroring capability-loader's existing slice(0,3) idiom. The same manifest now yields 11 records and 1748 chars. MINOR, newly reachable: manifest-supplied key names were interpolated raw. Unlike cap.id, which validateCapability gates on KEBAB_RE before these diagnostics run, hostBehaviors keys have no grammar check anywhere, so ANSI escapes and CRLF reached stderr and OverlayMeta.warnings intact. New describeKey replaces C0/C1 controls and clips at 80 chars. The file already had describeValue for this and applied it only to values. Both fixes land on the pre-existing reviewer.* sweep too — it carried the identical pair, and fixing only the new copy would leave the same defect one screen from its own fix. Refs #2801 --------- Co-authored-by: sim <sim@local>
149 lines
3.7 KiB
JSON
149 lines
3.7 KiB
JSON
{
|
|
"id": "cursor",
|
|
"role": "runtime",
|
|
"version": "1.10.0",
|
|
"title": "Cursor",
|
|
"description": "Cursor IDE — skills-only workflow surface; hooks.json surface; Claude hook event dialect; recursive skill loader (flat nesting); tier-2 support.",
|
|
"tier": "core",
|
|
"requires": [],
|
|
"engines": {
|
|
"gsd": ">=1.6.0"
|
|
},
|
|
"runtime": {
|
|
"configHome": {
|
|
"kind": "dot-home",
|
|
"name": ".cursor",
|
|
"env": [
|
|
"CURSOR_CONFIG_DIR"
|
|
]
|
|
},
|
|
"localConfigDir": ".cursor",
|
|
"configFormat": "none",
|
|
"artifactLayout": {
|
|
"global": [
|
|
{
|
|
"kind": "skills",
|
|
"destSubpath": "skills",
|
|
"prefix": "gsd-",
|
|
"nesting": "flat",
|
|
"recursive": true,
|
|
"converter": "convertClaudeCommandToCursorSkill"
|
|
},
|
|
{
|
|
"kind": "agents",
|
|
"destSubpath": "agents",
|
|
"prefix": "gsd-",
|
|
"nesting": "flat",
|
|
"recursive": false,
|
|
"converter": "convertClaudeAgentToCursorAgent"
|
|
}
|
|
],
|
|
"local": [
|
|
{
|
|
"kind": "skills",
|
|
"destSubpath": "skills",
|
|
"prefix": "gsd-",
|
|
"nesting": "flat",
|
|
"recursive": true,
|
|
"converter": "convertClaudeCommandToCursorSkill"
|
|
},
|
|
{
|
|
"kind": "agents",
|
|
"destSubpath": "agents",
|
|
"prefix": "gsd-",
|
|
"nesting": "flat",
|
|
"recursive": false,
|
|
"converter": "convertClaudeAgentToCursorAgent"
|
|
}
|
|
]
|
|
},
|
|
"commandStyle": "slash-hyphen",
|
|
"hooksSurface": "cursor-hooks-json",
|
|
"hookEvents": "claude",
|
|
"sandboxTier": "none",
|
|
"supportTier": 2,
|
|
"installSurface": "cursor-hooks-json",
|
|
"writesSharedSettings": false,
|
|
"permissionWriter": null,
|
|
"extendedHookEvents": [],
|
|
"hostIntegration": {
|
|
"embeddingMode": "imperative",
|
|
"commandSurface": "slash-file",
|
|
"dispatch": {
|
|
"namedDispatch": true,
|
|
"nested": true,
|
|
"maxDepth": 2,
|
|
"background": true,
|
|
"subagentToolkit": "full",
|
|
"backgroundDispatch": true,
|
|
"isolation": "harness-worktree"
|
|
},
|
|
"modelMode": "passive",
|
|
"hookBus": "host",
|
|
"stateIO": "filesystem",
|
|
"transport": "mcp",
|
|
"runtime": "node",
|
|
"effortSurface": "undocumented"
|
|
},
|
|
"harnessIsolationFlag": "--worktree",
|
|
"hostBehaviors": {
|
|
"reapplyCommand": "gsd-update --reapply (mention the skill name)",
|
|
"frontmatterDialect": "cursor",
|
|
"hooksJsonSurface": true,
|
|
"skipSharedHooksInstall": true,
|
|
"retiredArtifacts": [
|
|
{
|
|
"destSubpath": "commands",
|
|
"prefix": "gsd-",
|
|
"suffix": ".md"
|
|
}
|
|
],
|
|
"skipUpdateBannerCommand": true,
|
|
"skipSettingsUi": true,
|
|
"managedHookEvents": [
|
|
"sessionStart",
|
|
"postToolUse",
|
|
"preToolUse",
|
|
"stop",
|
|
"subagentStart",
|
|
"subagentStop"
|
|
]
|
|
}
|
|
},
|
|
"reviewer": {
|
|
"slug": "cursor",
|
|
"flags": [
|
|
"--cursor"
|
|
],
|
|
"transport": "spawn",
|
|
"probe": {
|
|
"kind": "command-exists",
|
|
"binary": "cursor-agent"
|
|
},
|
|
"invoke": {
|
|
"binary": "cursor-agent",
|
|
"args": [
|
|
"-p",
|
|
"--mode",
|
|
"ask",
|
|
"--trust",
|
|
"--output-format",
|
|
"text",
|
|
"{{prompt}}"
|
|
],
|
|
"promptChannel": "argv-file-ref",
|
|
"outputChannel": "stdout",
|
|
"modelArg": null,
|
|
"effortChannel": "none"
|
|
},
|
|
"timeoutFloorMs": 900000,
|
|
"emptyOutput": "stub-with-stderr",
|
|
"reviewsSection": "Cursor",
|
|
"evidenceClass": "source-grounded",
|
|
"requiresBinaries": [],
|
|
"promptBudgetKey": null,
|
|
"modelConfigKey": null,
|
|
"handler": null
|
|
}
|
|
}
|