amElnagdy/delegate-skills/skills/cursor-delegate/SKILL.md
cursor-delegate
Delegate a coding task to the Cursor Agent CLI (`cursor-agent`) as a background implementer, then review its diff and land it yourself. Use this whenever the user wants to hand implementation work to Cursor — phrasings like "have Cursor implement X", "delegate this to Cursor", "run it through Cursor Agent", or "use Cursor to implement/fix/refactor" — or wants to run a queue of coding tasks through Cursor while staying the reviewer. DO NOT USE for tasks small enough to do inline, or when the user
- Source repository stars
- 1,298
- Declared platforms
- 1
- Static risk flags
- 1
- Last source update
- 2026-08-21
- Source checked
- 2026-08-25
Decision brief
What it does: where it fits
You are the orchestrator. Hand a bounded coding task to a separate implementer — the Cursor Agent CLI — then review what it produced and land it yourself. You write the brief and own the judgment; Cursor does the typing in its own session; you verify and commit.
Not for
- The task is small enough to do inline; delegation overhead is not worth it.
- The cursor-agent CLI is not installed or authenticated (run cursor-agent login).
Compatibility matrix
Platform support, with evidence labels
| Platform | Status | Evidence | What to check |
|---|---|---|---|
| Codex | Not declared | No explicit evidence | Portability before use |
| Claude Code | Not declared | No explicit evidence | Portability before use |
| Cursor | Declared | Source record | Install path and trigger |
| Gemini CLI | Not declared | No explicit evidence | Portability before use |
Installation
Inspect first. Install second.
The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.
npx skills add https://github.com/amElnagdy/delegate-skills --skill "skills/cursor-delegate"Inspect the Agent Skill "cursor-delegate" from https://github.com/amElnagdy/delegate-skills/blob/2ecfa84d140cb34521471ce6cf5d358264865cbc/skills/cursor-delegate/SKILL.md at commit 2ecfa84d140cb34521471ce6cf5d358264865cbc. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.
Workflow
What the source asks the agent to do
- 01
read-only (plan mode — review/diagnosis, no edits): add --read-only
Review the “read-only (plan mode — review/diagnosis, no edits): add --read-only” section in the pinned source before continuing.
Review and apply the “read-only (plan mode — review/diagnosis, no edits): add --read-only” source section. - 02
hard time limit (watchdog): add --timeout 2h (the 30m default suits short runs; implementation briefs routinely need 1-2h)
Review the “hard time limit (watchdog): add --timeout 2h (the 30m default suits short runs; implementation briefs routinely need 1-2h)” section in the pinned source before continuing.
Review and apply the “hard time limit (watchdog): add --timeout 2h (the 30m default suits short runs; implementation briefs routinely need 1-2h)” source section. - 03
4. Review — do not trust the self-report
Treat Cursor's final message and gate claims as claims:
Re-run the project's gates yourself.Read the diff against the brief, starting with touchedFiles.Run relevant guard skills if installed. - 04
When NOT to use this
The task is small enough to do inline; delegation overhead is not worth it.
The task is small enough to do inline; delegation overhead is not worth it.The cursor-agent CLI is not installed or authenticated (run cursor-agent login).You want to write the code yourself, or you only need Cursor's opinion on code you wrote (a - 05
Prerequisites (check once)
1. cursor-agent --version succeeds. If not, follow the installer for your platform at cursor.com/cli, inspect what it will run, and authenticate with cursor-agent login. 2. cursor-agent status shows you logged in. 3. You are in (or will point --cd at) the target git repository.…
cursor-agent --version succeeds. If not, follow the installer for your platform atcursor-agent status shows you logged in.You are in (or will point --cd at) the target git repository. The relay passes --trust, so
Permission review
Static risk signals and limitations
Runs scripts
The documentation asks the agent to run terminal commands or scripts.
node "<skill-dir>/scripts/relay.mjs" --brief brief.txt --cd /path/to/repoEvidence record
Why each signal appears
| Signal | Value | Evidence type | Meaning |
|---|---|---|---|
| Quality score | 90/100 | Computed | Documentation, specificity, maintenance, and trust rules |
| Repository stars | 1,298 | Source | Repository attention, not individual Skill quality |
| Compatibility | 1 platforms | Source | Declared in the catalog source record |
| Usage guide | automated source guide | Editorial | Generated or reviewed according to the visible evidence level |
Pinned source
Provenance and original SKILL.md
- Repository
- amElnagdy/delegate-skills
- Skill path
- skills/cursor-delegate/SKILL.md
- Commit
- 2ecfa84d140cb34521471ce6cf5d358264865cbc
- License
- MIT
- Collected
- 2026-08-25
- Default branch
- master
View the original SKILL.md
Cursor Delegate
You are the orchestrator. Hand a bounded coding task to a separate implementer — the Cursor Agent CLI — then review what it produced and land it yourself. You write the brief and own the judgment; Cursor does the typing in its own session; you verify and commit.
The loop needs only a shell command and file access, so any comparable orchestrator can drive it.
When NOT to use this
- The task is small enough to do inline; delegation overhead is not worth it.
- The
cursor-agentCLI is not installed or authenticated (runcursor-agent login). - You want to write the code yourself, or you only need Cursor's opinion on code you wrote (a
--read-onlydispatch covers that — see below — but a plain review may not need delegation at all).
Prerequisites (check once)
cursor-agent --versionsucceeds. If not, follow the installer for your platform at cursor.com/cli, inspect what it will run, and authenticate withcursor-agent login.cursor-agent statusshows you logged in.- You are in (or will point
--cdat) the target git repository. The relay passes--trust, so point it only at repositories you trust.
Choose the model
Omitting --model uses your Cursor default (usually auto — Cursor picks). To pin one, pass
--model <name> with a name from the account's live cursor-agent models output — select from that
list rather than inventing a name. Parameterized forms like <name>[context=1m,effort=high] are
forwarded as-is. The model that actually served the run is recorded as resolvedModel in
result.json.
The loop
Run these five steps per task. Steps 1, 4, and 5 require judgment; 2 and 3 are mechanical.
1. Write the brief
Cursor sees only the text you send plus what it can inspect in the workspace — no chat history or shared context. Include the goal, current state, what to change, what to leave untouched, the project's actual gates, and a report contract. Tell Cursor not to commit. Keep one task per brief. See references/writing-the-brief.md.
2. Dispatch
Use the bundled helper. It wraps cursor-agent -p, feeds the brief on stdin, captures the
structured event stream, and writes result.json. (<skill-dir> is the installed folder containing
this SKILL.md.)
node "<skill-dir>/scripts/relay.mjs" --brief brief.txt --cd /path/to/repo
# read-only (plan mode — review/diagnosis, no edits): add --read-only
# write-capable without automatic command approval: add --no-force
# explicitly override Cursor's sandbox for this run: add --sandbox enabled|disabled
# pin a model from `cursor-agent models`: add --model <name>
# resume the most recent session: add --resume-last (delta brief only)
# resume a specific session: add --session <id> (delta brief only)
# hard time limit (watchdog): add --timeout 2h (the 30m default suits short runs; implementation briefs routinely need 1-2h)
# see all options: node .../relay.mjs --help
The child process's cwd pins the workspace. On Cursor 2026.07.23 or newer, use repeatable
--add-dir flags only for extra workspace directories. The relay writes artifacts under the system
temp dir by default and never commits. See
references/dispatch-and-poll.md.
3. Wait for completion
The helper blocks until Cursor finishes. Run it with the orchestrator's background-command facility,
or background it in the shell and poll for result.json. A pre-run usage error exits 2 and writes no
result; a missing cursor-agent exits 127 and writes status: "cursor_agent_unavailable".
Trust process state and the working tree over a progress display. Completion means the process exited
and result.json exists. Cursor's full report is the finalMessage field in result.json (also
printed in full on stdout between the report markers).
Windows + hooks caveat: if the user has Cursor hooks configured (~/.cursor/hooks.json, or
Claude Code PreToolUse hooks, which cursor-agent imports), dispatching from a Git Bash (MSYS)
console makes cursor-agent feed PowerShell-syntax hook wrappers to bash, so every command Cursor
tries to run is blocked — edits still land, gates do not run. Dispatch from a PowerShell or cmd
console instead. Details: references/dispatch-and-poll.md.
4. Review — do not trust the self-report
Treat Cursor's final message and gate claims as claims:
- Re-run the project's gates yourself.
- Read the diff against the brief, starting with
touchedFiles. - Run relevant guard skills if installed.
- Round-trip migrations and grep for dangling references after removals or renames.
See references/review-and-land.md.
5. Land it
The implementer edits the working tree; the orchestrator commits. Commit only after the gates
pass and the diff holds. If rework is needed, send a delta brief with --resume-last or
--session <id>, then review again.
Autonomy and permissions
A fresh run defaults to write-capable with --force: Cursor runs commands without approval
unless your Cursor config explicitly denies them, so ordinary gates (tests, linters, builds) run
headlessly. --no-force keeps the run write-capable but withholds automatic command approval;
commands that require approval are refused because a headless run cannot prompt. --read-only
switches to Cursor's plan mode (read-only analysis, no edits, no --force). The relay always
passes --trust to keep headless runs from stalling on the workspace-trust prompt, which is why
--cd must only ever point at repositories you trust. Pass --sandbox enabled or --sandbox disabled only when you need to override Cursor's sandbox for that dispatch. The requested value is
recorded as sandbox in result.json; it does not claim what Cursor actually applied. The permission
mode Cursor reports is recorded as permissionMode; inspect touchedFiles and the diff after every
run.
Read-only second opinions
--read-only doubles as a clean way to get an adversarial second opinion with no write risk:
dispatch a brief that lists the agreed points, then each contested point with both positions, and ask
Cursor to defend or concede each — deliverable in its final message, touching no files.
Authorization model
Delegation is something the human opts into. Once they have ("run this queue", "proceed"), committing verified, gate-passing work is the agreed contract. Two limits remain: surface, don't absorb (report Cursor's design decisions, defensible-but-unasked turns, and non-blocking nitpicks) and stop for scope changes (if correct completion needs going beyond the brief, ask instead of expanding the mandate). See references/review-and-land.md.
References
- references/writing-the-brief.md — structure, report contract, real gates, and delta briefs.
- references/dispatch-and-poll.md — flags, artifacts,
result.json, polling, and failure recovery. - references/review-and-land.md — review checklist, commit boundary, and rework through Cursor sessions.
- references/multi-task-queues.md — sequential queues, constraint carry-forward, progress tracking, and the final coherence pass.
Frequently asked questions
What to verify before installation and use
What does the cursor-delegate source document cover?
You are the orchestrator. Hand a bounded coding task to a separate implementer — the Cursor Agent CLI — then review what it produced and land it yourself. You write the brief and own the judgment; Cursor does the typing in its own session; you verify and commit.
How do I install cursor-delegate?
The source record exposes this install command: npx skills add https://github.com/amElnagdy/delegate-skills --skill "skills/cursor-delegate". Inspect the command and pinned source before running it.
Which Agent platforms does the source record declare?
The pinned source record declares support for: cursor.
Which permission-related actions were detected?
Static rules flagged exec-script in the source; the page lists the matching lines and excerpts.
Alternatives
Compare before choosing
brucesongs/kali-claw
insecure-design
Insecure Design (OWASP A06:2025) focuses on security flaws in system architecture and design phases, rather than code implementation-level bugs.
SerendipityOneInc/ZooData-Skills
zoodata
API endpoint reference for the ZooData data platform: the 12 commerce endpoints plus 10 keyword-intelligence endpoints (categories, markets, products, competitors, realtime ASIN, AI review analysis, raw reviews, price band, brand, history, and the keyword detail/trend/extends/search/ market-profile/product-traffic/competitor-keywords/traffic-profile/ traffic-timeline family) — their inputs/outputs, parameter quirks, Quick Start (auth, base URL), how credits are tracked (meta.creditsConsumed), an
brucesongs/kali-claw
binary-reverse
Binary reverse engineering covers the complete chain from static analysis, dynamic debugging, to vulnerability discovery, exploit development, and malware analysis.
PramodDutta/qaskills
Pairwise Test Generator
Generate optimized test combinations using pairwise (all-pairs) testing algorithms to achieve maximum coverage with minimum test cases across multiple input parameters