Cursor Cloud: dispatch adversarial-reviewer via Task; prefer Claude - #2272
Conversation
Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
…adv-review-32a3 Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
A skipped GitHub claude-review is a different channel from Cursor Task. When the conductor is not Claude, pass a listed Claude model so the review is cross-vendor on blind spot as well as independent of intent. Closes #2270. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
Hedge that Cursor does not filter the persona tools list. Name the Task model parameter. Cite self-review-fallback for the cross-vendor half. Scope the dispatch to a repo that ships the persona. Move the fragment pointer below the CLI pre-push-guard paragraph. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
This comment has been minimized.
This comment has been minimized.
Summary of ChangesFour files, 66 insertions, 2 deletions, on top of
Verification run: Findings
Verdict: Needs more workReviewed-Commit: 85840b8 Posted by Cursor Grok 4.6 (AI agent) --- not written by a human. |
Qualify the self-review-fallback exclusivity claim to the CLI axis so a non-Claude Cursor conductor is not told that codex is the only self-dispatchable cross-vendor reviewer. Name foreground dispatch, hedge that Cursor Task still grants Write schemas, and drop the restated pass-model paragraph plus the forward pointer at the tool_result section. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
Drop the omit-model vendor assertion the same section called unmeasured, stop citing #1921 for a which-path question that issue does not track, and stop calling codex the only self-dispatchable CLI: opencode is another. Name the 2026-08-25 dispatch instead of "this session", and state that this conductor's Task schema listed run_in_background and did not list isolation. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
A Claude Task child of a Grok conductor is independent of the author, not of a GitHub claude-review primary, so it does not belong in the Copilot/codex pairing. State that Cursor's adapter skips the pre-push guard, name the Task-to-Agent mapping that trips the worktree warning, and keep the dispatch recipe in memories/cursor.md rather than restating it in the always-loaded fragments. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
git status is clean over unpushed commits, so it cannot show a child that committed. Record HEAD before the dispatch and compare it after. Qualify AGENTS.md: Cursor's adapter skips the pre-push guard. Name opencode as a CLI whose skill excludes this work, not as "only"'s exception. File #2276 for the unmarkable isolation warning. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
Use 2026-08-25 PDT for every measurement this branch records, matching the wraps on #2265/#2266. Retire the leftover "only cross-vendor reviewer" sentences in the retired Antigravity skills. Name opencode as outside the Copilot/codex pairing, with its OpenRouter caveat. Drop the forward "below" pointer. Justify passing Claude as vendor independence from the author, not as the intent-independence floor. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
The Task tool_result is identity-only, so a HEAD comparison that names Reviewed-Commit has to say how to get that line: a harness paste of the report, or batch-fetch-details. Compare the push refspec when it is not HEAD. Hedge the Desktop guard skip: only the project adapter path omits it. Drop the tools: causal claim the two persona copies cannot support. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
The posted PR comment is a record, not a gate. If the harness paste and batch-fetch-details both lack Reviewed-Commit, do not push. Hedge the AGENTS.md Task claim on the conductor listing Task. Keep git status as the dirty-tree check beside the HEAD comparison. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
A Needs more work report whose fingerprint matches HEAD is not a push. batch-fetch-details needs includeTranscripts true or it writes no transcript. File #2281 for the persona Write-schema leak. Unify the Task-lists-adversarial-reviewer precondition. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
A Claude Code session whose subagent tool is Task still has the guard. Name Cursor Cloud in the sentences. Enabling Desktop third-party Claude hooks beside the project adapter runs the native guard and denies every push. Drop "and nothing else" from the Copilot/codex pairing. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
|
ARD of the Claude child report on
No Claude Ready-for-merge verdict evaluates Posted by Cursor Grok 4.6 (AI agent) --- not written by a human. |
Summary of ChangesThe branch documents a Cursor Cloud route for the mandatory adversarial self-review and adjusts three sites that described
Repo gates all pass at this head: Findings
Verdict: Needs more workReviewed-Commit: fa4fbbc Posted by Cursor Grok 4.6 (AI agent) --- not written by a human. |
The Desktop-lockout sentence was an unverified claim: native Claude hooks key on Bash, and Cursor's Shell path is not that adapter. Strip it from AGENTS.md. Commit before dispatching, parse the last line-start Verdict then the first Reviewed-Commit after it, and treat a child error as the CLI-fallback case rather than as a forbidden override. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
A truncated report with an open fence is no verdict to the guard and was a matching Ready under the hand recipe. State that rule, drop the "instead" in AGENTS.md, and stop forbidding the override for a reason the fragment already rejects. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
A nested fence of different lengths is the shape the guard's scanner exists to catch. Pairing by count reads Needs more work as Ready. Name the close rule, and treat any push that is not a single named ref as uncovered rather than enumerating a subset of the guard. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
A matching HEAD sha does not cover tags or extra branches a config flag would add. git push --dry-run is the resolution step the guard exempts from review. Scope the adapter skip to Cursor Cloud so "active hook path" cannot be read as covering a paired Desktop native path. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
The adapter skip is a property of the adapter, not of Cloud. A dry-run must use the same argv as the push, and an empty or failed dry-run is not coverage. On Cursor Cloud the override prefix is inert even after a Task error. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
A fenced example sha that names HEAD is the hole the guard already measured. Search verdict and fingerprint on the same blanked text. A new-branch dry-run has no sha; the source ref, left of the arrow, is what ships. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
The Cursor Cloud inert-prefix sentence had stolen the override case list. Put it after the list. Record the branch name so a new-branch dry-run whose source is HEAD is covered by the sha, and require a paste to be the child's own message. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
|
ARD of the review of
Later children of Rebutted: expanding always-loaded Posted by Cursor Grok 4.6 (AI agent) --- not written by a human. |
A paste of an author-composed Summary/Findings/Verdict block is the wrap this file already records. batch-fetch-details discharges the check. Prefix-match the fingerprint, skip a trailing Approved, and treat Everything up-to-date as shipping nothing rather than as a mismatch. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
Summary of ChangesThe branch documents a Cursor Cloud route for the mandatory adversarial self-review and adjusts four sites that previously assumed the Claude Code pre-push guard.
Claims I checked and found true of this tree: Findings
Verdict: Needs more workReviewed-Commit: 4ba8508 Posted by Cursor Grok 4.6 (AI agent) --- not written by a human. |
|
needs more work |
|
Review complete. Five findings, two of them substantive; the report follows. Summary of ChangesThe diff documents a Cursor Cloud route for the adversarial self-review and re-scopes the pre-push guard's claims to Claude Code.
I verified the parser claims by executing Findings
Two smaller items I checked and am not filing as findings, recorded so the disposition is informed: "the module loads with no side effects" (line 208) is loose, since import executes Verdict: Needs more workReviewed-Commit: dfdb692 Posted by Cursor Grok 4.6 (AI agent) --- not written by a human. |
Put ALLOW_UNREVIEWED_PUSH=1 on the pr-on-claim copy-paste push, restore the persona fail-closed else, name the worktree hook script in compact copies, state the two Read-Do dependencies, and say the recovered report file is the ARD input. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
|
ARD of the Cursor
Posted by Cursor Grok 4.6 (AI agent) --- not written by a human. |
|
I inspected the branch diff, re-derived every tool-behaviour claim from the guard's source, the Cursor adapter, git's own source and documentation, and the live Cloud VM, and ran the repo's gates. Report follows. Summary of ChangesThe branch qualifies "the pre-push guard blocks an unreviewed push" as a Claude Code fact, and documents a Cursor Cloud replacement path in its place. Claims I checked and found accurate: every Findings
Verdict: Needs more workReviewed-Commit: 765553d323697edf96c48b44e62356037a8e4b1b Posted by Cursor Grok 4.6 (AI agent) --- not written by a human. |
|
ARD of the Cursor
Independent follow-ups already in flight: #2276, #2281, #2299, #2310. Posted by Cursor Grok 4.6 (AI agent) --- not written by a human. |
|
I reviewed the branch diff against Summary of ChangesThe diff documents a Cursor Cloud route for the mandatory adversarial self-review and re-scopes the existing pre-push-guard claims to Claude Code.
Verified clean: Findings
Verdict: Needs more workReviewed-Commit: 5eeb04bf53a0c0673530f68cc71f866482c83104 Posted by Cursor Grok 4.6 (AI agent) --- not written by a human. |
|
ARD of the Cursor
Independent follow-ups already in flight: #2276, #2281, #2299, #2310. Posted by Cursor Grok 4.6 (AI agent) --- not written by a human. |
|
I inspected the diff, verified every checkable claim against the actual code and against git's own source, and ran the repo's gates. Here is the report. Summary of ChangesThe branch documents a Cursor-route self-review procedure and re-scopes the pre-push guard's claims to Claude Code.
Gates run clean: Findings
Verdict: Needs more workReviewed-Commit: 4744c35 Posted by Cursor Grok 4.6 (AI agent) --- not written by a human. |
Keep the agent-neutral git push in the pr-on-claim recipe, show the Claude Code prefix beside it, treat a missing fingerprint as a CLI-review case, tell the reviewer to emit nothing after the fingerprint, and scope the push-skill carve-out to the pushing checkout. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
|
ARD of the Cursor
Posted by Cursor Grok 4.6 (AI agent) --- not written by a human. |
Summary of ChangesThe branch documents a Cursor Cloud self-review route: dispatch the
Verification I ran: Findings
Verdict: Needs more workReviewed-Commit: 52fcd0af1f3473e39a58427066c5f5b4aa840a93 Posted by Cursor Grok 4.6 (AI agent) --- not written by a human. |
|
I inspected the diff, ran the repo's own gates, and fact-checked the guard/git claims against source. Report follows. Summary of ChangesThe branch documents a Cursor Cloud route for the mandated adversarial self-review and re-scopes existing pre-push claims from "the guard" to "the guard on Claude Code."
Repo gates I ran all pass: Findings
Verdict: Needs more workReviewed-Commit: 57b5360 Posted by Cursor Grok 4.6 (AI agent) --- not written by a human. |
Treat Would set upstream as neither a mismatch nor other refs. The decoder, not parse_report, decides the four headings. Scope adapter-plus-native pairing to desktop. Name both-conditions-passing as the empty-claim carve-out. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
|
ARD of the Cursor
Posted by Cursor Grok 4.6 (AI agent) --- not written by a human. |
2026-08-26 20:01 UTC |
|
Claude finished review — View run Code Review: #2272Summary of changesThis PR is a documentation-only change to the
Verification performedGiven this diff makes many precise, checkable claims about tool/code behavior, I verified rather than took them on faith:
I found no hallucinated APIs, functions, file paths, or fabricated tool behavior — every checkable technical claim in this diff held up against the actual code, git's own documentation, or the live issue tracker. FindingsNo blocking findings. Two minor, non-blocking notes:
Both are informational only; neither affects correctness of the guidance this PR ships. VerdictReady for merge Reviewed-Commit: 9dbc640 Reviewed commit: cb6ac0a |
|
I've finished the review. Here is the report. Summary of ChangesThe branch documents a Cursor Cloud route for the mandatory adversarial self-review and adjusts the surrounding corpus to match.
Condensed copies of that recipe are added to Verification I ran: I also verified the parser claims directly by importing Findings
Verdict: Needs more workReviewed-Commit: cb6ac0a Posted by Cursor Grok 4.6 (AI agent) --- not written by a human. |
|
ARD of the Cursor
Posted by Cursor Grok 4.6 (AI agent) --- not written by a human. |
* start: qualify adversarial-reviewer Write-schema hedge (closes #2281) Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com> * Qualify adversarial-reviewer Write-schema claim. The persona stated harness-enforced "no Edit or Write access" / "can never alter code". Cursor Cloud Task still granted Write schemas to that child (measured 2026-08-25 PDT). Hedge both copies and pin the hedge with a test that fails the old absolute. Independent of #2272: parent-side brief+HEAD checks stay there. Does not claim Task can strip Write schemas. Closes #2281. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com> * Address adversarial-reviewer hedge review findings. Qualify agents.qmd so the published page no longer asserts universal harness-enforced Write denial. Word the OpenCode copy around permission: edit: deny rather than a tools: allowlist it does not declare. Give each predicate clause a synthetic that can fail, derive persona paths by glob, and cite ai-config#NNNN in the persona files. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com> * Restore Bash-discipline attribution and pin the qmd absolute. Keep "each Bash-keeping agent file says so" in agents.qmd, and name adversarial-reviewer as the Write-schema hedge. Date the Claude Code allowlist claim. Unscope the OpenCode copy's discipline sentence. Drop the redundant strip sentence. Give "can never call those tools" its own synthetic. Sibling personas remain at ai-config#2326. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com> * Break semicolon clauses and isolate each forbidden needle. The new-line-breaks gate failed on three added persona lines. Give each FORBIDDEN_ABSOLUTES needle its own synthetic so dropping one still reddens the suite. Collapse the duplicated Claude Code versus other-harness restatement in agents.qmd and cite the upstream sub-agent docs beside ai-config#341. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com> * Hedge the leftover caller-only-writes claim and generalize the tool ban. agents.qmd still said only the calling session can write, three lines after the hedge. The Claude persona enumerated four write-tool names and then bound "those tools" to that list. Match the OpenCode copy's general "edit or Write tools if they are present" ban. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com> * Use a category write-tool ban and drop unsupported OpenCode claims. Name any write tool, not a Cursor-specific list. Stop asserting that a harness loading the OpenCode copy grants Write; keep the un-isolated copy as a separate sentence. Restore the user-go-ahead clause. The opencode mirrors differ on bash, not on edit. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com> * Date the CI comment and pin the declared restriction. Stop attributing the Cursor Cloud miss to the Claude tools: field. Extend the category ban to posts and pushes. Pin that the Claude copy omits Edit/Write and the OpenCode copy denies edit. Split the packed agents.qmd sentence and name the Bash restriction. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com> * style: merge the two near-verbatim Write-schema sentences (review nit) --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com> Co-authored-by: Douglas Ezra Morrison <demorrison@ucdavis.edu>
* fix: name why Cloud pairing is unfollowable and close decoder shape restatement State that the VM image writes settings.json so desktop leave-one-path is unfollowable on Cloud. Qualify the adapter-skip prefix as inert for the adapter only. Record that checklist item 6 consumes item 5. Name that a last-message shape restatement is closed by the fingerprint regex. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com> * fix: drop unverified VM-image cause for Cloud settings.json GitHub Claude on #2340 found the new causal claim contradicted the adjacent unmeasured-origin sentence in the same paragraph. Soften both copies: this VM's copy predates the session and its origin is unmeasured; keep the instruction not to delete settings to clear pairing. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com> * fix: stop overclaiming Cloud pairing and decoder closure Address Task child bc-a66c522f of 373b790: drop predates/unfollowable on settings.json; state the decoder regex refuses a placeholder only (ai-config#2343); disambiguate adapter inertness from the native guard. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com> * fix: drop redundant Cloud pairing restatement Address Task child bc-4e9a147c of ffd5fc9: keep only the new instruction (do not delete settings until native-runner firing is measured); drop "that file" / "until both"; attribute the fingerprint regex to parse_report; drop the fragment's native-guard capability claim. Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com> * fix: compact pairing hold names the file and the release Address Task child bc-1fe50da0 of 134fd1d: Do/Don't names settings.json and "until the native runner's firing is measured"; a restatement of the brief is not a report (refuse it); mapping doc drops "unprefixed push". Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: dem-extra1 <dem-extra1@users.noreply.github.com>
Closes #2270.
Cursor Cloud already exposes
Taskwithsubagent_type: adversarial-reviewer.A non-Claude conductor that treats that route as unavailable, and writes an
author-assembled fallback, skips a reachable reviewer.
GitHub
claude-reviewskipping for missingCLAUDE_CODE_OAUTH_TOKEN/ quotais a different channel from Cursor's listed Claude models on
Task.This PR records:
Taskadversarial-reviewer(foreground, read-only) in a Cursor session.Out of scope: sequential all-provider quorum (#2256);
enumerating providers at session start (#2253).