Record Cursor's write gate and stop follow-up from a live witness (0.3.3) - #158
Merged
jothimani-rajendran merged 2 commits intoSep 23, 2026
Merged
Conversation
Cursor 3.21.18 was probed with a capturing hook. The generic preToolUse
event fires for the Write tool with the target path and full content,
and a {"permission": "deny"} answer is honoured. The stop event honours
{"followup_message": ...} (loop_count 0 -> 1), and a silent stop ends
the turn, so stop fails open. afterFileEdit accepts nothing back and
the chat reply is not a tool call.
- cursor vendor: tools.write = ["Write"]; stop gate recorded as the new
G6 follow-up grammar (no escalate, no transform); stop is allowed to
stay silent, so the wrapper never installs failClosed for it
- cursor adapter: a refusal at stop is handed back as followup_message
- matrix: cursor stop block=true, rewrite=false, fail_mode=open, with
live-run-partial evidence; verified version 3.21.18
- recount: G6 classification, sourced tools evidence, stated
allow_silent_events; schema accepts G6
- goldens, examples, dialect-families doc, changelog and version 0.3.3
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: Claude <noreply@anthropic.com>
The matrix figure now grades Cursor's stop cell best-effort, and the social preview carries the 0.3.3 version. Both are derived from the package by docs/figures/make_*.py and docs/assets/gen_brand_assets.py. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: Claude <noreply@anthropic.com>
jothimani-rajendran
marked this pull request as ready for review
September 23, 2026 10:39
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this changes
Cursor is no longer recorded as unreachable at the write and stop surfaces. A live probe of Cursor 3.21.18 (Windows) showed that the generic
preToolUseevent fires for theWritetool with the target path and full content, and honours{"permission": "deny"}; and that thestopevent honours{"followup_message": ...}(observedloop_count0 → 1), while a silent stop simply ends the turn (fail open).afterFileEditaccepts nothing back, and the chat reply is not a tool call.tools.write = ["Write"]; the stop gate is recorded under a new grammar G6 (followup_message), with no escalate and no transform;stopis listed inallow_silent_events, so the hook-entry wrapper never installsfailClosedfor it.stopis handed back as{"followup_message": <reason>}; a clean stop stays silent; anaskdegrades with the existing "cannot prompt" wording.stopis nowblock: true, rewrite: false, fail_mode: openwithlive-run-partialevidence dated 2026-09-23;pre_toolblock evidence updated;verifiedrecord set to 3.21.18.tools/recount/gates.py, sourced tools evidence, statedallow_silent_events; the vendor schema accepts G6.examples/generated/cursor.md,docs/design/dialect-families.md(G6 row), changelog and version bumped to 0.3.3 (pyproject, CITATION.cff,__version__).Claim check
preToolUse,followup_messageatstop, both exercised live)MATRIXrow carries averifiedrecord (version 3.21.18, date 2026-09-23, method: capturing hook on a Windows install)hooks.jsonon Cursor 3.21.18. The capture is reproduced in the WITNESS text on the cursor matrix row and inmatrix-notes.json; the payloads carry a UTF-8 BOM, which the dispatcher already strips.Checks
pytest -qpasses (1850 passed, 4 skipped)ruff check .andruff format --check .passgit commit -s)Notes for the reviewer
The stop-side claim is deliberately
live-run-partial: the follow-up was observed to re-enter the agent once, but the probe did not exercise how Cursor behaves when the follow-up itself is refused again, sohonours_escalateandhonours_transformstay false. After this ships, chock will pin 0.3.3 so its packaged Cursor gate reaches writes atpreToolUseand reports atstop. Tagging v0.3.3 for the PyPI release is a maintainer action.🤖 Generated with Claude Code
https://claude.ai/code/session_01CzNYfzP8ymU3r4JB9Sz8Ha
Generated by Claude Code