Skip to content

Record Cursor's write gate and stop follow-up from a live witness (0.3.3) - #158

Merged
jothimani-rajendran merged 2 commits into
mainfrom
claude/cursor-write-gate-and-stop-followup
Sep 23, 2026
Merged

jothimani-rajendran merged 2 commits into
mainfrom
claude/cursor-write-gate-and-stop-followup

Conversation

@jothimani-rajendran

Copy link
Copy Markdown
Collaborator

What this changes

Cursor is no longer recorded as unreachable at the write and stop surfaces. A live probe of Cursor 3.21.18 (Windows) showed that the generic preToolUse event fires for the Write tool with the target path and full content, and honours {"permission": "deny"}; and that the stop event honours {"followup_message": ...} (observed loop_count 0 → 1), while a silent stop simply ends the turn (fail open). afterFileEdit accepts nothing back, and the chat reply is not a tool call.

  • cursor vendor: tools.write = ["Write"]; the stop gate is recorded under a new grammar G6 (followup_message), with no escalate and no transform; stop is listed in allow_silent_events, so the hook-entry wrapper never installs failClosed for it.
  • cursor adapter: a refusal at stop is handed back as {"followup_message": <reason>}; a clean stop stays silent; an ask degrades with the existing "cannot prompt" wording.
  • matrix: cursor stop is now block: true, rewrite: false, fail_mode: open with live-run-partial evidence dated 2026-09-23; pre_tool block evidence updated; verified record set to 3.21.18.
  • recount tooling: G6 classification in tools/recount/gates.py, sourced tools evidence, stated allow_silent_events; the vendor schema accepts G6.
  • Goldens, examples/generated/cursor.md, docs/design/dialect-families.md (G6 row), changelog and version bumped to 0.3.3 (pyproject, CITATION.cff, __version__).

Claim check

  • No capability claim is widened without a mechanism behind it (deny at preToolUse, followup_message at stop, both exercised live)
  • Any new/changed MATRIX row carries a verified record (version 3.21.18, date 2026-09-23, method: capturing hook on a Windows install)
  • Payload shapes come from a primary source: a captured run with a capturing hooks.json on Cursor 3.21.18. The capture is reproduced in the WITNESS text on the cursor matrix row and in matrix-notes.json; the payloads carry a UTF-8 BOM, which the dispatcher already strips.

Checks

  • pytest -q passes (1850 passed, 4 skipped)
  • ruff check . and ruff format --check . pass
  • Runtime path is still stdlib-only (no new imports outside the standard library)
  • Commits are signed off (git commit -s)

Notes for the reviewer

The stop-side claim is deliberately live-run-partial: the follow-up was observed to re-enter the agent once, but the probe did not exercise how Cursor behaves when the follow-up itself is refused again, so honours_escalate and honours_transform stay false. After this ships, chock will pin 0.3.3 so its packaged Cursor gate reaches writes at preToolUse and reports at stop. Tagging v0.3.3 for the PyPI release is a maintainer action.

🤖 Generated with Claude Code

https://claude.ai/code/session_01CzNYfzP8ymU3r4JB9Sz8Ha


Generated by Claude Code

Cursor 3.21.18 was probed with a capturing hook. The generic preToolUse
event fires for the Write tool with the target path and full content,
and a {"permission": "deny"} answer is honoured. The stop event honours
{"followup_message": ...} (loop_count 0 -> 1), and a silent stop ends
the turn, so stop fails open. afterFileEdit accepts nothing back and
the chat reply is not a tool call.

- cursor vendor: tools.write = ["Write"]; stop gate recorded as the new
  G6 follow-up grammar (no escalate, no transform); stop is allowed to
  stay silent, so the wrapper never installs failClosed for it
- cursor adapter: a refusal at stop is handed back as followup_message
- matrix: cursor stop block=true, rewrite=false, fail_mode=open, with
  live-run-partial evidence; verified version 3.21.18
- recount: G6 classification, sourced tools evidence, stated
  allow_silent_events; schema accepts G6
- goldens, examples, dialect-families doc, changelog and version 0.3.3

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: Claude <noreply@anthropic.com>
The matrix figure now grades Cursor's stop cell best-effort, and the
social preview carries the 0.3.3 version. Both are derived from the
package by docs/figures/make_*.py and docs/assets/gen_brand_assets.py.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: Claude <noreply@anthropic.com>
@jothimani-rajendran
jothimani-rajendran marked this pull request as ready for review September 23, 2026 10:39
@jothimani-rajendran
jothimani-rajendran merged commit a7e712b into main Sep 23, 2026
19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants