feat(agent-relay-cursor): add share_desktop - #1158
Merged
Merged
Conversation
Contributor
Module Scorecard Check
|
| Theme | Before | After |
|---|---|---|
| Presentation & Onboarding | 6 / 17 | 6 / 17 |
| Integration | 5 / 25 | 5 / 25 |
| Credential Hygiene | 20 / 20 | 20 / 20 |
| Restricted-Environment | 12 / 20 | 12 / 20 |
| Engineering Quality | 10 / 10 | 10 / 10 |
| Overall | 58 / 100 | 58 / 100 |
Full scorecard for this PR
| Presentation & Onboarding | Agent Integration | Credential Hygiene | Restricted-Environment Readiness | Engineering Quality | Overall |
|---|---|---|---|---|---|
| 6 / 17 | 5 / 25 | 20 / 20 | 12 / 20 | 10 / 10 | 58 / 100 |
Drilldown
Presentation & Onboarding — 6 / 17
| Criterion | Max | Score | Notes |
|---|---|---|---|
| Configuration-mode examples | 12 | 6 | The README shows one full example (default install_cli = true). Other major modes—install_cli = false (baked image), computer_use = true, share_desktop = true—are mentioned in the Requirements section but lack dedicated examples with sensible defaults. Partial credit for documenting the primary mode and referencing the others. |
| Visual preview | 5 | 0 | No image, GIF, or video is embedded in the README. The frontmatter references an SVG icon (icon: ../../../../.icons/cursor.svg), but icons do not count. |
Credential Hygiene — 20 / 20
| Criterion | Max | Score | Notes |
|---|---|---|---|
| Secrets marked sensitive | 16 | 16 | agent_relay_credential is declared with mask_input = true and ephemeral = true in its styling block. The README example contains no inline secrets—only agent_id and install_cli. The "Worker credential" section explicitly states the token "is never written to disk." |
| Non-hardcoded auth path | 4 | 4 | The "Worker credential" section documents that Agent Relay mints a per-user sub-token at dispatch time; the service-account key never leaves Agent Relay. The README shows the full flow (relay exchanges key → stamps ephemeral parameter → module reads from environment). No raw keys are pasted into templates. |
Restricted-Environment Readiness — 12 / 20
| Criterion | Max | Score | Notes |
|---|---|---|---|
| Mirrorable artifact source | 5 | 0 | The install URL https://cursor.com/install is hardcoded in install.sh.tftpl. No module input variable overrides this URL. cli_binary changes the binary path, not the download source. No variable exists to point the installer at an internal mirror. |
| Bring-your-own binary | 10 | 10 | install_cli = false is documented in the README ("Bake the CLI into the image and set this to false for faster workspaces"). The install script becomes a no-op, and the start script still checks ~/.local/bin and PATH for the binary. Fully documented and tested. |
| Egress transparency | 3 | 0 | No dedicated README section enumerates external endpoints. cursor.com/install appears in the variable description and install script; cursor.com/agents/<id> and cursor:// appear in the app descriptions. These are scattered across unrelated sections with no air-gapped or restricted-network guidance. |
| Runs without sudo | 2 | 2 | All three scripts (install.sh.tftpl, start.sh.tftpl, status.sh.tftpl) never invoke sudo. The installer writes to ~/.local/bin; the start script writes to $HOME/.coder-modules/.... No root required for core functionality. |
Engineering Quality — 10 / 10
| Criterion | Max | Score | Notes |
|---|---|---|---|
| Input quality | 6 | 6 | All 8 module variables have clear descriptions and sensible defaults. cli_binary has a regex validation rejecting shell metacharacters; share_desktop validates the computer_use dependency; serving_log_pattern rejects empty strings. The agent_relay_cursor_credential_kind parameter includes named options. |
| Test coverage | 4 | 4 | main.tftest.hcl (12 test runs) covers the parameter contract, script rendering, credential wiring, and validation failures. main.test.ts (14 test cases) exercises the actual install/start scripts in a container with stub binaries, verifying lifecycle states, restart idempotency, credential routing, shell-injection safety, and file layout. Clear separation: HCL tests cover Terraform-level logic; TS tests cover end-to-end script behavior. |
Agent Integration — 5 / 25
| Criterion | Max | Score | Notes |
|---|---|---|---|
| AI governance | 10 | 0 | No mention of Coder AI Gateway or Agent Firewall in the README or code. The credential system is Agent Relay's own token-minting flow, not AI Gateway routing or Agent Firewall policy enforcement. |
| Dashboard entry point | 5 | 5 | Two coder_app resources are declared: cursor_web ("Open in Cursor Web") and cursor_desktop ("Open in Cursor Desktop"), both conditional on agent_relay_session_id being set. Documented in the README with the exact URLs and behavior. |
| Session continuity | 5 | 0 | The README documents worker-process restart safety (re-running the start step leaves a live worker alone), but does not document resuming a Cursor chat session across reconnects or relaunches. No mention of session-ID resumption, tmux, screen, or boo. Session continuity is delegated to Cursor/Agent Relay, not the module. |
| Managed configuration | 5 | 0 | No documentation of managed MCP servers, agent settings, policies, or workdir configuration. The module runs the Cursor CLI worker but does not expose or document any managed-configuration surface. |
Overall — 58 / 100
Raw 53 / 92 → round(53 / 92 × 100) = 58
Tip
You can run this locally by telling your agent: "review this module against .github/scorecard/SCORECARD.md".
Scored against SCORECARD.md with solstice-1. Language-model scores are advisory.
Emyrk
approved these changes
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Adds
share_desktoptoagent-relay-cursor. When set, the worker starts with--share-desktop=view_and_control, so people can watch or take control of the agent's desktop from the Desktop tab in Cursor. It requirescomputer_use = true(validated) and TigerVNC/Xfce in the image, e.g.ghcr.io/coder/agent-relay-workspace:desktop(coder/agent-relay#86).The mode is passed explicitly because
--share-desktoptakes an optional argument and, bare, swallows the followingstart.Type of Change
Module Information
Path:
registry/coder/modules/agent-relay-cursorNew version:
v0.4.0Breaking change: [ ] Yes [x] No
Testing & Validation
bun test: 19 pass;terraform test: 12 pass)bun fmt)computer_use+share_desktop. The worker ran with--computer-use --share-desktop=view_and_control, started Xtigervnc and Xfce, andagent worker debugreported computer use ready and desktop share supported. The agent's desktop showed up live in Cursor's Desktop tab.Related Issues
coder/agent-relay#86
https://claude.ai/code/session_01L2wLoUuHsK2Nzm93TjjoMi