Conversation
…s and start logic - Replace the agentapi module with coder-utils; drop Tasks/web-app inputs, the start script, and the task-reporting coder MCP server. - Install via the official installer for latest; pinned versions and mirrors use the release archive. - Make workdir optional; add mcp (merged into ~/.kiro/settings/mcp.json) and api_key (KIRO_API_KEY). - Keep agent_config and auth_tarball; the tarball is read from its env var instead of being rendered into the script. - Add scripts output, rewrite README and tests, bump to 2.0.0.
Contributor
Module Scorecard Check
|
| Presentation & Onboarding | Agent Integration | Credential Hygiene | Restricted-Environment Readiness | Engineering Quality | Overall |
|---|---|---|---|---|---|
| 12 / 17 | 10 / 25 | 20 / 20 | 18.5 / 20 | 10 / 10 | 77 / 100 |
Drilldown
Presentation & Onboarding — 12 / 17
| Criterion | Max | Score | Notes |
|---|---|---|---|
| Configuration-mode examples | 12 | 12 | README documents multiple major modes with examples: standalone with launcher app (workdir + auth_tarball), MCP servers + custom agent, pinned version / internal mirror (kiro_cli_version, kiro_install_url), install_kiro_cli = false (BYO binary), and script serialization. The Authentication section covers all three auth paths (tarball, API key, device flow). Sensible defaults are shown throughout. |
| Visual preview | 5 | 0 | No embedded image, GIF, or video in the README. The frontmatter icon field references an SVG file, but this is not a visual preview of the module in action. |
Credential Hygiene — 20 / 20
| Criterion | Max | Score | Notes |
|---|---|---|---|
| Secrets marked sensitive | 16 | 16 | Both auth_tarball and api_key are declared with sensitive = true in main.tf. README examples reference var.kiro_cli_auth_tarball (a variable, not an inline literal). No inline secrets appear in any README example. The install script reads credentials from environment variables (KIRO_CLI_AUTH_TARBALL, KIRO_API_KEY), never from the script body. |
| Non-hardcoded auth path | 4 | 4 | README documents three auth paths that avoid pasting raw keys into templates: (1) auth tarball generated on another machine and passed as a sensitive variable, (2) device flow via kiro-cli login in the workspace terminal, (3) API key as a sensitive variable. The tarball and device-flow paths explicitly avoid raw keys in HCL. |
Restricted-Environment Readiness — 18.5 / 20
| Criterion | Max | Score | Notes |
|---|---|---|---|
| Mirrorable artifact source | 5 | 5 | The kiro_install_url variable (default null) overrides the base URL from which Kiro CLI release archives are downloaded. The README "Pinned version or internal mirror" example shows kiro_install_url = "https://artifacts.internal.corp/kiro-cli-releases". The install script uses ARG_INSTALL_URL to construct the archive download URL, replacing the default https://prod.download.cli.kiro.dev/stable. |
| Bring-your-own binary | 10 | 10 | The install_kiro_cli variable (default true) allows disabling installation entirely. When set to false, the module validates that kiro-cli is already on PATH and skips download. README documents: "If install_kiro_cli = false, a working kiro-cli must already be on PATH, or workspace startup fails." The install script also auto-skips when a matching version is already present. |
| Egress transparency | 3 | 1.5 | No dedicated "Network Endpoints" or "Air-gapped Environments" README section exists. The "Pinned version or internal mirror" section does enumerate the two download endpoints (cli.kiro.dev/install, prod.download.cli.kiro.dev/stable) and describes the mirror layout for restricted environments, but it is framed as a configuration example rather than a dedicated egress-transparency section. Half credit for partial, under-documented coverage. |
| Runs without sudo | 2 | 2 | The install script (scripts/install.sh.tftpl) never invokes sudo. All operations target user-local paths: $HOME/.local/bin, $HOME/.kiro, $HOME/.local/share/kiro-cli, and shell profile files in $HOME. No root privileges are required for any step. |
Engineering Quality — 10 / 10
| Criterion | Max | Score | Notes |
|---|---|---|---|
| Input quality | 6 | 6 | All 12 variables have clear descriptions and sensible defaults. kiro_cli_version has a regex validation (`^(latest |
| Test coverage | 4 | 4 | main.tftest.hcl (10 test runs) covers business logic: defaults, workdir trimming, env-var creation for secrets, validation failures (version, MCP, agent_config), and scripts output ordering. main.test.ts (16 tests) covers end-to-end behavior in containers: install paths (official, pinned, mirror, BYO), version-matching skip, download failure, workdir creation, MCP merge/backup, agent config writing, auth tarball extraction, zstd requirement, secret isolation from scripts, and pre/post-install hooks. |
Agent Integration — 10 / 25
| Criterion | Max | Score | Notes |
|---|---|---|---|
| AI governance | 10 | 0 | No mention of Coder AI Gateway or Agent Firewall anywhere in the README or module code. The module installs and configures Kiro CLI but does not document how Coder governs auth, routing, or policy enforcement for the agent. |
| Dashboard entry point | 5 | 5 | The README "Standalone mode with a launcher app" example includes a complete coder_app resource with slug, display_name, icon, open_in = "slim-window", and a command that launches kiro-cli chat --trust-all-tools. |
| Session continuity | 5 | 0 | The README contains a brief NOTE suggesting tmux for one-shot prompts ("a coder_app that attaches to the existing session (for example, with tmux)"), but the module does not implement, configure, or document a session manager, resume mechanism, or session-ID support. This is a user-side tip, not documented module support. |
| Managed configuration | 5 | 5 | The module documents and implements managed MCP configuration (mcp variable merged into ~/.kiro/settings/mcp.json with existing-server-wins semantics) and managed agent settings (agent_config variable written to ~/.kiro/agents/<name>.json and set as chat.defaultAgent in ~/.kiro/settings/cli.json). Both are covered in the "MCP servers and a custom agent" README example with merge/preservation semantics explained. |
Overall — 77 / 100
Raw 70.5 / 92 → round(70.5 / 92 × 100) = 77
Tip
You can run this locally by telling your agent: "review this module against .github/scorecard/SCORECARD.md".
Scored against SCORECARD.md with solstice-1. Language-model scores are advisory.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refactor
harleylrn/kiro-clito install and configure Kiro CLI only, matching the claude-code, codex, copilot, and cursor-cli (#1152) migrations.order,group,report_tasks,cli_app,web_app_display_name,cli_app_display_name,install_agentapi,agentapi_version,agentapi_chat_based_path,ai_prompt,system_prompt,coder_mcp_instructions), thetask_app_idoutput, the start script, and the task-reportingcoderMCP server.https://cli.kiro.dev/install, temp file +bash -nvalidation, retrying curl) forlatest. Pinnedkiro_cli_versionor a customkiro_install_urldownloads<url>/<version>/kirocli-<arch>-linux.zipand runs itsinstall.sh, keeping the existing version-pinning and air-gapped support. Skipped whenkiro-cliis already onPATH(and matches a pinned version).workdiris now optional (defaultnull) and is created if missing.mcp, merged into user-level~/.kiro/settings/mcp.json(existing servers win on duplicate names; invalid JSON is backed up to.bak), andapi_key(KIRO_API_KEY).agent_config(written to~/.kiro/agents/<name>.json, setschat.defaultAgentincli.jsonwhile preserving other keys;namevalidated as a plain file name) andauth_tarball(KIRO_CLI_AUTH_TARBALL). The tarball is now read from that env var at install time instead of being rendered into the script.trust_all_toolsand the default agent template:--trust-all-toolsmoves to the user'scoder_app, and withoutagent_configKiro's built-in default agent is used.scriptsoutput; rewrite README (v2 warning, launcher example) and tests. Bump to2.0.0.Important
Not verified end to end, because every Kiro command beyond
settings/--versionrequires a login (no Kiro account available): that the built-in default agent loads~/.kiro/settings/mcp.json(the docs say user-level servers apply globally), thatkiro-cli mcp addwithout--forcekeeps the existing server (the--helptext says--forceoverwrites), and that an extractedauth_tarballauthenticates 2.26.0. The README screenshot (.images/kiro-cli.png, likely the AgentAPI web UI) is no longer referenced; the image file itself is left in place.Decision log
Verified against the installed CLI (
kiro-cli 2.26.0) and the Kiro docs:VERSIONto the official installer<channel>/latestand prompts on/dev/ttyif~/.local/bin/kiro-cliexists; versioned archives exist atprod.download.cli.kiro.dev/stable/<ver>/(no per-version manifest, so no checksum)latest; release archive for pinned versions/mirrors; skip install when already presentchat.defaultModelsetting and--modelflag--modelmanaged_settingsroot-owned policymcp addduplicate semanticskiro-cli mcp addrequires login, so it cannot run at install time;--forceoverwrites~/.kiro/settings/mcp.json, existing wins--trust-all-tools,--trust-tools)trust_all_toolsbecomes a launcher flagKIRO_API_KEY(after browser login in precedence; documented for headless use)api_key; keepauth_tarballfor interactive sessionsauth_tarballinto the scriptKIRO_CLI_AUTH_TARBALLfrom the agent envsystem_promptis a Tasks inputsystem_promptand the@codertask toolpromptinagent_configinsteadKIRO_HOMEoverrides~/.kirofor agents and settings (verified)KIRO_HOMEinstall.sh --no-confirm(shell-integration setup); official installer setsKIRO_CLI_SKIP_SETUP=1Testing
terraform validate,terraform test(10 passed)bun test main.test.ts(17 passed, container-based)codercom/enterprise-nodewith the rendered install script: official installer (2.26.0), idempotent re-run, then pinned 2.25.0 archive over it;CODER_SCRIPT_BIN_DIRsymlink runskiro-cli chat --helpwithout~/.local/binonPATHreadmevalidationGenerated with Coder Agents.