sha256:e8f6ee09673e66182700b39e8ef0b167f5e2570530fe6d2c441ff04945f9ee2d
Last pushed
9 days by cdupuis
Type
Sandbox Kit
Manifest digest
sha256:e8f6ee09673e66182700b39e8ef0b167f5e2570530fe6d2c441ff04945f9ee2d
schemaVersion: "3"
displayName: Cursor (mixin)
description: Cursor's agent CLI as a mixin — the agent in an overlay, with the Cursor credential (API key or OAuth), scoped egress, and the workspace pre-trust and config seeds the agent needs. Layer it onto a shell base and run `cursor-agent`.
version: 2026.09.18-9a7762b
kind: mixin
provides:
- [email protected]
capabilities:
- type: com.docker.sandbox/network-policy@1
config:
runtime:
allow:
- api2.cursor.sh
- api3.cursor.sh
- repo42.cursor.sh
- cursor.com
- '*.cursor.sh'
- downloads.cursor.com
- registry.npmjs.org
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: api2.cursor.sh
format: Bearer %s
header: Authorization
- domain: api3.cursor.sh
format: Bearer %s
header: Authorization
- domain: repo42.cursor.sh
format: Bearer %s
header: Authorization
- domain: cursor.com
format: Bearer %s
header: Authorization
name: CURSOR_API_KEY
oauth:
resourceHosts:
- api3.cursor.sh
- repo42.cursor.sh
- cursor.com
responseFields:
accessToken: accessToken
refreshToken: refreshToken
sentinels:
accessToken: cursor-oat-proxy-managed
refreshToken: cursor-ort-proxy-managed
tokenEndpoint:
host: api2.cursor.sh
path: /auth/poll
phase: runtime
service: cursor
description: Cursor API access (API key or Cursor OAuth)
- type: com.docker.sandbox/lifecycle@1
config:
files:
- content: '{"network": {"useHttp1ForAgent": true}}'
description: Seed HTTP/1.1+SSE for agent connections so traffic goes through the forward proxy
overwrite: false
path: /home/agent/.cursor/cli-config.json
install:
- command: mkdir -p /home/agent/.cursor && chown agent:agent /home/agent/.cursor
description: Ensure .cursor is owned by agent before the file seed and bind mounts run
user: "0"
- command: |
[ -n "$WORKSPACE_DIR" ] || { echo "WORKSPACE_DIR unset; skipping Cursor workspace pre-trust" >&2; exit 0; }
ws="$WORKSPACE_DIR"
slug=$(printf '%s' "$ws" | sed 's#^/##; s#/#-#g')
dir="/home/agent/.cursor/projects/$slug"
mkdir -p "$dir"
esc=$(printf '%s' "$ws" | sed 's/\\/\\\\/g; s/"/\\"/g')
[ -f "$dir/.workspace-trusted" ] || printf '{"trustedAt":"%s","workspacePath":"%s"}\n' "$(date -u +%Y-%m-%dT%H:%M:%S.000Z)" "$esc" > "$dir/.workspace-trusted"
description: Pre-trust the workspace so cursor-agent skips the interactive Workspace Trust prompt
env:
- WORKSPACE_DIR
user: agent
- type: com.docker.sandbox/agent-context@1
config:
contentFile: /usr/share/sandbox/kit/cursor-mixin/cursor-mixin-context.md
args:
version:
default: 2026.09.18-9a7762b
description: Cursor Agent release to install (calendar version plus build hash)
pattern: ^[0-9]{4}\.[0-9]{2}\.[0-9]{2}-[0-9a-f]{7,40}$
buildArg: CURSOR_VERSION