Repository files navigation

AgentStack Cursor Plugin

Turn every Cursor agent into an AgentStack-native engineer.
v0.4.18 (gen3) · Plugin MCP Connect + Device Code · one MCP tool


30-second install

# In Cursor chat:
/agentstack-init

The plugin prints a short code, opens https://agentstack.tech/activate, and after you approve writes a scoped Bearer into ~/.cursor/mcp.json. No copy-pasting API keys. (OAuth 2.1 Device Authorization Grant — RFC 8628.) Quick re-auth: /agentstack-authorize. New chats auto-open Activate when MCP is unsigned or the JWT has service_caps=null (sessionStart --from-hook).

MCP surface (0.4.18):

WhatContract
Plugin MCPplugin.jsonmcpServers: "./mcp.json" — URL-only, click Connect (G-A174)
User MCP~/.cursor/mcp.json from Device Code / session-start (hooks)
tools/listOne tool: agentstack.execute (Cursor UI may show agentstack_execute)
tools/callAccepts agentstack.executeandagentstack_execute
ActionsLive catalog: GET https://agentstack.tech/mcp/actions

Plugin mcp.json must not contain Authorization or ${AGENTSTACK_ACCESS_TOKEN} (G-A162 empty Bearer). Device Code still writes a Bearer into ~/.cursor/mcp.json. User template: mcp.example.json.


Why AgentStack

Most AI tools generate backend code. AgentStack teaches the agent to route intent to an existing platform action first, and only write code when no action fits.

You asked the agent for …Without the pluginWith the plugin
User sign-in / sign-upHandwritten JWT, sessions, bcryptauth.login + session cookie
Role-based accessCustom middleware + roles tablerbac.* + protected.* 8DNA
Persistent app dataPrisma/Drizzle + migrations8DNA project.data.* / user.data.*
Payments / subscriptionsStripe SDK from scratchpayments.* + buffs.*
RAG / semantic searchpgvector + embedding pipelinerag.* (TurboQuant, hybrid)
Cron / webhooks / signalsNew routes + queue gluescheduler.*, webhooks.*, logic.*

Layout (Cursor 2.6+)

provided_plugins/cursor-plugin/
├── .cursor-plugin/
│ ├── marketplace.json # Add marketplace / GitHub install (pluginRoot: plugins)
│ ├── listing.json # Publisher SoT (screenshots, privacy, support)
│ └── VALIDATION.md
├── plugins/agentstack/ # ← the plugin package Cursor loads
│ ├── .cursor-plugin/plugin.json
│ ├── mcp.json # URL-only plugin MCP (Connect); no Bearer placeholder
│ ├── rules/ # 9 .mdc (1 alwaysApply: agentstack-prefer)
│ ├── skills/ # 24 domains + optional solana
│ ├── commands/ # 14 slash workflows
│ ├── agents/ # 3 marketplace agents (+2 maintainer overlay)
│ ├── hooks/ # lifecycle + policy scripts
│ ├── lib/plugin-kernel/ # vendored Device Code + MCP helpers
│ └── assets/ # logos + marketplace screenshots
├── scripts/ # validate, smoke, install-local, diagnose, verify
├── docs/CAPABILITY_MATRIX.md
├── README.md · CHANGELOG.md · LICENSE
└── FLOW.md · LOCAL_INSTALL.md · MCP_QUICKSTART.md · …

5-layer product surface (inside plugins/agentstack/): rules → skills → commands → agents → hooks.
Catalog plane: live GET /mcp/actions (never hard-code action counts in skills).


First 5 minutes

  1. node scripts/install-local.mjsDeveloper: Reload Window
  2. /agentstack-authorize (or /agentstack-init) → approve at /activate
  3. /agentstack-diagnose then /agentstack-capability-matrix
  4. Optional: /agentstack-host-site for a live /s/ URL

Primary auth: click Connect on plugin MCP (G-A174) or Device Code → Bearer in ~/.cursor/mcp.json. Fallback: API key via MCP_QUICKSTART.md.


Slash commands

CommandWhat it does
/agentstack-authorizeDevice Code sign-in (no API key) — plugin auth control
/agentstack-initDevice Code auth + lean MCP write + SDK scaffold
/agentstack-loginRe-auth or switch project / scopes
/agentstack-scaffold-authMinimal login/register UI on auth.*
/agentstack-scaffold-backendRBAC + Buffs gates + AgentPay + admin panel
/agentstack-sync-schemaPrisma/Drizzle → 8DNA + FAP + Logic
/agentstack-index-docsRAG-index project markdown into my-project-docs
/agentstack-capability-matrixLive domain × actions from /mcp/actions
/agentstack-diagnoseToken, discovery, MCP surface, hooks health
/agentstack-host-sitePublish HTML/ZIP → /s/ URL
/agentstack-support-setupProject support channel binding
/agentstack-integrations-wizardIntegration Hub recipes
/agentstack-sdk-surface@agentstack/sdk / protocol pointers
/agentstack-discoverDiscover hub / Compass routing

Intent → MCP routing

Intent signalFirst port of call
login / register / sessionsauth.* (tenant app). Plugin MCP sign-in → /agentstack-authorize
permissions / rolesrbac.* + protected.* 8DNA
store / read app dataproject.data.* / user.data.*
files / blobsstorage.*
payments / creditspayments.* + wallets.* + buffs.*
chat / channelssocial.*
trials / tier gatesbuffs.*
semantic search / memoryrag.*
async reactionslogic.* rules + triggers

Live catalogue: GET https://agentstack.tech/mcp/actions or /agentstack-capability-matrix.


Local test

# From this repo root (provided_plugins/cursor-plugin/)
node scripts/install-local.mjs
# Cursor → Developer: Reload Window → /agentstack-init
node scripts/install-local.mjs --check
node scripts/smoke-local.mjs --install
node scripts/diagnose-local.mjs --seed-snapshot
node scripts/verify-mcp-surface-e2e.mjs # single tools/list + Postel alias
node scripts/uninstall-local.mjs

Offline CI-style:

node scripts/validate-plugin.mjs --strict-screenshots
node scripts/ci-validate.mjs

Monorepo: node provided_plugins/scripts/audit-cursor-plugin.mjs

Guides: LOCAL_INSTALL.md · data flow: FLOW.md · MCP dedupe map: monorepo docs/plugins/MCP_DEDUPE_FLOW.md

If Cursor still loads an old manifest ($schema error or duplicate MCP servers):

node scripts/refresh-cursor-runtime.mjs --fix
# then Developer: Reload Window

Docs map

DocAudience
MCP_QUICKSTART.mdAuth + call shape one-pager
FLOW.mdDevice Code → mcp.json → hooks → MCP
LOCAL_INSTALL.mdSymlink install + troubleshooting
TESTING_AND_CAPABILITIES.mdLayers, skills, agents, automated checks
VERIFICATION_CHECKLIST.mdStaging / release operator log
SHIP_TODO.mdMarketplace ship checklist
SUBMIT_FORM.mdMarketplace form paste fields
MARKETPLACE_DEMO.md60–90s demo script
PUBLISHER_TERMS_CHECK.mdPublisher Terms compliance
SECURITY.mdTokens, telemetry, reporting
CONTRIBUTING.mdSync / audit before PR
CHANGELOG.mdRelease notes

Marketplace submit

  1. Paste fields from SUBMIT_FORM.md
  2. Terms check: PUBLISHER_TERMS_CHECK.md
  3. Demo: MARKETPLACE_DEMO.md
  4. Preflight: node scripts/diagnose-local.mjs · node scripts/audit-layers.mjs

Submit URL: https://cursor.com/marketplace/publish


OAuth Device Code (summary)

  1. POST /api/oauth2/device/authorizedevice_code + user_code
  2. Browser: /activate?user_code=… → user approves
  3. Poll POST /api/oauth2/token until a long-lived PAT JWT (service_caps from Device Code scopes; usually no refresh_token)
  4. Plugin writes Authorization: Bearer … into ~/.cursor/mcp.json
  5. session-start keeps a flat capability snapshot; auto Device Code if the gate is unsigned / placeholder / service_caps=null

Full sequence diagram: FLOW.md.


Telemetry

Opt-in only. Set agentstack.sendTelemetry: true in Cursor settings to buffer usage events and flush to POST /api/telemetry/plugin. No prompt text is uploaded. Source: plugins/agentstack/hooks/scripts/post-tool-telemetry.mjs.


Git (monorepo workspace)

AgentStack/ is often not a single Git root. Commit from this directory:

cd provided_plugins/cursor-plugin
git status && git commit && git push

Marketplace publish is a copy-only sibling checkout — see monorepo docs/plugins/CURSOR_PLUGIN_PUBLISH.md.


Contributing

  1. Edit under plugins/agentstack/{rules,skills,commands,agents,hooks}/.
  2. Run node scripts/smoke-local.mjs (or pwsh scripts/smoke-local.ps1) before every PR.
  3. Do not hard-code action lists in skills — use live GET /mcp/actions.
  4. Bump plugins/agentstack/.cursor-plugin/plugin.jsonandCHANGELOG.md together.
  5. From monorepo: node provided_plugins/scripts/sync-plugin-kernel.mjs then audit-cursor-plugin.mjs.

Details: CONTRIBUTING.md.


License

MIT — see LICENSE.

About

AgentStack for Cursor: full backend ecosystem (8DNA, Rules Engine, Buffs, Payments) and 500+ MCP tools. Skills, Rules, MCP config. One API key.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

AgentStack Cursor Plugin

Turn every Cursor agent into an AgentStack-native engineer.
v0.4.18 (gen3) · Plugin MCP Connect + Device Code · one MCP tool


30-second install

# In Cursor chat:
/agentstack-init

The plugin prints a short code, opens https://agentstack.tech/activate, and after you approve writes a scoped Bearer into ~/.cursor/mcp.json. No copy-pasting API keys. (OAuth 2.1 Device Authorization Grant — RFC 8628.) Quick re-auth: /agentstack-authorize. New chats auto-open Activate when MCP is unsigned or the JWT has service_caps=null (sessionStart --from-hook).

MCP surface (0.4.18):

WhatContract
Plugin MCPplugin.jsonmcpServers: "./mcp.json" — URL-only, click Connect (G-A174)
User MCP~/.cursor/mcp.json from Device Code / session-start (hooks)
tools/listOne tool: agentstack.execute (Cursor UI may show agentstack_execute)
tools/callAccepts agentstack.executeandagentstack_execute
ActionsLive catalog: GET https://agentstack.tech/mcp/actions

Plugin mcp.json must not contain Authorization or ${AGENTSTACK_ACCESS_TOKEN} (G-A162 empty Bearer). Device Code still writes a Bearer into ~/.cursor/mcp.json. User template: mcp.example.json.


Why AgentStack

Most AI tools generate backend code. AgentStack teaches the agent to route intent to an existing platform action first, and only write code when no action fits.

You asked the agent for …Without the pluginWith the plugin
User sign-in / sign-upHandwritten JWT, sessions, bcryptauth.login + session cookie
Role-based accessCustom middleware + roles tablerbac.* + protected.* 8DNA
Persistent app dataPrisma/Drizzle + migrations8DNA project.data.* / user.data.*
Payments / subscriptionsStripe SDK from scratchpayments.* + buffs.*
RAG / semantic searchpgvector + embedding pipelinerag.* (TurboQuant, hybrid)
Cron / webhooks / signalsNew routes + queue gluescheduler.*, webhooks.*, logic.*

Layout (Cursor 2.6+)

provided_plugins/cursor-plugin/
├── .cursor-plugin/
│ ├── marketplace.json # Add marketplace / GitHub install (pluginRoot: plugins)
│ ├── listing.json # Publisher SoT (screenshots, privacy, support)
│ └── VALIDATION.md
├── plugins/agentstack/ # ← the plugin package Cursor loads
│ ├── .cursor-plugin/plugin.json
│ ├── mcp.json # URL-only plugin MCP (Connect); no Bearer placeholder
│ ├── rules/ # 9 .mdc (1 alwaysApply: agentstack-prefer)
│ ├── skills/ # 24 domains + optional solana
│ ├── commands/ # 14 slash workflows
│ ├── agents/ # 3 marketplace agents (+2 maintainer overlay)
│ ├── hooks/ # lifecycle + policy scripts
│ ├── lib/plugin-kernel/ # vendored Device Code + MCP helpers
│ └── assets/ # logos + marketplace screenshots
├── scripts/ # validate, smoke, install-local, diagnose, verify
├── docs/CAPABILITY_MATRIX.md
├── README.md · CHANGELOG.md · LICENSE
└── FLOW.md · LOCAL_INSTALL.md · MCP_QUICKSTART.md · …

5-layer product surface (inside plugins/agentstack/): rules → skills → commands → agents → hooks.
Catalog plane: live GET /mcp/actions (never hard-code action counts in skills).


First 5 minutes

  1. node scripts/install-local.mjsDeveloper: Reload Window
  2. /agentstack-authorize (or /agentstack-init) → approve at /activate
  3. /agentstack-diagnose then /agentstack-capability-matrix
  4. Optional: /agentstack-host-site for a live /s/ URL

Primary auth: click Connect on plugin MCP (G-A174) or Device Code → Bearer in ~/.cursor/mcp.json. Fallback: API key via MCP_QUICKSTART.md.


Slash commands

CommandWhat it does
/agentstack-authorizeDevice Code sign-in (no API key) — plugin auth control
/agentstack-initDevice Code auth + lean MCP write + SDK scaffold
/agentstack-loginRe-auth or switch project / scopes
/agentstack-scaffold-authMinimal login/register UI on auth.*
/agentstack-scaffold-backendRBAC + Buffs gates + AgentPay + admin panel
/agentstack-sync-schemaPrisma/Drizzle → 8DNA + FAP + Logic
/agentstack-index-docsRAG-index project markdown into my-project-docs
/agentstack-capability-matrixLive domain × actions from /mcp/actions
/agentstack-diagnoseToken, discovery, MCP surface, hooks health
/agentstack-host-sitePublish HTML/ZIP → /s/ URL
/agentstack-support-setupProject support channel binding
/agentstack-integrations-wizardIntegration Hub recipes
/agentstack-sdk-surface@agentstack/sdk / protocol pointers
/agentstack-discoverDiscover hub / Compass routing

Intent → MCP routing

Intent signalFirst port of call
login / register / sessionsauth.* (tenant app). Plugin MCP sign-in → /agentstack-authorize
permissions / rolesrbac.* + protected.* 8DNA
store / read app dataproject.data.* / user.data.*
files / blobsstorage.*
payments / creditspayments.* + wallets.* + buffs.*
chat / channelssocial.*
trials / tier gatesbuffs.*
semantic search / memoryrag.*
async reactionslogic.* rules + triggers

Live catalogue: GET https://agentstack.tech/mcp/actions or /agentstack-capability-matrix.


Local test

# From this repo root (provided_plugins/cursor-plugin/)
node scripts/install-local.mjs
# Cursor → Developer: Reload Window → /agentstack-init
node scripts/install-local.mjs --check
node scripts/smoke-local.mjs --install
node scripts/diagnose-local.mjs --seed-snapshot
node scripts/verify-mcp-surface-e2e.mjs # single tools/list + Postel alias
node scripts/uninstall-local.mjs

Offline CI-style:

node scripts/validate-plugin.mjs --strict-screenshots
node scripts/ci-validate.mjs

Monorepo: node provided_plugins/scripts/audit-cursor-plugin.mjs

Guides: LOCAL_INSTALL.md · data flow: FLOW.md · MCP dedupe map: monorepo docs/plugins/MCP_DEDUPE_FLOW.md

If Cursor still loads an old manifest ($schema error or duplicate MCP servers):

node scripts/refresh-cursor-runtime.mjs --fix
# then Developer: Reload Window

Docs map

DocAudience
MCP_QUICKSTART.mdAuth + call shape one-pager
FLOW.mdDevice Code → mcp.json → hooks → MCP
LOCAL_INSTALL.mdSymlink install + troubleshooting
TESTING_AND_CAPABILITIES.mdLayers, skills, agents, automated checks
VERIFICATION_CHECKLIST.mdStaging / release operator log
SHIP_TODO.mdMarketplace ship checklist
SUBMIT_FORM.mdMarketplace form paste fields
MARKETPLACE_DEMO.md60–90s demo script
PUBLISHER_TERMS_CHECK.mdPublisher Terms compliance
SECURITY.mdTokens, telemetry, reporting
CONTRIBUTING.mdSync / audit before PR
CHANGELOG.mdRelease notes

Marketplace submit

  1. Paste fields from SUBMIT_FORM.md
  2. Terms check: PUBLISHER_TERMS_CHECK.md
  3. Demo: MARKETPLACE_DEMO.md
  4. Preflight: node scripts/diagnose-local.mjs · node scripts/audit-layers.mjs

Submit URL: https://cursor.com/marketplace/publish


OAuth Device Code (summary)

  1. POST /api/oauth2/device/authorizedevice_code + user_code
  2. Browser: /activate?user_code=… → user approves
  3. Poll POST /api/oauth2/token until a long-lived PAT JWT (service_caps from Device Code scopes; usually no refresh_token)
  4. Plugin writes Authorization: Bearer … into ~/.cursor/mcp.json
  5. session-start keeps a flat capability snapshot; auto Device Code if the gate is unsigned / placeholder / service_caps=null

Full sequence diagram: FLOW.md.


Telemetry

Opt-in only. Set agentstack.sendTelemetry: true in Cursor settings to buffer usage events and flush to POST /api/telemetry/plugin. No prompt text is uploaded. Source: plugins/agentstack/hooks/scripts/post-tool-telemetry.mjs.


Git (monorepo workspace)

AgentStack/ is often not a single Git root. Commit from this directory:

cd provided_plugins/cursor-plugin
git status && git commit && git push

Marketplace publish is a copy-only sibling checkout — see monorepo docs/plugins/CURSOR_PLUGIN_PUBLISH.md.


Contributing

  1. Edit under plugins/agentstack/{rules,skills,commands,agents,hooks}/.
  2. Run node scripts/smoke-local.mjs (or pwsh scripts/smoke-local.ps1) before every PR.
  3. Do not hard-code action lists in skills — use live GET /mcp/actions.
  4. Bump plugins/agentstack/.cursor-plugin/plugin.jsonandCHANGELOG.md together.
  5. From monorepo: node provided_plugins/scripts/sync-plugin-kernel.mjs then audit-cursor-plugin.mjs.

Details: CONTRIBUTING.md.


License

MIT — see LICENSE.

About

AgentStack for Cursor: full backend ecosystem (8DNA, Rules Engine, Buffs, Payments) and 500+ MCP tools. Skills, Rules, MCP config. One API key.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

AgentStack Cursor Plugin

Turn every Cursor agent into an AgentStack-native engineer.
v0.4.18 (gen3) · Plugin MCP Connect + Device Code · one MCP tool


30-second install

# In Cursor chat:
/agentstack-init

The plugin prints a short code, opens https://agentstack.tech/activate, and after you approve writes a scoped Bearer into ~/.cursor/mcp.json. No copy-pasting API keys. (OAuth 2.1 Device Authorization Grant — RFC 8628.) Quick re-auth: /agentstack-authorize. New chats auto-open Activate when MCP is unsigned or the JWT has service_caps=null (sessionStart --from-hook).

MCP surface (0.4.18):

WhatContract
Plugin MCPplugin.jsonmcpServers: "./mcp.json" — URL-only, click Connect (G-A174)
User MCP~/.cursor/mcp.json from Device Code / session-start (hooks)
tools/listOne tool: agentstack.execute (Cursor UI may show agentstack_execute)
tools/callAccepts agentstack.executeandagentstack_execute
ActionsLive catalog: GET https://agentstack.tech/mcp/actions

Plugin mcp.json must not contain Authorization or ${AGENTSTACK_ACCESS_TOKEN} (G-A162 empty Bearer). Device Code still writes a Bearer into ~/.cursor/mcp.json. User template: mcp.example.json.


Why AgentStack

Most AI tools generate backend code. AgentStack teaches the agent to route intent to an existing platform action first, and only write code when no action fits.

You asked the agent for …Without the pluginWith the plugin
User sign-in / sign-upHandwritten JWT, sessions, bcryptauth.login + session cookie
Role-based accessCustom middleware + roles tablerbac.* + protected.* 8DNA
Persistent app dataPrisma/Drizzle + migrations8DNA project.data.* / user.data.*
Payments / subscriptionsStripe SDK from scratchpayments.* + buffs.*
RAG / semantic searchpgvector + embedding pipelinerag.* (TurboQuant, hybrid)
Cron / webhooks / signalsNew routes + queue gluescheduler.*, webhooks.*, logic.*

Layout (Cursor 2.6+)

provided_plugins/cursor-plugin/
├── .cursor-plugin/
│ ├── marketplace.json # Add marketplace / GitHub install (pluginRoot: plugins)
│ ├── listing.json # Publisher SoT (screenshots, privacy, support)
│ └── VALIDATION.md
├── plugins/agentstack/ # ← the plugin package Cursor loads
│ ├── .cursor-plugin/plugin.json
│ ├── mcp.json # URL-only plugin MCP (Connect); no Bearer placeholder
│ ├── rules/ # 9 .mdc (1 alwaysApply: agentstack-prefer)
│ ├── skills/ # 24 domains + optional solana
│ ├── commands/ # 14 slash workflows
│ ├── agents/ # 3 marketplace agents (+2 maintainer overlay)
│ ├── hooks/ # lifecycle + policy scripts
│ ├── lib/plugin-kernel/ # vendored Device Code + MCP helpers
│ └── assets/ # logos + marketplace screenshots
├── scripts/ # validate, smoke, install-local, diagnose, verify
├── docs/CAPABILITY_MATRIX.md
├── README.md · CHANGELOG.md · LICENSE
└── FLOW.md · LOCAL_INSTALL.md · MCP_QUICKSTART.md · …

5-layer product surface (inside plugins/agentstack/): rules → skills → commands → agents → hooks.
Catalog plane: live GET /mcp/actions (never hard-code action counts in skills).


First 5 minutes

  1. node scripts/install-local.mjsDeveloper: Reload Window
  2. /agentstack-authorize (or /agentstack-init) → approve at /activate
  3. /agentstack-diagnose then /agentstack-capability-matrix
  4. Optional: /agentstack-host-site for a live /s/ URL

Primary auth: click Connect on plugin MCP (G-A174) or Device Code → Bearer in ~/.cursor/mcp.json. Fallback: API key via MCP_QUICKSTART.md.


Slash commands

CommandWhat it does
/agentstack-authorizeDevice Code sign-in (no API key) — plugin auth control
/agentstack-initDevice Code auth + lean MCP write + SDK scaffold
/agentstack-loginRe-auth or switch project / scopes
/agentstack-scaffold-authMinimal login/register UI on auth.*
/agentstack-scaffold-backendRBAC + Buffs gates + AgentPay + admin panel
/agentstack-sync-schemaPrisma/Drizzle → 8DNA + FAP + Logic
/agentstack-index-docsRAG-index project markdown into my-project-docs
/agentstack-capability-matrixLive domain × actions from /mcp/actions
/agentstack-diagnoseToken, discovery, MCP surface, hooks health
/agentstack-host-sitePublish HTML/ZIP → /s/ URL
/agentstack-support-setupProject support channel binding
/agentstack-integrations-wizardIntegration Hub recipes
/agentstack-sdk-surface@agentstack/sdk / protocol pointers
/agentstack-discoverDiscover hub / Compass routing

Intent → MCP routing

Intent signalFirst port of call
login / register / sessionsauth.* (tenant app). Plugin MCP sign-in → /agentstack-authorize
permissions / rolesrbac.* + protected.* 8DNA
store / read app dataproject.data.* / user.data.*
files / blobsstorage.*
payments / creditspayments.* + wallets.* + buffs.*
chat / channelssocial.*
trials / tier gatesbuffs.*
semantic search / memoryrag.*
async reactionslogic.* rules + triggers

Live catalogue: GET https://agentstack.tech/mcp/actions or /agentstack-capability-matrix.


Local test

# From this repo root (provided_plugins/cursor-plugin/)
node scripts/install-local.mjs
# Cursor → Developer: Reload Window → /agentstack-init
node scripts/install-local.mjs --check
node scripts/smoke-local.mjs --install
node scripts/diagnose-local.mjs --seed-snapshot
node scripts/verify-mcp-surface-e2e.mjs # single tools/list + Postel alias
node scripts/uninstall-local.mjs

Offline CI-style:

node scripts/validate-plugin.mjs --strict-screenshots
node scripts/ci-validate.mjs

Monorepo: node provided_plugins/scripts/audit-cursor-plugin.mjs

Guides: LOCAL_INSTALL.md · data flow: FLOW.md · MCP dedupe map: monorepo docs/plugins/MCP_DEDUPE_FLOW.md

If Cursor still loads an old manifest ($schema error or duplicate MCP servers):

node scripts/refresh-cursor-runtime.mjs --fix
# then Developer: Reload Window

Docs map

DocAudience
MCP_QUICKSTART.mdAuth + call shape one-pager
FLOW.mdDevice Code → mcp.json → hooks → MCP
LOCAL_INSTALL.mdSymlink install + troubleshooting
TESTING_AND_CAPABILITIES.mdLayers, skills, agents, automated checks
VERIFICATION_CHECKLIST.mdStaging / release operator log
SHIP_TODO.mdMarketplace ship checklist
SUBMIT_FORM.mdMarketplace form paste fields
MARKETPLACE_DEMO.md60–90s demo script
PUBLISHER_TERMS_CHECK.mdPublisher Terms compliance
SECURITY.mdTokens, telemetry, reporting
CONTRIBUTING.mdSync / audit before PR
CHANGELOG.mdRelease notes

Marketplace submit

  1. Paste fields from SUBMIT_FORM.md
  2. Terms check: PUBLISHER_TERMS_CHECK.md
  3. Demo: MARKETPLACE_DEMO.md
  4. Preflight: node scripts/diagnose-local.mjs · node scripts/audit-layers.mjs

Submit URL: https://cursor.com/marketplace/publish


OAuth Device Code (summary)

  1. POST /api/oauth2/device/authorizedevice_code + user_code
  2. Browser: /activate?user_code=… → user approves
  3. Poll POST /api/oauth2/token until a long-lived PAT JWT (service_caps from Device Code scopes; usually no refresh_token)
  4. Plugin writes Authorization: Bearer … into ~/.cursor/mcp.json
  5. session-start keeps a flat capability snapshot; auto Device Code if the gate is unsigned / placeholder / service_caps=null

Full sequence diagram: FLOW.md.


Telemetry

Opt-in only. Set agentstack.sendTelemetry: true in Cursor settings to buffer usage events and flush to POST /api/telemetry/plugin. No prompt text is uploaded. Source: plugins/agentstack/hooks/scripts/post-tool-telemetry.mjs.


Git (monorepo workspace)

AgentStack/ is often not a single Git root. Commit from this directory:

cd provided_plugins/cursor-plugin
git status && git commit && git push

Marketplace publish is a copy-only sibling checkout — see monorepo docs/plugins/CURSOR_PLUGIN_PUBLISH.md.


Contributing

  1. Edit under plugins/agentstack/{rules,skills,commands,agents,hooks}/.
  2. Run node scripts/smoke-local.mjs (or pwsh scripts/smoke-local.ps1) before every PR.
  3. Do not hard-code action lists in skills — use live GET /mcp/actions.
  4. Bump plugins/agentstack/.cursor-plugin/plugin.jsonandCHANGELOG.md together.
  5. From monorepo: node provided_plugins/scripts/sync-plugin-kernel.mjs then audit-cursor-plugin.mjs.

Details: CONTRIBUTING.md.


License

MIT — see LICENSE.

About

AgentStack for Cursor: full backend ecosystem (8DNA, Rules Engine, Buffs, Payments) and 500+ MCP tools. Skills, Rules, MCP config. One API key.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

AgentStack Cursor Plugin

Turn every Cursor agent into an AgentStack-native engineer.
v0.4.18 (gen3) · Plugin MCP Connect + Device Code · one MCP tool


30-second install

# In Cursor chat:
/agentstack-init

The plugin prints a short code, opens https://agentstack.tech/activate, and after you approve writes a scoped Bearer into ~/.cursor/mcp.json. No copy-pasting API keys. (OAuth 2.1 Device Authorization Grant — RFC 8628.) Quick re-auth: /agentstack-authorize. New chats auto-open Activate when MCP is unsigned or the JWT has service_caps=null (sessionStart --from-hook).

MCP surface (0.4.18):

WhatContract
Plugin MCPplugin.jsonmcpServers: "./mcp.json" — URL-only, click Connect (G-A174)
User MCP~/.cursor/mcp.json from Device Code / session-start (hooks)
tools/listOne tool: agentstack.execute (Cursor UI may show agentstack_execute)
tools/callAccepts agentstack.executeandagentstack_execute
ActionsLive catalog: GET https://agentstack.tech/mcp/actions

Plugin mcp.json must not contain Authorization or ${AGENTSTACK_ACCESS_TOKEN} (G-A162 empty Bearer). Device Code still writes a Bearer into ~/.cursor/mcp.json. User template: mcp.example.json.


Why AgentStack

Most AI tools generate backend code. AgentStack teaches the agent to route intent to an existing platform action first, and only write code when no action fits.

You asked the agent for …Without the pluginWith the plugin
User sign-in / sign-upHandwritten JWT, sessions, bcryptauth.login + session cookie
Role-based accessCustom middleware + roles tablerbac.* + protected.* 8DNA
Persistent app dataPrisma/Drizzle + migrations8DNA project.data.* / user.data.*
Payments / subscriptionsStripe SDK from scratchpayments.* + buffs.*
RAG / semantic searchpgvector + embedding pipelinerag.* (TurboQuant, hybrid)
Cron / webhooks / signalsNew routes + queue gluescheduler.*, webhooks.*, logic.*

Layout (Cursor 2.6+)

provided_plugins/cursor-plugin/
├── .cursor-plugin/
│ ├── marketplace.json # Add marketplace / GitHub install (pluginRoot: plugins)
│ ├── listing.json # Publisher SoT (screenshots, privacy, support)
│ └── VALIDATION.md
├── plugins/agentstack/ # ← the plugin package Cursor loads
│ ├── .cursor-plugin/plugin.json
│ ├── mcp.json # URL-only plugin MCP (Connect); no Bearer placeholder
│ ├── rules/ # 9 .mdc (1 alwaysApply: agentstack-prefer)
│ ├── skills/ # 24 domains + optional solana
│ ├── commands/ # 14 slash workflows
│ ├── agents/ # 3 marketplace agents (+2 maintainer overlay)
│ ├── hooks/ # lifecycle + policy scripts
│ ├── lib/plugin-kernel/ # vendored Device Code + MCP helpers
│ └── assets/ # logos + marketplace screenshots
├── scripts/ # validate, smoke, install-local, diagnose, verify
├── docs/CAPABILITY_MATRIX.md
├── README.md · CHANGELOG.md · LICENSE
└── FLOW.md · LOCAL_INSTALL.md · MCP_QUICKSTART.md · …

5-layer product surface (inside plugins/agentstack/): rules → skills → commands → agents → hooks.
Catalog plane: live GET /mcp/actions (never hard-code action counts in skills).


First 5 minutes

  1. node scripts/install-local.mjsDeveloper: Reload Window
  2. /agentstack-authorize (or /agentstack-init) → approve at /activate
  3. /agentstack-diagnose then /agentstack-capability-matrix
  4. Optional: /agentstack-host-site for a live /s/ URL

Primary auth: click Connect on plugin MCP (G-A174) or Device Code → Bearer in ~/.cursor/mcp.json. Fallback: API key via MCP_QUICKSTART.md.


Slash commands

CommandWhat it does
/agentstack-authorizeDevice Code sign-in (no API key) — plugin auth control
/agentstack-initDevice Code auth + lean MCP write + SDK scaffold
/agentstack-loginRe-auth or switch project / scopes
/agentstack-scaffold-authMinimal login/register UI on auth.*
/agentstack-scaffold-backendRBAC + Buffs gates + AgentPay + admin panel
/agentstack-sync-schemaPrisma/Drizzle → 8DNA + FAP + Logic
/agentstack-index-docsRAG-index project markdown into my-project-docs
/agentstack-capability-matrixLive domain × actions from /mcp/actions
/agentstack-diagnoseToken, discovery, MCP surface, hooks health
/agentstack-host-sitePublish HTML/ZIP → /s/ URL
/agentstack-support-setupProject support channel binding
/agentstack-integrations-wizardIntegration Hub recipes
/agentstack-sdk-surface@agentstack/sdk / protocol pointers
/agentstack-discoverDiscover hub / Compass routing

Intent → MCP routing

Intent signalFirst port of call
login / register / sessionsauth.* (tenant app). Plugin MCP sign-in → /agentstack-authorize
permissions / rolesrbac.* + protected.* 8DNA
store / read app dataproject.data.* / user.data.*
files / blobsstorage.*
payments / creditspayments.* + wallets.* + buffs.*
chat / channelssocial.*
trials / tier gatesbuffs.*
semantic search / memoryrag.*
async reactionslogic.* rules + triggers

Live catalogue: GET https://agentstack.tech/mcp/actions or /agentstack-capability-matrix.


Local test

# From this repo root (provided_plugins/cursor-plugin/)
node scripts/install-local.mjs
# Cursor → Developer: Reload Window → /agentstack-init
node scripts/install-local.mjs --check
node scripts/smoke-local.mjs --install
node scripts/diagnose-local.mjs --seed-snapshot
node scripts/verify-mcp-surface-e2e.mjs # single tools/list + Postel alias
node scripts/uninstall-local.mjs

Offline CI-style:

node scripts/validate-plugin.mjs --strict-screenshots
node scripts/ci-validate.mjs

Monorepo: node provided_plugins/scripts/audit-cursor-plugin.mjs

Guides: LOCAL_INSTALL.md · data flow: FLOW.md · MCP dedupe map: monorepo docs/plugins/MCP_DEDUPE_FLOW.md

If Cursor still loads an old manifest ($schema error or duplicate MCP servers):

node scripts/refresh-cursor-runtime.mjs --fix
# then Developer: Reload Window

Docs map

DocAudience
MCP_QUICKSTART.mdAuth + call shape one-pager
FLOW.mdDevice Code → mcp.json → hooks → MCP
LOCAL_INSTALL.mdSymlink install + troubleshooting
TESTING_AND_CAPABILITIES.mdLayers, skills, agents, automated checks
VERIFICATION_CHECKLIST.mdStaging / release operator log
SHIP_TODO.mdMarketplace ship checklist
SUBMIT_FORM.mdMarketplace form paste fields
MARKETPLACE_DEMO.md60–90s demo script
PUBLISHER_TERMS_CHECK.mdPublisher Terms compliance
SECURITY.mdTokens, telemetry, reporting
CONTRIBUTING.mdSync / audit before PR
CHANGELOG.mdRelease notes

Marketplace submit

  1. Paste fields from SUBMIT_FORM.md
  2. Terms check: PUBLISHER_TERMS_CHECK.md
  3. Demo: MARKETPLACE_DEMO.md
  4. Preflight: node scripts/diagnose-local.mjs · node scripts/audit-layers.mjs

Submit URL: https://cursor.com/marketplace/publish


OAuth Device Code (summary)

  1. POST /api/oauth2/device/authorizedevice_code + user_code
  2. Browser: /activate?user_code=… → user approves
  3. Poll POST /api/oauth2/token until a long-lived PAT JWT (service_caps from Device Code scopes; usually no refresh_token)
  4. Plugin writes Authorization: Bearer … into ~/.cursor/mcp.json
  5. session-start keeps a flat capability snapshot; auto Device Code if the gate is unsigned / placeholder / service_caps=null

Full sequence diagram: FLOW.md.


Telemetry

Opt-in only. Set agentstack.sendTelemetry: true in Cursor settings to buffer usage events and flush to POST /api/telemetry/plugin. No prompt text is uploaded. Source: plugins/agentstack/hooks/scripts/post-tool-telemetry.mjs.


Git (monorepo workspace)

AgentStack/ is often not a single Git root. Commit from this directory:

cd provided_plugins/cursor-plugin
git status && git commit && git push

Marketplace publish is a copy-only sibling checkout — see monorepo docs/plugins/CURSOR_PLUGIN_PUBLISH.md.


Contributing

  1. Edit under plugins/agentstack/{rules,skills,commands,agents,hooks}/.
  2. Run node scripts/smoke-local.mjs (or pwsh scripts/smoke-local.ps1) before every PR.
  3. Do not hard-code action lists in skills — use live GET /mcp/actions.
  4. Bump plugins/agentstack/.cursor-plugin/plugin.jsonandCHANGELOG.md together.
  5. From monorepo: node provided_plugins/scripts/sync-plugin-kernel.mjs then audit-cursor-plugin.mjs.

Details: CONTRIBUTING.md.


License

MIT — see LICENSE.

About

AgentStack for Cursor: full backend ecosystem (8DNA, Rules Engine, Buffs, Payments) and 500+ MCP tools. Skills, Rules, MCP config. One API key.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

AgentStack Cursor Plugin

Turn every Cursor agent into an AgentStack-native engineer.
v0.4.18 (gen3) · Plugin MCP Connect + Device Code · one MCP tool


30-second install

# In Cursor chat:
/agentstack-init

The plugin prints a short code, opens https://agentstack.tech/activate, and after you approve writes a scoped Bearer into ~/.cursor/mcp.json. No copy-pasting API keys. (OAuth 2.1 Device Authorization Grant — RFC 8628.) Quick re-auth: /agentstack-authorize. New chats auto-open Activate when MCP is unsigned or the JWT has service_caps=null (sessionStart --from-hook).

MCP surface (0.4.18):

WhatContract
Plugin MCPplugin.jsonmcpServers: "./mcp.json" — URL-only, click Connect (G-A174)
User MCP~/.cursor/mcp.json from Device Code / session-start (hooks)
tools/listOne tool: agentstack.execute (Cursor UI may show agentstack_execute)
tools/callAccepts agentstack.executeandagentstack_execute
ActionsLive catalog: GET https://agentstack.tech/mcp/actions

Plugin mcp.json must not contain Authorization or ${AGENTSTACK_ACCESS_TOKEN} (G-A162 empty Bearer). Device Code still writes a Bearer into ~/.cursor/mcp.json. User template: mcp.example.json.


Why AgentStack

Most AI tools generate backend code. AgentStack teaches the agent to route intent to an existing platform action first, and only write code when no action fits.

You asked the agent for …Without the pluginWith the plugin
User sign-in / sign-upHandwritten JWT, sessions, bcryptauth.login + session cookie
Role-based accessCustom middleware + roles tablerbac.* + protected.* 8DNA
Persistent app dataPrisma/Drizzle + migrations8DNA project.data.* / user.data.*
Payments / subscriptionsStripe SDK from scratchpayments.* + buffs.*
RAG / semantic searchpgvector + embedding pipelinerag.* (TurboQuant, hybrid)
Cron / webhooks / signalsNew routes + queue gluescheduler.*, webhooks.*, logic.*

Layout (Cursor 2.6+)

provided_plugins/cursor-plugin/
├── .cursor-plugin/
│ ├── marketplace.json # Add marketplace / GitHub install (pluginRoot: plugins)
│ ├── listing.json # Publisher SoT (screenshots, privacy, support)
│ └── VALIDATION.md
├── plugins/agentstack/ # ← the plugin package Cursor loads
│ ├── .cursor-plugin/plugin.json
│ ├── mcp.json # URL-only plugin MCP (Connect); no Bearer placeholder
│ ├── rules/ # 9 .mdc (1 alwaysApply: agentstack-prefer)
│ ├── skills/ # 24 domains + optional solana
│ ├── commands/ # 14 slash workflows
│ ├── agents/ # 3 marketplace agents (+2 maintainer overlay)
│ ├── hooks/ # lifecycle + policy scripts
│ ├── lib/plugin-kernel/ # vendored Device Code + MCP helpers
│ └── assets/ # logos + marketplace screenshots
├── scripts/ # validate, smoke, install-local, diagnose, verify
├── docs/CAPABILITY_MATRIX.md
├── README.md · CHANGELOG.md · LICENSE
└── FLOW.md · LOCAL_INSTALL.md · MCP_QUICKSTART.md · …

5-layer product surface (inside plugins/agentstack/): rules → skills → commands → agents → hooks.
Catalog plane: live GET /mcp/actions (never hard-code action counts in skills).


First 5 minutes

  1. node scripts/install-local.mjsDeveloper: Reload Window
  2. /agentstack-authorize (or /agentstack-init) → approve at /activate
  3. /agentstack-diagnose then /agentstack-capability-matrix
  4. Optional: /agentstack-host-site for a live /s/ URL

Primary auth: click Connect on plugin MCP (G-A174) or Device Code → Bearer in ~/.cursor/mcp.json. Fallback: API key via MCP_QUICKSTART.md.


Slash commands

CommandWhat it does
/agentstack-authorizeDevice Code sign-in (no API key) — plugin auth control
/agentstack-initDevice Code auth + lean MCP write + SDK scaffold
/agentstack-loginRe-auth or switch project / scopes
/agentstack-scaffold-authMinimal login/register UI on auth.*
/agentstack-scaffold-backendRBAC + Buffs gates + AgentPay + admin panel
/agentstack-sync-schemaPrisma/Drizzle → 8DNA + FAP + Logic
/agentstack-index-docsRAG-index project markdown into my-project-docs
/agentstack-capability-matrixLive domain × actions from /mcp/actions
/agentstack-diagnoseToken, discovery, MCP surface, hooks health
/agentstack-host-sitePublish HTML/ZIP → /s/ URL
/agentstack-support-setupProject support channel binding
/agentstack-integrations-wizardIntegration Hub recipes
/agentstack-sdk-surface@agentstack/sdk / protocol pointers
/agentstack-discoverDiscover hub / Compass routing

Intent → MCP routing

Intent signalFirst port of call
login / register / sessionsauth.* (tenant app). Plugin MCP sign-in → /agentstack-authorize
permissions / rolesrbac.* + protected.* 8DNA
store / read app dataproject.data.* / user.data.*
files / blobsstorage.*
payments / creditspayments.* + wallets.* + buffs.*
chat / channelssocial.*
trials / tier gatesbuffs.*
semantic search / memoryrag.*
async reactionslogic.* rules + triggers

Live catalogue: GET https://agentstack.tech/mcp/actions or /agentstack-capability-matrix.


Local test

# From this repo root (provided_plugins/cursor-plugin/)
node scripts/install-local.mjs
# Cursor → Developer: Reload Window → /agentstack-init
node scripts/install-local.mjs --check
node scripts/smoke-local.mjs --install
node scripts/diagnose-local.mjs --seed-snapshot
node scripts/verify-mcp-surface-e2e.mjs # single tools/list + Postel alias
node scripts/uninstall-local.mjs

Offline CI-style:

node scripts/validate-plugin.mjs --strict-screenshots
node scripts/ci-validate.mjs

Monorepo: node provided_plugins/scripts/audit-cursor-plugin.mjs

Guides: LOCAL_INSTALL.md · data flow: FLOW.md · MCP dedupe map: monorepo docs/plugins/MCP_DEDUPE_FLOW.md

If Cursor still loads an old manifest ($schema error or duplicate MCP servers):

node scripts/refresh-cursor-runtime.mjs --fix
# then Developer: Reload Window

Docs map

DocAudience
MCP_QUICKSTART.mdAuth + call shape one-pager
FLOW.mdDevice Code → mcp.json → hooks → MCP
LOCAL_INSTALL.mdSymlink install + troubleshooting
TESTING_AND_CAPABILITIES.mdLayers, skills, agents, automated checks
VERIFICATION_CHECKLIST.mdStaging / release operator log
SHIP_TODO.mdMarketplace ship checklist
SUBMIT_FORM.mdMarketplace form paste fields
MARKETPLACE_DEMO.md60–90s demo script
PUBLISHER_TERMS_CHECK.mdPublisher Terms compliance
SECURITY.mdTokens, telemetry, reporting
CONTRIBUTING.mdSync / audit before PR
CHANGELOG.mdRelease notes

Marketplace submit

  1. Paste fields from SUBMIT_FORM.md
  2. Terms check: PUBLISHER_TERMS_CHECK.md
  3. Demo: MARKETPLACE_DEMO.md
  4. Preflight: node scripts/diagnose-local.mjs · node scripts/audit-layers.mjs

Submit URL: https://cursor.com/marketplace/publish


OAuth Device Code (summary)

  1. POST /api/oauth2/device/authorizedevice_code + user_code
  2. Browser: /activate?user_code=… → user approves
  3. Poll POST /api/oauth2/token until a long-lived PAT JWT (service_caps from Device Code scopes; usually no refresh_token)
  4. Plugin writes Authorization: Bearer … into ~/.cursor/mcp.json
  5. session-start keeps a flat capability snapshot; auto Device Code if the gate is unsigned / placeholder / service_caps=null

Full sequence diagram: FLOW.md.


Telemetry

Opt-in only. Set agentstack.sendTelemetry: true in Cursor settings to buffer usage events and flush to POST /api/telemetry/plugin. No prompt text is uploaded. Source: plugins/agentstack/hooks/scripts/post-tool-telemetry.mjs.


Git (monorepo workspace)

AgentStack/ is often not a single Git root. Commit from this directory:

cd provided_plugins/cursor-plugin
git status && git commit && git push

Marketplace publish is a copy-only sibling checkout — see monorepo docs/plugins/CURSOR_PLUGIN_PUBLISH.md.


Contributing

  1. Edit under plugins/agentstack/{rules,skills,commands,agents,hooks}/.
  2. Run node scripts/smoke-local.mjs (or pwsh scripts/smoke-local.ps1) before every PR.
  3. Do not hard-code action lists in skills — use live GET /mcp/actions.
  4. Bump plugins/agentstack/.cursor-plugin/plugin.jsonandCHANGELOG.md together.
  5. From monorepo: node provided_plugins/scripts/sync-plugin-kernel.mjs then audit-cursor-plugin.mjs.

Details: CONTRIBUTING.md.


License

MIT — see LICENSE.

About

AgentStack for Cursor: full backend ecosystem (8DNA, Rules Engine, Buffs, Payments) and 500+ MCP tools. Skills, Rules, MCP config. One API key.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

AgentStack Cursor Plugin

Turn every Cursor agent into an AgentStack-native engineer.
v0.4.18 (gen3) · Plugin MCP Connect + Device Code · one MCP tool


30-second install

# In Cursor chat:
/agentstack-init

The plugin prints a short code, opens https://agentstack.tech/activate, and after you approve writes a scoped Bearer into ~/.cursor/mcp.json. No copy-pasting API keys. (OAuth 2.1 Device Authorization Grant — RFC 8628.) Quick re-auth: /agentstack-authorize. New chats auto-open Activate when MCP is unsigned or the JWT has service_caps=null (sessionStart --from-hook).

MCP surface (0.4.18):

WhatContract
Plugin MCPplugin.jsonmcpServers: "./mcp.json" — URL-only, click Connect (G-A174)
User MCP~/.cursor/mcp.json from Device Code / session-start (hooks)
tools/listOne tool: agentstack.execute (Cursor UI may show agentstack_execute)
tools/callAccepts agentstack.executeandagentstack_execute
ActionsLive catalog: GET https://agentstack.tech/mcp/actions

Plugin mcp.json must not contain Authorization or ${AGENTSTACK_ACCESS_TOKEN} (G-A162 empty Bearer). Device Code still writes a Bearer into ~/.cursor/mcp.json. User template: mcp.example.json.


Why AgentStack

Most AI tools generate backend code. AgentStack teaches the agent to route intent to an existing platform action first, and only write code when no action fits.

You asked the agent for …Without the pluginWith the plugin
User sign-in / sign-upHandwritten JWT, sessions, bcryptauth.login + session cookie
Role-based accessCustom middleware + roles tablerbac.* + protected.* 8DNA
Persistent app dataPrisma/Drizzle + migrations8DNA project.data.* / user.data.*
Payments / subscriptionsStripe SDK from scratchpayments.* + buffs.*
RAG / semantic searchpgvector + embedding pipelinerag.* (TurboQuant, hybrid)
Cron / webhooks / signalsNew routes + queue gluescheduler.*, webhooks.*, logic.*

Layout (Cursor 2.6+)

provided_plugins/cursor-plugin/
├── .cursor-plugin/
│ ├── marketplace.json # Add marketplace / GitHub install (pluginRoot: plugins)
│ ├── listing.json # Publisher SoT (screenshots, privacy, support)
│ └── VALIDATION.md
├── plugins/agentstack/ # ← the plugin package Cursor loads
│ ├── .cursor-plugin/plugin.json
│ ├── mcp.json # URL-only plugin MCP (Connect); no Bearer placeholder
│ ├── rules/ # 9 .mdc (1 alwaysApply: agentstack-prefer)
│ ├── skills/ # 24 domains + optional solana
│ ├── commands/ # 14 slash workflows
│ ├── agents/ # 3 marketplace agents (+2 maintainer overlay)
│ ├── hooks/ # lifecycle + policy scripts
│ ├── lib/plugin-kernel/ # vendored Device Code + MCP helpers
│ └── assets/ # logos + marketplace screenshots
├── scripts/ # validate, smoke, install-local, diagnose, verify
├── docs/CAPABILITY_MATRIX.md
├── README.md · CHANGELOG.md · LICENSE
└── FLOW.md · LOCAL_INSTALL.md · MCP_QUICKSTART.md · …

5-layer product surface (inside plugins/agentstack/): rules → skills → commands → agents → hooks.
Catalog plane: live GET /mcp/actions (never hard-code action counts in skills).


First 5 minutes

  1. node scripts/install-local.mjsDeveloper: Reload Window
  2. /agentstack-authorize (or /agentstack-init) → approve at /activate
  3. /agentstack-diagnose then /agentstack-capability-matrix
  4. Optional: /agentstack-host-site for a live /s/ URL

Primary auth: click Connect on plugin MCP (G-A174) or Device Code → Bearer in ~/.cursor/mcp.json. Fallback: API key via MCP_QUICKSTART.md.


Slash commands

CommandWhat it does
/agentstack-authorizeDevice Code sign-in (no API key) — plugin auth control
/agentstack-initDevice Code auth + lean MCP write + SDK scaffold
/agentstack-loginRe-auth or switch project / scopes
/agentstack-scaffold-authMinimal login/register UI on auth.*
/agentstack-scaffold-backendRBAC + Buffs gates + AgentPay + admin panel
/agentstack-sync-schemaPrisma/Drizzle → 8DNA + FAP + Logic
/agentstack-index-docsRAG-index project markdown into my-project-docs
/agentstack-capability-matrixLive domain × actions from /mcp/actions
/agentstack-diagnoseToken, discovery, MCP surface, hooks health
/agentstack-host-sitePublish HTML/ZIP → /s/ URL
/agentstack-support-setupProject support channel binding
/agentstack-integrations-wizardIntegration Hub recipes
/agentstack-sdk-surface@agentstack/sdk / protocol pointers
/agentstack-discoverDiscover hub / Compass routing

Intent → MCP routing

Intent signalFirst port of call
login / register / sessionsauth.* (tenant app). Plugin MCP sign-in → /agentstack-authorize
permissions / rolesrbac.* + protected.* 8DNA
store / read app dataproject.data.* / user.data.*
files / blobsstorage.*
payments / creditspayments.* + wallets.* + buffs.*
chat / channelssocial.*
trials / tier gatesbuffs.*
semantic search / memoryrag.*
async reactionslogic.* rules + triggers

Live catalogue: GET https://agentstack.tech/mcp/actions or /agentstack-capability-matrix.


Local test

# From this repo root (provided_plugins/cursor-plugin/)
node scripts/install-local.mjs
# Cursor → Developer: Reload Window → /agentstack-init
node scripts/install-local.mjs --check
node scripts/smoke-local.mjs --install
node scripts/diagnose-local.mjs --seed-snapshot
node scripts/verify-mcp-surface-e2e.mjs # single tools/list + Postel alias
node scripts/uninstall-local.mjs

Offline CI-style:

node scripts/validate-plugin.mjs --strict-screenshots
node scripts/ci-validate.mjs

Monorepo: node provided_plugins/scripts/audit-cursor-plugin.mjs

Guides: LOCAL_INSTALL.md · data flow: FLOW.md · MCP dedupe map: monorepo docs/plugins/MCP_DEDUPE_FLOW.md

If Cursor still loads an old manifest ($schema error or duplicate MCP servers):

node scripts/refresh-cursor-runtime.mjs --fix
# then Developer: Reload Window

Docs map

DocAudience
MCP_QUICKSTART.mdAuth + call shape one-pager
FLOW.mdDevice Code → mcp.json → hooks → MCP
LOCAL_INSTALL.mdSymlink install + troubleshooting
TESTING_AND_CAPABILITIES.mdLayers, skills, agents, automated checks
VERIFICATION_CHECKLIST.mdStaging / release operator log
SHIP_TODO.mdMarketplace ship checklist
SUBMIT_FORM.mdMarketplace form paste fields
MARKETPLACE_DEMO.md60–90s demo script
PUBLISHER_TERMS_CHECK.mdPublisher Terms compliance
SECURITY.mdTokens, telemetry, reporting
CONTRIBUTING.mdSync / audit before PR
CHANGELOG.mdRelease notes

Marketplace submit

  1. Paste fields from SUBMIT_FORM.md
  2. Terms check: PUBLISHER_TERMS_CHECK.md
  3. Demo: MARKETPLACE_DEMO.md
  4. Preflight: node scripts/diagnose-local.mjs · node scripts/audit-layers.mjs

Submit URL: https://cursor.com/marketplace/publish


OAuth Device Code (summary)

  1. POST /api/oauth2/device/authorizedevice_code + user_code
  2. Browser: /activate?user_code=… → user approves
  3. Poll POST /api/oauth2/token until a long-lived PAT JWT (service_caps from Device Code scopes; usually no refresh_token)
  4. Plugin writes Authorization: Bearer … into ~/.cursor/mcp.json
  5. session-start keeps a flat capability snapshot; auto Device Code if the gate is unsigned / placeholder / service_caps=null

Full sequence diagram: FLOW.md.


Telemetry

Opt-in only. Set agentstack.sendTelemetry: true in Cursor settings to buffer usage events and flush to POST /api/telemetry/plugin. No prompt text is uploaded. Source: plugins/agentstack/hooks/scripts/post-tool-telemetry.mjs.


Git (monorepo workspace)

AgentStack/ is often not a single Git root. Commit from this directory:

cd provided_plugins/cursor-plugin
git status && git commit && git push

Marketplace publish is a copy-only sibling checkout — see monorepo docs/plugins/CURSOR_PLUGIN_PUBLISH.md.


Contributing

  1. Edit under plugins/agentstack/{rules,skills,commands,agents,hooks}/.
  2. Run node scripts/smoke-local.mjs (or pwsh scripts/smoke-local.ps1) before every PR.
  3. Do not hard-code action lists in skills — use live GET /mcp/actions.
  4. Bump plugins/agentstack/.cursor-plugin/plugin.jsonandCHANGELOG.md together.
  5. From monorepo: node provided_plugins/scripts/sync-plugin-kernel.mjs then audit-cursor-plugin.mjs.

Details: CONTRIBUTING.md.


License

MIT — see LICENSE.

About

AgentStack for Cursor: full backend ecosystem (8DNA, Rules Engine, Buffs, Payments) and 500+ MCP tools. Skills, Rules, MCP config. One API key.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

AgentStack Cursor Plugin

Turn every Cursor agent into an AgentStack-native engineer.
v0.4.18 (gen3) · Plugin MCP Connect + Device Code · one MCP tool


30-second install

# In Cursor chat:
/agentstack-init

The plugin prints a short code, opens https://agentstack.tech/activate, and after you approve writes a scoped Bearer into ~/.cursor/mcp.json. No copy-pasting API keys. (OAuth 2.1 Device Authorization Grant — RFC 8628.) Quick re-auth: /agentstack-authorize. New chats auto-open Activate when MCP is unsigned or the JWT has service_caps=null (sessionStart --from-hook).

MCP surface (0.4.18):

WhatContract
Plugin MCPplugin.jsonmcpServers: "./mcp.json" — URL-only, click Connect (G-A174)
User MCP~/.cursor/mcp.json from Device Code / session-start (hooks)
tools/listOne tool: agentstack.execute (Cursor UI may show agentstack_execute)
tools/callAccepts agentstack.executeandagentstack_execute
ActionsLive catalog: GET https://agentstack.tech/mcp/actions

Plugin mcp.json must not contain Authorization or ${AGENTSTACK_ACCESS_TOKEN} (G-A162 empty Bearer). Device Code still writes a Bearer into ~/.cursor/mcp.json. User template: mcp.example.json.


Why AgentStack

Most AI tools generate backend code. AgentStack teaches the agent to route intent to an existing platform action first, and only write code when no action fits.

You asked the agent for …Without the pluginWith the plugin
User sign-in / sign-upHandwritten JWT, sessions, bcryptauth.login + session cookie
Role-based accessCustom middleware + roles tablerbac.* + protected.* 8DNA
Persistent app dataPrisma/Drizzle + migrations8DNA project.data.* / user.data.*
Payments / subscriptionsStripe SDK from scratchpayments.* + buffs.*
RAG / semantic searchpgvector + embedding pipelinerag.* (TurboQuant, hybrid)
Cron / webhooks / signalsNew routes + queue gluescheduler.*, webhooks.*, logic.*

Layout (Cursor 2.6+)

provided_plugins/cursor-plugin/
├── .cursor-plugin/
│ ├── marketplace.json # Add marketplace / GitHub install (pluginRoot: plugins)
│ ├── listing.json # Publisher SoT (screenshots, privacy, support)
│ └── VALIDATION.md
├── plugins/agentstack/ # ← the plugin package Cursor loads
│ ├── .cursor-plugin/plugin.json
│ ├── mcp.json # URL-only plugin MCP (Connect); no Bearer placeholder
│ ├── rules/ # 9 .mdc (1 alwaysApply: agentstack-prefer)
│ ├── skills/ # 24 domains + optional solana
│ ├── commands/ # 14 slash workflows
│ ├── agents/ # 3 marketplace agents (+2 maintainer overlay)
│ ├── hooks/ # lifecycle + policy scripts
│ ├── lib/plugin-kernel/ # vendored Device Code + MCP helpers
│ └── assets/ # logos + marketplace screenshots
├── scripts/ # validate, smoke, install-local, diagnose, verify
├── docs/CAPABILITY_MATRIX.md
├── README.md · CHANGELOG.md · LICENSE
└── FLOW.md · LOCAL_INSTALL.md · MCP_QUICKSTART.md · …

5-layer product surface (inside plugins/agentstack/): rules → skills → commands → agents → hooks.
Catalog plane: live GET /mcp/actions (never hard-code action counts in skills).


First 5 minutes

  1. node scripts/install-local.mjsDeveloper: Reload Window
  2. /agentstack-authorize (or /agentstack-init) → approve at /activate
  3. /agentstack-diagnose then /agentstack-capability-matrix
  4. Optional: /agentstack-host-site for a live /s/ URL

Primary auth: click Connect on plugin MCP (G-A174) or Device Code → Bearer in ~/.cursor/mcp.json. Fallback: API key via MCP_QUICKSTART.md.


Slash commands

CommandWhat it does
/agentstack-authorizeDevice Code sign-in (no API key) — plugin auth control
/agentstack-initDevice Code auth + lean MCP write + SDK scaffold
/agentstack-loginRe-auth or switch project / scopes
/agentstack-scaffold-authMinimal login/register UI on auth.*
/agentstack-scaffold-backendRBAC + Buffs gates + AgentPay + admin panel
/agentstack-sync-schemaPrisma/Drizzle → 8DNA + FAP + Logic
/agentstack-index-docsRAG-index project markdown into my-project-docs
/agentstack-capability-matrixLive domain × actions from /mcp/actions
/agentstack-diagnoseToken, discovery, MCP surface, hooks health
/agentstack-host-sitePublish HTML/ZIP → /s/ URL
/agentstack-support-setupProject support channel binding
/agentstack-integrations-wizardIntegration Hub recipes
/agentstack-sdk-surface@agentstack/sdk / protocol pointers
/agentstack-discoverDiscover hub / Compass routing

Intent → MCP routing

Intent signalFirst port of call
login / register / sessionsauth.* (tenant app). Plugin MCP sign-in → /agentstack-authorize
permissions / rolesrbac.* + protected.* 8DNA
store / read app dataproject.data.* / user.data.*
files / blobsstorage.*
payments / creditspayments.* + wallets.* + buffs.*
chat / channelssocial.*
trials / tier gatesbuffs.*
semantic search / memoryrag.*
async reactionslogic.* rules + triggers

Live catalogue: GET https://agentstack.tech/mcp/actions or /agentstack-capability-matrix.


Local test

# From this repo root (provided_plugins/cursor-plugin/)
node scripts/install-local.mjs
# Cursor → Developer: Reload Window → /agentstack-init
node scripts/install-local.mjs --check
node scripts/smoke-local.mjs --install
node scripts/diagnose-local.mjs --seed-snapshot
node scripts/verify-mcp-surface-e2e.mjs # single tools/list + Postel alias
node scripts/uninstall-local.mjs

Offline CI-style:

node scripts/validate-plugin.mjs --strict-screenshots
node scripts/ci-validate.mjs

Monorepo: node provided_plugins/scripts/audit-cursor-plugin.mjs

Guides: LOCAL_INSTALL.md · data flow: FLOW.md · MCP dedupe map: monorepo docs/plugins/MCP_DEDUPE_FLOW.md

If Cursor still loads an old manifest ($schema error or duplicate MCP servers):

node scripts/refresh-cursor-runtime.mjs --fix
# then Developer: Reload Window

Docs map

DocAudience
MCP_QUICKSTART.mdAuth + call shape one-pager
FLOW.mdDevice Code → mcp.json → hooks → MCP
LOCAL_INSTALL.mdSymlink install + troubleshooting
TESTING_AND_CAPABILITIES.mdLayers, skills, agents, automated checks
VERIFICATION_CHECKLIST.mdStaging / release operator log
SHIP_TODO.mdMarketplace ship checklist
SUBMIT_FORM.mdMarketplace form paste fields
MARKETPLACE_DEMO.md60–90s demo script
PUBLISHER_TERMS_CHECK.mdPublisher Terms compliance
SECURITY.mdTokens, telemetry, reporting
CONTRIBUTING.mdSync / audit before PR
CHANGELOG.mdRelease notes

Marketplace submit

  1. Paste fields from SUBMIT_FORM.md
  2. Terms check: PUBLISHER_TERMS_CHECK.md
  3. Demo: MARKETPLACE_DEMO.md
  4. Preflight: node scripts/diagnose-local.mjs · node scripts/audit-layers.mjs

Submit URL: https://cursor.com/marketplace/publish


OAuth Device Code (summary)

  1. POST /api/oauth2/device/authorizedevice_code + user_code
  2. Browser: /activate?user_code=… → user approves
  3. Poll POST /api/oauth2/token until a long-lived PAT JWT (service_caps from Device Code scopes; usually no refresh_token)
  4. Plugin writes Authorization: Bearer … into ~/.cursor/mcp.json
  5. session-start keeps a flat capability snapshot; auto Device Code if the gate is unsigned / placeholder / service_caps=null

Full sequence diagram: FLOW.md.


Telemetry

Opt-in only. Set agentstack.sendTelemetry: true in Cursor settings to buffer usage events and flush to POST /api/telemetry/plugin. No prompt text is uploaded. Source: plugins/agentstack/hooks/scripts/post-tool-telemetry.mjs.


Git (monorepo workspace)

AgentStack/ is often not a single Git root. Commit from this directory:

cd provided_plugins/cursor-plugin
git status && git commit && git push

Marketplace publish is a copy-only sibling checkout — see monorepo docs/plugins/CURSOR_PLUGIN_PUBLISH.md.


Contributing

  1. Edit under plugins/agentstack/{rules,skills,commands,agents,hooks}/.
  2. Run node scripts/smoke-local.mjs (or pwsh scripts/smoke-local.ps1) before every PR.
  3. Do not hard-code action lists in skills — use live GET /mcp/actions.
  4. Bump plugins/agentstack/.cursor-plugin/plugin.jsonandCHANGELOG.md together.
  5. From monorepo: node provided_plugins/scripts/sync-plugin-kernel.mjs then audit-cursor-plugin.mjs.

Details: CONTRIBUTING.md.


License

MIT — see LICENSE.

About

AgentStack for Cursor: full backend ecosystem (8DNA, Rules Engine, Buffs, Payments) and 500+ MCP tools. Skills, Rules, MCP config. One API key.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

AgentStack Cursor Plugin

Turn every Cursor agent into an AgentStack-native engineer.
v0.4.18 (gen3) · Plugin MCP Connect + Device Code · one MCP tool


30-second install

# In Cursor chat:
/agentstack-init

The plugin prints a short code, opens https://agentstack.tech/activate, and after you approve writes a scoped Bearer into ~/.cursor/mcp.json. No copy-pasting API keys. (OAuth 2.1 Device Authorization Grant — RFC 8628.) Quick re-auth: /agentstack-authorize. New chats auto-open Activate when MCP is unsigned or the JWT has service_caps=null (sessionStart --from-hook).

MCP surface (0.4.18):

WhatContract
Plugin MCPplugin.jsonmcpServers: "./mcp.json" — URL-only, click Connect (G-A174)
User MCP~/.cursor/mcp.json from Device Code / session-start (hooks)
tools/listOne tool: agentstack.execute (Cursor UI may show agentstack_execute)
tools/callAccepts agentstack.executeandagentstack_execute
ActionsLive catalog: GET https://agentstack.tech/mcp/actions

Plugin mcp.json must not contain Authorization or ${AGENTSTACK_ACCESS_TOKEN} (G-A162 empty Bearer). Device Code still writes a Bearer into ~/.cursor/mcp.json. User template: mcp.example.json.


Why AgentStack

Most AI tools generate backend code. AgentStack teaches the agent to route intent to an existing platform action first, and only write code when no action fits.

You asked the agent for …Without the pluginWith the plugin
User sign-in / sign-upHandwritten JWT, sessions, bcryptauth.login + session cookie
Role-based accessCustom middleware + roles tablerbac.* + protected.* 8DNA
Persistent app dataPrisma/Drizzle + migrations8DNA project.data.* / user.data.*
Payments / subscriptionsStripe SDK from scratchpayments.* + buffs.*
RAG / semantic searchpgvector + embedding pipelinerag.* (TurboQuant, hybrid)
Cron / webhooks / signalsNew routes + queue gluescheduler.*, webhooks.*, logic.*

Layout (Cursor 2.6+)

provided_plugins/cursor-plugin/
├── .cursor-plugin/
│ ├── marketplace.json # Add marketplace / GitHub install (pluginRoot: plugins)
│ ├── listing.json # Publisher SoT (screenshots, privacy, support)
│ └── VALIDATION.md
├── plugins/agentstack/ # ← the plugin package Cursor loads
│ ├── .cursor-plugin/plugin.json
│ ├── mcp.json # URL-only plugin MCP (Connect); no Bearer placeholder
│ ├── rules/ # 9 .mdc (1 alwaysApply: agentstack-prefer)
│ ├── skills/ # 24 domains + optional solana
│ ├── commands/ # 14 slash workflows
│ ├── agents/ # 3 marketplace agents (+2 maintainer overlay)
│ ├── hooks/ # lifecycle + policy scripts
│ ├── lib/plugin-kernel/ # vendored Device Code + MCP helpers
│ └── assets/ # logos + marketplace screenshots
├── scripts/ # validate, smoke, install-local, diagnose, verify
├── docs/CAPABILITY_MATRIX.md
├── README.md · CHANGELOG.md · LICENSE
└── FLOW.md · LOCAL_INSTALL.md · MCP_QUICKSTART.md · …

5-layer product surface (inside plugins/agentstack/): rules → skills → commands → agents → hooks.
Catalog plane: live GET /mcp/actions (never hard-code action counts in skills).


First 5 minutes

  1. node scripts/install-local.mjsDeveloper: Reload Window
  2. /agentstack-authorize (or /agentstack-init) → approve at /activate
  3. /agentstack-diagnose then /agentstack-capability-matrix
  4. Optional: /agentstack-host-site for a live /s/ URL

Primary auth: click Connect on plugin MCP (G-A174) or Device Code → Bearer in ~/.cursor/mcp.json. Fallback: API key via MCP_QUICKSTART.md.


Slash commands

CommandWhat it does
/agentstack-authorizeDevice Code sign-in (no API key) — plugin auth control
/agentstack-initDevice Code auth + lean MCP write + SDK scaffold
/agentstack-loginRe-auth or switch project / scopes
/agentstack-scaffold-authMinimal login/register UI on auth.*
/agentstack-scaffold-backendRBAC + Buffs gates + AgentPay + admin panel
/agentstack-sync-schemaPrisma/Drizzle → 8DNA + FAP + Logic
/agentstack-index-docsRAG-index project markdown into my-project-docs
/agentstack-capability-matrixLive domain × actions from /mcp/actions
/agentstack-diagnoseToken, discovery, MCP surface, hooks health
/agentstack-host-sitePublish HTML/ZIP → /s/ URL
/agentstack-support-setupProject support channel binding
/agentstack-integrations-wizardIntegration Hub recipes
/agentstack-sdk-surface@agentstack/sdk / protocol pointers
/agentstack-discoverDiscover hub / Compass routing

Intent → MCP routing

Intent signalFirst port of call
login / register / sessionsauth.* (tenant app). Plugin MCP sign-in → /agentstack-authorize
permissions / rolesrbac.* + protected.* 8DNA
store / read app dataproject.data.* / user.data.*
files / blobsstorage.*
payments / creditspayments.* + wallets.* + buffs.*
chat / channelssocial.*
trials / tier gatesbuffs.*
semantic search / memoryrag.*
async reactionslogic.* rules + triggers

Live catalogue: GET https://agentstack.tech/mcp/actions or /agentstack-capability-matrix.


Local test

# From this repo root (provided_plugins/cursor-plugin/)
node scripts/install-local.mjs
# Cursor → Developer: Reload Window → /agentstack-init
node scripts/install-local.mjs --check
node scripts/smoke-local.mjs --install
node scripts/diagnose-local.mjs --seed-snapshot
node scripts/verify-mcp-surface-e2e.mjs # single tools/list + Postel alias
node scripts/uninstall-local.mjs

Offline CI-style:

node scripts/validate-plugin.mjs --strict-screenshots
node scripts/ci-validate.mjs

Monorepo: node provided_plugins/scripts/audit-cursor-plugin.mjs

Guides: LOCAL_INSTALL.md · data flow: FLOW.md · MCP dedupe map: monorepo docs/plugins/MCP_DEDUPE_FLOW.md

If Cursor still loads an old manifest ($schema error or duplicate MCP servers):

node scripts/refresh-cursor-runtime.mjs --fix
# then Developer: Reload Window

Docs map

DocAudience
MCP_QUICKSTART.mdAuth + call shape one-pager
FLOW.mdDevice Code → mcp.json → hooks → MCP
LOCAL_INSTALL.mdSymlink install + troubleshooting
TESTING_AND_CAPABILITIES.mdLayers, skills, agents, automated checks
VERIFICATION_CHECKLIST.mdStaging / release operator log
SHIP_TODO.mdMarketplace ship checklist
SUBMIT_FORM.mdMarketplace form paste fields
MARKETPLACE_DEMO.md60–90s demo script
PUBLISHER_TERMS_CHECK.mdPublisher Terms compliance
SECURITY.mdTokens, telemetry, reporting
CONTRIBUTING.mdSync / audit before PR
CHANGELOG.mdRelease notes

Marketplace submit

  1. Paste fields from SUBMIT_FORM.md
  2. Terms check: PUBLISHER_TERMS_CHECK.md
  3. Demo: MARKETPLACE_DEMO.md
  4. Preflight: node scripts/diagnose-local.mjs · node scripts/audit-layers.mjs

Submit URL: https://cursor.com/marketplace/publish


OAuth Device Code (summary)

  1. POST /api/oauth2/device/authorizedevice_code + user_code
  2. Browser: /activate?user_code=… → user approves
  3. Poll POST /api/oauth2/token until a long-lived PAT JWT (service_caps from Device Code scopes; usually no refresh_token)
  4. Plugin writes Authorization: Bearer … into ~/.cursor/mcp.json
  5. session-start keeps a flat capability snapshot; auto Device Code if the gate is unsigned / placeholder / service_caps=null

Full sequence diagram: FLOW.md.


Telemetry

Opt-in only. Set agentstack.sendTelemetry: true in Cursor settings to buffer usage events and flush to POST /api/telemetry/plugin. No prompt text is uploaded. Source: plugins/agentstack/hooks/scripts/post-tool-telemetry.mjs.


Git (monorepo workspace)

AgentStack/ is often not a single Git root. Commit from this directory:

cd provided_plugins/cursor-plugin
git status && git commit && git push

Marketplace publish is a copy-only sibling checkout — see monorepo docs/plugins/CURSOR_PLUGIN_PUBLISH.md.


Contributing

  1. Edit under plugins/agentstack/{rules,skills,commands,agents,hooks}/.
  2. Run node scripts/smoke-local.mjs (or pwsh scripts/smoke-local.ps1) before every PR.
  3. Do not hard-code action lists in skills — use live GET /mcp/actions.
  4. Bump plugins/agentstack/.cursor-plugin/plugin.jsonandCHANGELOG.md together.
  5. From monorepo: node provided_plugins/scripts/sync-plugin-kernel.mjs then audit-cursor-plugin.mjs.

Details: CONTRIBUTING.md.


License

MIT — see LICENSE.

About

AgentStack for Cursor: full backend ecosystem (8DNA, Rules Engine, Buffs, Payments) and 500+ MCP tools. Skills, Rules, MCP config. One API key.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages