Skip to content

Commit 34130b7

Browse files
feat: add agent surfaces for Cursor, Windsurf, Gemini CLI (#121)
* feat: add agent surfaces for Cursor, Windsurf, Gemini CLI Three new pull-request drift checks, the same shape #68 established for Copilot: rules/context, skills and MCP configuration are files that arrive by pull request, so each is a status check rather than a session hook. Each path list was verified against current vendor documentation rather than assumed from the issue's own table, per #78's own instruction, and that changed the design in both directions: - Cursor: .cursor/rules/*.mdc is measured one level deep only, since Cursor's own forum documents nested rule files as not reliably read. Skills, by contrast, are measured anywhere in the tree, since Cursor's docs describe monorepo-scoped skill roots as intentional. - Windsurf: caught mid-rebrand from Cognition's Devin acquisition. .devin/rules/ is now preferred over .windsurf/rules/, verified directly against docs.windsurf.com's redirect to docs.devin.ai, but the skills surface has not moved the same way as of this writing, verified separately rather than assumed. Windsurf has no repository-resident MCP surface at all (home-directory only), so that engine ships with no mcp category. - Gemini CLI: GEMINI.md is measured anywhere in the tree per the documented context hierarchy; MCP configuration lives in .gemini/settings.json, digested whole rather than parsed for the one key that matters, the same tradeoff Copilot's engine makes for devcontainer.json. All three share agentrust-capture-core, wire up tests + integrity CI workflows matching the Copilot pattern's pinned action SHAs, and ship empty approved baselines in this repo for self-check dogfooding. 152 tests passing across all engines in this repo; no collisions with existing capture-core consumers. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Signed-off-by: oluwajuwon omotayo <ginuxtechacademy@gmail.com> * fix(cursor): recurse .cursor/rules and measure AGENTS.md Direct confirmation against cursor.com/docs (Customize > Rules, Customize > MCP) corrected two things the earlier forum/blog-sourced research got wrong: - .cursor/rules/*.mdc was globbed one level only, based on a forum report that nested rule files were unreliable. The official docs show nested folders as an intended pattern (.cursor/rules/frontend/components.mdc, presented as normal organisation, not an edge case), so a real nested rule file was silently not tracked for drift. Now globs recursively. - AGENTS.md was missing entirely. It's one of exactly four documented Cursor rule types ("a simple alternative to .cursor/rules"), read from the project root and subdirectories, with "Nested AGENTS.md support" as a shipped improvement. Now measured anywhere in the tree, same as Copilot's engine already does for the same file. .cursorrules and the .cursor/mcp.json / ~/.cursor/mcp.json split are both confirmed accurate as originally shipped; only the citations changed from secondary-source hedging to direct doc references. .cursorrules itself does not appear in current docs at all (four rule types are listed and it isn't one of them), so its README note now says that plainly rather than repeating an unconfirmed forum deprecation claim. 28 tests now (was 24): the flipped nested-mdc assertion plus four new AGENTS.md/plain-.md-extension cases. Full repo suite still green (156 tests across all five engines), self-check baseline still passes clean. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Signed-off-by: oluwajuwon omotayo <ginuxtechacademy@gmail.com> * docs(cursor): confirm skills paths directly against cursor.com/docs The skills implementation (root-anywhere-in-tree, recursive category subfolders, the four skill roots) turned out to already match Cursor's official docs (Customize > Skills) exactly, unlike rules and AGENTS.md in the previous commit. No logic change here, just upgrading the citations from secondary-source hedging to a direct doc reference, and adding one honest gap to the README: Cursor's built-in skills (/automate, /babysit, etc.) ship with the product itself, not as repository files, so they're correctly out of scope for a file-based check. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Signed-off-by: oluwajuwon omotayo <ginuxtechacademy@gmail.com> * docs(cursor): trim the .cursorrules note to what's actually confirmed The previous wording cited "no staff confirmation" from Cursor's community forum as if the forum had been checked broadly. Only one thread was actually checked, once. Trimmed the claim to what's verifiable: .cursorrules is absent from current docs, and whether Cursor still reads it is unconfirmed either way, full stop. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Signed-off-by: oluwajuwon omotayo <ginuxtechacademy@gmail.com> * docs(cursor): reflect community consensus that .cursorrules still works Additional research (independent of the earlier single forum thread) turned up several converging community sources describing .cursorrules as still read today, applied globally, just deprioritised in favour of .cursor/rules .mdc files. Still not confirmed by any official Cursor source, so the note says exactly that rather than treating it as settled. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Signed-off-by: oluwajuwon omotayo <ginuxtechacademy@gmail.com> --------- Signed-off-by: oluwajuwon omotayo <ginuxtechacademy@gmail.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
1 parent 09d4dd0 commit 34130b7

28 files changed

Lines changed: 2554 additions & 16 deletions

‎.agentrust/cursor-baseline.json‎

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
{
2+
"captured_at": "2026-08-16T06:22:53Z",
3+
"scope": 1,
4+
"observed": [
5+
"rules",
6+
"skills",
7+
"mcp"
8+
],
9+
"rules": {},
10+
"skills": {},
11+
"mcp": {}
12+
}
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
{
2+
"captured_at": "2026-08-16T06:22:53Z",
3+
"scope": 1,
4+
"observed": [
5+
"context",
6+
"skills",
7+
"mcp"
8+
],
9+
"context": {},
10+
"skills": {},
11+
"mcp": {}
12+
}

‎.agentrust/windsurf-baseline.json‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
{
2+
"captured_at": "2026-08-16T06:22:53Z",
3+
"scope": 1,
4+
"observed": [
5+
"rules",
6+
"skills"
7+
],
8+
"rules": {},
9+
"skills": {}
10+
}
Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
name: Cursor integrity
2+
3+
on:
4+
pull_request:
5+
6+
permissions:
7+
contents: read
8+
9+
jobs:
10+
verify:
11+
runs-on: ubuntu-latest
12+
steps:
13+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
14+
with:
15+
persist-credentials: false
16+
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
17+
with:
18+
python-version: "3.12"
19+
- name: Verify the approved Cursor composition
20+
uses: ./cursor
21+
with:
22+
# Keep fork pull requests read-only. The job summary carries the same
23+
# result without requiring pull-requests: write.
24+
comment: "false"
25+
fail-on-drift: "true"

‎.github/workflows/cursor-tests.yml‎

Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,50 @@
1+
name: cursor tests
2+
3+
on:
4+
pull_request:
5+
paths:
6+
- "cursor/**"
7+
- ".github/workflows/cursor-tests.yml"
8+
push:
9+
branches: [main]
10+
paths:
11+
- "cursor/**"
12+
- ".github/workflows/cursor-tests.yml"
13+
14+
permissions:
15+
contents: read
16+
17+
jobs:
18+
tests:
19+
runs-on: ubuntu-latest
20+
strategy:
21+
matrix:
22+
python-version: ["3.9", "3.11", "3.12", "3.13"]
23+
steps:
24+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
25+
with:
26+
persist-credentials: false
27+
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
28+
with:
29+
python-version: ${{ matrix.python-version }}
30+
- name: Run the suite against the core in this checkout
31+
run: |
32+
pip install ./packages/agentrust-capture-core pytest
33+
cd cursor
34+
python -m pytest tests -q
35+
36+
self-check:
37+
runs-on: ubuntu-latest
38+
steps:
39+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
40+
with:
41+
persist-credentials: false
42+
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
43+
with:
44+
python-version: "3.12"
45+
- name: Install the core from this checkout
46+
run: pip install ./packages/agentrust-capture-core
47+
- name: Snapshot this repository's Cursor composition
48+
run: python cursor/engine/capture.py snapshot
49+
- name: Verify against the committed baseline
50+
run: python cursor/engine/capture.py verify
Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
name: Gemini CLI integrity
2+
3+
on:
4+
pull_request:
5+
6+
permissions:
7+
contents: read
8+
9+
jobs:
10+
verify:
11+
runs-on: ubuntu-latest
12+
steps:
13+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
14+
with:
15+
persist-credentials: false
16+
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
17+
with:
18+
python-version: "3.12"
19+
- name: Verify the approved Gemini CLI composition
20+
uses: ./gemini-cli
21+
with:
22+
# Keep fork pull requests read-only. The job summary carries the same
23+
# result without requiring pull-requests: write.
24+
comment: "false"
25+
fail-on-drift: "true"
Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,50 @@
1+
name: gemini-cli tests
2+
3+
on:
4+
pull_request:
5+
paths:
6+
- "gemini-cli/**"
7+
- ".github/workflows/gemini-cli-tests.yml"
8+
push:
9+
branches: [main]
10+
paths:
11+
- "gemini-cli/**"
12+
- ".github/workflows/gemini-cli-tests.yml"
13+
14+
permissions:
15+
contents: read
16+
17+
jobs:
18+
tests:
19+
runs-on: ubuntu-latest
20+
strategy:
21+
matrix:
22+
python-version: ["3.9", "3.11", "3.12", "3.13"]
23+
steps:
24+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
25+
with:
26+
persist-credentials: false
27+
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
28+
with:
29+
python-version: ${{ matrix.python-version }}
30+
- name: Run the suite against the core in this checkout
31+
run: |
32+
pip install ./packages/agentrust-capture-core pytest
33+
cd gemini-cli
34+
python -m pytest tests -q
35+
36+
self-check:
37+
runs-on: ubuntu-latest
38+
steps:
39+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
40+
with:
41+
persist-credentials: false
42+
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
43+
with:
44+
python-version: "3.12"
45+
- name: Install the core from this checkout
46+
run: pip install ./packages/agentrust-capture-core
47+
- name: Snapshot this repository's Gemini CLI composition
48+
run: python gemini-cli/engine/capture.py snapshot
49+
- name: Verify against the committed baseline
50+
run: python gemini-cli/engine/capture.py verify
Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
name: Windsurf integrity
2+
3+
on:
4+
pull_request:
5+
6+
permissions:
7+
contents: read
8+
9+
jobs:
10+
verify:
11+
runs-on: ubuntu-latest
12+
steps:
13+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
14+
with:
15+
persist-credentials: false
16+
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
17+
with:
18+
python-version: "3.12"
19+
- name: Verify the approved Windsurf composition
20+
uses: ./windsurf
21+
with:
22+
# Keep fork pull requests read-only. The job summary carries the same
23+
# result without requiring pull-requests: write.
24+
comment: "false"
25+
fail-on-drift: "true"
Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,50 @@
1+
name: windsurf tests
2+
3+
on:
4+
pull_request:
5+
paths:
6+
- "windsurf/**"
7+
- ".github/workflows/windsurf-tests.yml"
8+
push:
9+
branches: [main]
10+
paths:
11+
- "windsurf/**"
12+
- ".github/workflows/windsurf-tests.yml"
13+
14+
permissions:
15+
contents: read
16+
17+
jobs:
18+
tests:
19+
runs-on: ubuntu-latest
20+
strategy:
21+
matrix:
22+
python-version: ["3.9", "3.11", "3.12", "3.13"]
23+
steps:
24+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
25+
with:
26+
persist-credentials: false
27+
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
28+
with:
29+
python-version: ${{ matrix.python-version }}
30+
- name: Run the suite against the core in this checkout
31+
run: |
32+
pip install ./packages/agentrust-capture-core pytest
33+
cd windsurf
34+
python -m pytest tests -q
35+
36+
self-check:
37+
runs-on: ubuntu-latest
38+
steps:
39+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
40+
with:
41+
persist-credentials: false
42+
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
43+
with:
44+
python-version: "3.12"
45+
- name: Install the core from this checkout
46+
run: pip install ./packages/agentrust-capture-core
47+
- name: Snapshot this repository's Windsurf composition
48+
run: python windsurf/engine/capture.py snapshot
49+
- name: Verify against the committed baseline
50+
run: python windsurf/engine/capture.py verify

‎README.md‎

Lines changed: 19 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -49,11 +49,12 @@ TRACE only works as a standard if it is genuinely neutral. Integrations are list
4949
| [scheduled-agents](scheduled-agents/) | agentrust-io | trace | community |
5050
<!-- integration-index:end -->
5151

52-
The [Copilot drift check](copilot/) is intentionally outside this manifest index:
53-
it emits neither TRACE nor Agent Manifest today, so it cannot truthfully select
54-
an `integrates_with` value from the current schema. See the note below.
52+
The [Copilot](copilot/), [Cursor](cursor/), [Windsurf](windsurf/) and
53+
[Gemini CLI](gemini-cli/) drift checks are intentionally outside this manifest
54+
index: none of them emit TRACE or Agent Manifest today, so none can truthfully
55+
select an `integrates_with` value from the current schema. See the note below.
5556

56-
All four engines share [`agentrust-capture-core`](packages/agentrust-capture-core),
57+
All seven engines share [`agentrust-capture-core`](packages/agentrust-capture-core),
5758
which owns fingerprinting, comparison, baseline sealing and the report honesty rules.
5859

5960
Adapters that build a Trust Record from evidence **another system produced** share
@@ -62,22 +63,24 @@ carry `origin.kind: third-party-control-plane`, `runtime.platform: software-only
6263
`appraisal.status: none`, so the assurance downgrade is something a consumer reads from
6364
the record rather than from a README. None of the three is a parameter.
6465

65-
**Note on the Copilot entry.** It is a pull-request status check rather than a
66-
session hook, because Copilot's composition lives in the repository. It emits no
67-
TRACE record and no Agent Manifest, so it claims neither: `integrates_with` offers
68-
only `cmcp`, `trace` and `agent-manifest`, and asserting one today would be an
69-
unverifiable claim.
66+
**Note on the Copilot, Cursor, Windsurf and Gemini CLI entries.** Each is a
67+
pull-request status check rather than a session hook, because all four agents'
68+
composition lives in the repository rather than a developer's home directory.
69+
Each emits no TRACE record and no Agent Manifest, so each claims neither:
70+
`integrates_with` offers only `cmcp`, `trace` and `agent-manifest`, and asserting
71+
one today would be an unverifiable claim.
7072

7173
That is currently blocked on a spec question rather than on implementation, tracked
7274
in [agent-manifest#256](https://github.com/agentrust-io/agent-manifest/issues/256).
73-
TRACE describes an execution and this check describes a composition, so a TRACE
75+
TRACE describes an execution and these checks describe a composition, so a TRACE
7476
record is the wrong artifact. Agent Manifest is the right one, but every level
75-
requires `artifacts.model_identity`, and a repository cannot know the model: Copilot
76-
picks it at session time from the user's plan and settings. The same repository
77-
serves every model, with an identical contributed composition. Manufacturing a
78-
model to satisfy the field would be exactly the kind of unverifiable claim
79-
`CONTRIBUTING.md` rules out, so the integration ships without one until the spec
80-
has a way to express a composition whose model is unknowable at authoring time.
77+
requires `artifacts.model_identity`, and a repository cannot know the model: each
78+
of these agents picks it at session time from the user's own plan and settings.
79+
The same repository serves every model, with an identical contributed composition.
80+
Manufacturing a model to satisfy the field would be exactly the kind of
81+
unverifiable claim `CONTRIBUTING.md` rules out, so all four integrations ship
82+
without one until the spec has a way to express a composition whose model is
83+
unknowable at authoring time.
8184

8285
## Community
8386

0 commit comments

Comments
 (0)