You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Let agents consume request_secret via Shell (secretRef → env/stdin)
#17266
request_secret returns a one-use secretRef, but today the only tool that accepts it is schedule_task webhook signature.secretRef.
Agents (Cursor harness via T3) naturally try to pass secretRef into Shell for things like:
sudo / NetworkManager (nmcli connection up …)
one-off API tokens for a single command
git / gh auth that should not land in chat
That fails: Cursor Shell has no secretRef parameter, and T3 does not expose a secret-consuming shell/exec tool. The private paste card works, then the ref is stranded.
Desired behavior
After request_secret → { status: "saved", secretRef }, an agent should be able to run a host command with the secret injected without the model ever seeing the value, with output redaction.
Consume the one-use secretRef the same way webhook signatures do
Never put the secret in argv in a way that shows up in process lists if avoidable (prefer env / stdin / SUDO_ASKPASS)
Redact the secret (and common encodings) from stdout/stderr before returning to the model
Document it in request_secret (“e.g. run_with_secret / Shell”) and orchestration instructions
Why not only webhook signatures?
Webhook signing is a narrow case. The paste-card UX is already general-purpose; agents hit the gap as soon as they need elevated host actions or short-lived credentials.
Alternatives considered
Ask the user to run sudo … in a real terminal (works; breaks hands-off agent loops)
NOPASSWD / polkit for specific commands (works for known commands; not a general secret path)
Paste secrets into chat (explicitly discouraged by request_secret)
Ask
Is this direction something maintainers would approve for an Ideas → implementation PR? Happy to take a focused MCP tool first (without changing Cursor’s native Shell schema), if that’s the preferred boundary.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Problem
request_secretreturns a one-usesecretRef, but today the only tool that accepts it isschedule_taskwebhooksignature.secretRef.Agents (Cursor harness via T3) naturally try to pass
secretRefinto Shell for things like:sudo/ NetworkManager (nmcli connection up …)git/ghauth that should not land in chatThat fails: Cursor Shell has no
secretRefparameter, and T3 does not expose a secret-consuming shell/exec tool. The private paste card works, then the ref is stranded.Desired behavior
After
request_secret→{ status: "saved", secretRef }, an agent should be able to run a host command with the secret injected without the model ever seeing the value, with output redaction.Concrete sketch (name flexible):
Requirements that matter:
secretRefthe same way webhook signatures doSUDO_ASKPASS)request_secret(“e.g.run_with_secret/ Shell”) and orchestration instructionsWhy not only webhook signatures?
Webhook signing is a narrow case. The paste-card UX is already general-purpose; agents hit the gap as soon as they need elevated host actions or short-lived credentials.
Alternatives considered
sudo …in a real terminal (works; breaks hands-off agent loops)request_secret)Ask
Is this direction something maintainers would approve for an Ideas → implementation PR? Happy to take a focused MCP tool first (without changing Cursor’s native Shell schema), if that’s the preferred boundary.
All reactions