Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Delegate a coding task to the Cursor Agent CLI (`cursor-agent`) as a background implementer, then review its diff and land it yourself. Use this whenever the user wants to hand implementation work to Cursor — phrasings like "have Cursor implement X", "delegate this to Cursor", "run it through Cursor Agent", or "use Cursor to implement/fix/refactor" — or wants to run a queue of coding tasks through Cursor while staying the reviewer. DO NOT USE for tasks small enough to do inline, or when the user
.claude/skills/amelnagdy-cursor-delegate/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-07 | ✗→✓ | ▲ Improved | 31% | 0% |
| case-08 | ✗→✓ | ▲ Improved | 9% | 0% |
| case-09 | ✗→✓ | ▲ Improved | 174% | 0% |
| case-10 | ✗→✓ | ▲ Improved | 29% | 0% |
| case-11 | ✗→✓ | ▲ Improved | 20% | 0% |
You are the orchestrator. Hand a bounded coding task to a separate implementer — the Cursor Agent CLI — then review what it produced and land it yourself. You write the brief and own the judgment; Cursor does the typing in its own session; you verify and commit.
The loop needs only a shell command and file access, so any comparable orchestrator can drive it.
cursor-agent CLI is not installed or authenticated (run cursor-agent login).--read-only dispatch covers that — see below — but a plain review may not need delegation at all).
cursor-agent --version succeeds. If not, follow the installer for your platform atcursor.com/cli, inspect what it will run, and authenticate with cursor-agent login.
cursor-agent status shows you logged in.--cd at) the target git repository. The relay passes --trust, sopoint it only at repositories you trust.
Omitting --model uses your Cursor default (usually auto — Cursor picks). To pin one, pass --model <name> with a name from the account's live cursor-agent models output — select from that list rather than inventing a name. Parameterized forms like <name>[context=1m,effort=high] are forwarded as-is. The model that actually served the run is recorded as resolvedModel in result.json.
Run these five steps per task. Steps 1, 4, and 5 require judgment; 2 and 3 are mechanical.
Cursor sees only the text you send plus what it can inspect in the workspace — no chat history or shared context. Include the goal, current state, what to change, what to leave untouched, the project's actual gates, and a report contract. Tell Cursor not to commit. Keep one task per brief. See references/writing-the-brief.md.
Use the bundled helper. It wraps cursor-agent -p, feeds the brief on stdin, captures the structured event stream, and writes result.json. (<skill-dir> is the installed folder containing this SKILL.md.)
bashnode "<skill-dir>/scripts/relay.mjs" --brief brief.txt --cd /path/to/repo # read-only (plan mode — review/diagnosis, no edits): add --read-only # write-capable without automatic command approval: add --no-force # explicitly override Cursor's sandbox for this run: add --sandbox enabled|disabled # pin a model from `cursor-agent models`: add --model <name> # resume the most recent session: add --resume-last (delta brief only) # resume a specific session: add --session <id> (delta brief only) # hard time limit (watchdog): add --timeout 2h (the 30m default suits short runs; implementation briefs routinely need 1-2h) # see all options: node .../relay.mjs --help
The child process's cwd pins the workspace. On Cursor 2026.07.23 or newer, use repeatable --add-dir flags only for extra workspace directories. The relay writes artifacts under the system temp dir by default and never commits. See references/dispatch-and-poll.md.
The helper blocks until Cursor finishes. Run it with the orchestrator's background-command facility, or background it in the shell and poll for result.json. A pre-run usage error exits 2 and writes no result; a missing cursor-agent exits 127 and writes status: "cursor_agent_unavailable".
Trust process state and the working tree over a progress display. Completion means the process exited and result.json exists. Cursor's full report is the finalMessage field in result.json (also printed in full on stdout between the report markers).
Windows + hooks caveat: if the user has Cursor hooks configured (~/.cursor/hooks.json, or Claude Code PreToolUse hooks, which cursor-agent imports), dispatching from a Git Bash (MSYS) console makes cursor-agent feed PowerShell-syntax hook wrappers to bash, so every command Cursor tries to run is blocked — edits still land, gates do not run. Dispatch from a PowerShell or cmd console instead. Details: references/dispatch-and-poll.md.
Treat Cursor's final message and gate claims as claims:
touchedFiles.See references/review-and-land.md.
The implementer edits the working tree; the orchestrator commits. Commit only after the gates pass and the diff holds. If rework is needed, send a delta brief with --resume-last or --session <id>, then review again.
A fresh run defaults to write-capable with --force: Cursor runs commands without approval unless your Cursor config explicitly denies them, so ordinary gates (tests, linters, builds) run headlessly. --no-force keeps the run write-capable but withholds automatic command approval; commands that require approval are refused because a headless run cannot prompt. --read-only switches to Cursor's plan mode (read-only analysis, no edits, no --force). The relay always passes --trust to keep headless runs from stalling on the workspace-trust prompt, which is why --cd must only ever point at repositories you trust. Pass --sandbox enabled or --sandbox disabled only when you need to override Cursor's sandbox for that dispatch. The requested value is recorded as sandbox in result.json; it does not claim what Cursor actually applied. The permission mode Cursor reports is recorded as permissionMode; inspect touchedFiles and the diff after every run.
--read-only doubles as a clean way to get an adversarial second opinion with no write risk: dispatch a brief that lists the agreed points, then each contested point with both positions, and ask Cursor to defend or concede each — deliverable in its final message, touching no files.
Delegation is something the human opts into. Once they have ("run this queue", "proceed"), committing verified, gate-passing work is the agreed contract. Two limits remain: surface, don't absorb (report Cursor's design decisions, defensible-but-unasked turns, and non-blocking nitpicks) and stop for scope changes (if correct completion needs going beyond the brief, ask instead of expanding the mandate). See references/review-and-land.md.
real gates, and delta briefs.
result.json, polling, and failure recovery.
and rework through Cursor sessions.
carry-forward, progress tracking, and the final coherence pass.
Other measured skills in the registry, with their headline benchmark lift.