Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/quickerhub/quicker-rpc/cursor-sdkgit clone --depth 1 https://github.com/QuickerHub/quicker-rpcWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/quickerhub/quicker-rpc/cursor-sdk)<a href="https://agentmods.dev/commands/quickerhub/quicker-rpc/cursor-sdk"><img src="https://agentmods.dev/badge/commands/quickerhub/quicker-rpc/cursor-sdk.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00935 |
| Opus 5 | $0.00000 | $0.00467 |
| Sonnet 5 | $0.00000 | $0.00187 |
| Haiku 4.5 | $0.00000 | $0.00093 |
Grade A, and why
cursor-sdk scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 84 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Cursor SDK — quicker-rpc 脚本化 Agent
在仓库根目录用 @cursor/sdk 跑 authoring benchmark(L3 刻意练习)。计费与 IDE 同一套餐(Dashboard 里标 SDK 分项)。
动作级学习(pattern / 动作库 / skill)用
/learn-authoring;命令选型见/cursor-cli(索引页)。
一次性配置
- API Key:Cursor Dashboard → API Keys
$env:CURSOR_API_KEY = "key_..."
# 或持久化到 scripts/sdk/.env(gitignore)
- qkrpc + Quicker 插件(benchmark 必开)
qkrpc wait --json
qkrpc agent setup --upgrade
- 安装 SDK 依赖
pwsh -NoProfile -File ./scripts/Invoke-CursorSdk.ps1 -Script install
常用命令
| 场景 | 命令 |
|---|---|
| 冒烟(仅读仓库) | pwsh ./scripts/Invoke-CursorSdk.ps1 -Minimal |
| 冒烟 + qkrpc MCP | pwsh ./scripts/Invoke-CursorSdk.ps1 -WithQkrpc |
| 单条 benchmark | pwsh ./scripts/Invoke-CursorSdk.ps1 -Script benchmark -TaskId discover-step-expr |
| L2 写动作 | pwsh ./scripts/Invoke-CursorSdk.ps1 -Script benchmark -TaskId clip-lines-expr |
| L2 + 真实宿主 F 轴 | 先运行 benchmark,再用 qkrpc action run --id <guid> --debug --wait --json 验证 |
| L2 主干批量 | pwsh ./scripts/Invoke-CursorSdk.ps1 -Script benchmark-batch -Preset l2-core -Limit 3 |
| JSON 结果 | 加 -Json;落盘 .local/cursor-sdk/<task>-<ts>.json |
| 类型检查 | pwsh ./scripts/Invoke-CursorSdk.ps1 -Script check |
npm(已 dot-source env):
. ./scripts/cursor-agent-env.ps1
cd scripts/sdk
npm run benchmark -- clip-lines-expr --json
npm run benchmark:batch -- --preset l2-core --limit 1
真实 Quicker 验证(F 轴)
npm run benchmark -- multi-var-assign --json
qkrpc action run --id <guid> --debug --wait --json
MCP 场景优先调用 qkrpc_action_debug 并检查真实步骤 trace 与返回值;表单、文件选择、窗口等交互任务在 Quicker UI 中验证。
固定模型:$env:CURSOR_SDK_MODEL = "composer-2.5"(默认可 auto)。
Headless 注意
- qkrpc MCP 在
config.tsinline;autoReview: false(否则 headless 无法批 MCP)。 - 默认不加载
settingSources;benchmark 规则见benchmark-prompt.ts。 - IDE 同款 rules/skills:
$env:CURSOR_SDK_SETTING_SOURCES = "project,user"
目录
| 路径 | 作用 |
|---|---|
scripts/sdk/src/config.ts |
repo 根、qkrpc 路径、MCP |
scripts/sdk/src/run-benchmark-task.ts |
单任务 |
scripts/sdk/src/run-benchmark-batch.ts |
批量 |
scripts/Invoke-CursorSdk.ps1 |
包装脚本 |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 84 lines · 0 tokens per session scan A 37d670d3c8b5
cursor-sdk is a command published in the GitHub repository QuickerHub/quicker-rpc (13 stars, last pushed 20d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 935 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
review
Review current changes for correctness, style, and potential issues.
dumpmt
Displays details about method tables (MethodTable).
extend
Capture a mid-PR sub-idea and implement it onto the current open PR's branch — no new branch, no new PR. Preserves Verify → Review → Deliver.
security-review
Depth-first security audit of the current git diff — OWASP Top 10, secret leakage, insecure-by-default APIs, and language-specific foot-guns. Pass a PR number to audit a specific PR's diff.
sync
Bring the current branch up to date with the default branch — delegates the mechanical merge/rebase to rimba (or git), then walks through any conflicts file-by-file with a recommended resolution before applying. Never auto-pushes. Pass --rebase to rebase instead of merge. Pass --check-redundancy to also surface…
pre-ship
Run the pre-ship quality gate checklist before publishing your agent.