Open a private security advisory on the repository, or email the maintainers listed on the latest release. Do not file a public issue for a key leak, auth bypass, or host-pinning failure.
- Store a Cursor API key in git, npm, or plugin config.
- Send
repostogether with a named Cursor-hosted cloud environment. - Follow redirects off
api.cursor.com. - Download artifacts or permanently delete agents in the default tool set.
- Interpolate run result text into a shell command line.
- Put
CURSOR_API_KEYin the OpenClaw gateway environment (systemdEnvironmentFile, secret manager, or your host equivalent). The plugin only reads the variable named byapiKeyEnv. - Keep
apiBaseUrlonhttps://api.cursor.comunless you are running the test suite withCURSOR_CLOUD_ALLOW_INSECURE_HOST=1. - Register environments by id. The model must not invent
env.type/env.namepayloads. - Treat
IDLEas “follow-ups accepted,” not “the change is good.” Readproof.prUrlson the run record. - Do not put secrets in Cloud prompts,
envVars, issues, or notify text.
Default tools: launch, reply, status, cancel, watch, me, envs, agents.
Optional tools (must be allowlisted): list, models.
The local agent JSON stores bc-… ids, env/project/repo, and run status — not API keys or prompt text.
Not shipped: archive, delete, artifact download URLs, GitHub repo listing.