ADLC
Integrations

Cursor

Native ADLC integration for Cursor: marketplace plugin with sessionStart context, preToolUse rails, packaged prosecutor agents + MCP one-root channel (rebind unverified), /adlc-* commands, and CI as the backstop.

ADLC in Cursor

Wire the Agentic Development Lifecycle into Cursor using its native plugin surfaces: hooks, rules, skills, commands, agents, and MCP. The integration ships as plugins/adlc-cursor with a Cursor marketplace manifest (.cursor-plugin/) plus an npm scaffolder kept as a legacy/dev fallback.

Status

Marketplace plugin shipped (hooks/commands/skills/rules). The MCP one-root channel is proven; rebind and live multi-root refusal remain unverified. Prosecutor agents are packaged-but-unverified until AC10 fan-out proof. A live deny-proof harness lives under scripts/cursor-deny-proof/ (result pending maintainer run).

What you get

  • sessionStart — ticket/rails context injection (best-effort) + session id env.
  • preToolUse dispatcher — rails first; Task spawn allowlist during P5.
  • afterFileEdit / beforeShellExecution — observational / advisory only.
  • preCompact + subagentStart / subagentStop — compaction reminder + P5 defense-in-depth.
  • stop / beforeSubmitPrompt — on by default.
  • MCP Roots proxy — mcp.json asks Cursor to expand ${CURSOR_PLUGIN_ROOT} and launch the bundled wrapper, which then runs adlc mcp-server (adlc_gate / adlc_prosecute) after Roots resolution. Cursor Desktop 3.20.10 live proof confirms expansion in args and cwd, startup without plugin-cache node_modules or a consumer shim, and a roots/list response. The post-fix run bound, exposed adlc_gate and adlc_prosecute, and returned ok / exitCode: 0 for adlc_gate gate-manifest show. The decoder accepts both file:// and bare absolute Root paths. It requires a global @adlc/cli installation resolvable by Cursor's Node/npm environment, without launching a Windows .cmd shim.
  • Prosecutor agents — agents/prosecutor-* with readonly: true; prefer Task fan-out.
  • Command palette — /adlc-* including one-flow /adlc-init.

The buildgate is advisory, disabled by default (ADLC_BUILD_GATE_ENFORCEMENT=1) and has NO unbypassable backstop.

Install

Preferred: marketplace plugin

  1. In Cursor: Settings → Plugins → Add marketplace and paste https://github.com/voodootikigod/adlc (marketplace adlc-plugins, plugin ADLC for Cursor / adlc-cursor).
  2. Install the plugin.
  3. Run /adlc-init, or:
npm install -g @adlc/cli
adlc init --harness cursor

Do not require npx @adlc/cursor for normal users. Do not commit a generated .adlc/config.json into a repo that already freezes that path.

  1. Wire docs/ci/rails-guard.yml as a required check.

Scaffolder one-liner: npm package

npm install -g @adlc/cli
npx @adlc/cursor .

An existing .adlc/config.json is never rewritten; if it is not a JSON object (empty, malformed, or an array), the scaffolder reports it as unreadable and exits 1 instead of counting it as present.

Rail enforcement: two layers

  1. In-session (advisory). permission: "deny" is best-effort; failClosed: false.
  2. Commit-time (unbypassable). CI docs/ci/rails-guard.yml reads rails from the trusted base ref. Make it a required check.

Formal ADLC coverage

PhaseSurface in Cursor
P0 Triage/adlc-ticket authors a ticket into .adlc/tickets.json
P1 Interrogate/adlc-spec · /adlc-approve-spec
P2 Decompose/adlc-decompose
P3 RailpreToolUse dispatcher + CI rails-guard
P4 Build/adlc-verify-build
P5 Prosecute/adlc-prosecute + packaged agents (Task fan-out preferred; sequential is degraded fallback with weaker independence) + adversarial-review --providers
P6 Integrateadlc gate-manifest
P7 Distill/adlc-distill

Gaps

  • Live deny-proof — harness at scripts/cursor-deny-proof/; dated ADR result pending.
  • MCP rebind and live ambiguity unverified — expansion, bundle boot, one-root binding, and both MCP tools are proven. roots/list_changed rebind and live multi-root refusal remain unverified.
  • Prosecutor agents packaged-but-unverified — agents-backed claim waits on fan-out proof. Sequential same-context remains a degraded fallback with weaker independence.
  • buildgate has no unbypassable backstop.
  • Marketplace publish — human submit; see publish checklist in docs/integrations/cursor.md. Do not fabricate a live listing URL.
  • Shell writes are advisory-only.

Go deeper

Design rationale: ADR 0006. Source: plugins/adlc-cursor/.

On this page