Read-only delegate to cursor-agent (Composer) for questions, investigation, design discussion, and adversarial sanity checks.

MITAuto-check: notesDevelopment

Install Cursor Ask

skills CLI
$ npx skills add Chachamaru127/claude-code-harness --skill cursor-ask -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Chachamaru127/claude-code-harness cursor-ask --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Chachamaru127/claude-code-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cursor-ask .claude/skills/cursor-ask && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cursor-ask
GitHub stars
3.2k
Token cost
~1.9k tokens
SKILL.md length
391 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
MIT

At a glance

Read-only delegate to cursor-agent (Composer) for questions, investigation, design discussion, and adversarial sanity checks.

  • Works in 4 steps: 起動時 banner + plan → banner 確認 → helper root 解決 + cursor-companion 直接実行 → …
  • User says: ask cursor
  • SKILL.md covers Quick Reference, Narration Rules (UX Contract), Execution Flow and Trust Boundary, plus 2 more sections
  • Calls bash

What it does

Cursor Ask is an agent skill from Chachamaru127/claude-code-harness. Read-only delegate to cursor-agent (Composer) for questions, investigation, design discussion, and adversarial sanity checks. No worktree, no cherry-pick, no Lead diff review — cursor-agent is locked to ask mode and cannot write. Use when user says: ask cursor, cursor sanity check, get a second opinion, adversarial review, design discussion, investigate with cursor, cursor:ask. Do NOT load for: implementation, refactor, file edits, commit/push work, anything requiring write access (use cursor:do or breezing…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Git worktrees. The repository describes itself as: Claude Code Dedicated Development Harness - Achieving High-Quality Development Through an Autonomous Plan→Work→Review Cycle. The licence is MIT.

When your agent uses it

  • User says: ask cursor
  • Cursor sanity check
  • Get a second opinion
  • Adversarial review

Example prompts

  • “/cursor-ask”

Requirements

  • Pre-approved tools (allowed-tools): Read, Bash

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. 起動時 banner + plan
  2. banner 確認
  3. helper root 解決 + cursor-companion 直接実行
  4. 結果を host が 3-5 行で要約

What it can do on your machine

Read from SKILL.md and the folder at commit 2b2b748. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cursor Ask loads about 1.9k tokens when it runs. Until then it costs about 136 tokens; SKILL.md has 391 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~136
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:158
    | Secret 遮断 | `.cursorignore` で `.env` / `*.pem` / `*.key` / `.ssh` / `.aws` / `.git` を読取対象から除外 | repo root `.cursorigno
  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Chachamaru127/claude-code-harness at commit 2b2b748, republished under its MIT licence (© Chachamaru127). 391 words, ~1,863 tokens.

Download SKILL.mdSave it as .claude/skills/cursor-ask/SKILL.md (or your agent's skills folder).
name
cursor-ask
description
Read-only delegate to cursor-agent (Composer) for questions, investigation, design discussion, and adversarial sanity checks. No worktree, no cherry-pick, no Lead diff review — cursor-agent is locked to ask mode and cannot write. Use when user says: ask cursor, cursor sanity check, get a second opinion, adversarial review, design discussion, investigate with cursor, cursor:ask. Do NOT load for: implementation, refactor, file edits, commit/push work, anything requiring write access (use cursor:do or breezing --cursor instead).
allowed-tools
Read, Bash
description-en
Read-only delegate to cursor-agent (Composer) for questions, investigation, design discussion, and adversarial sanity checks. No worktree, no cherry-pick, no…
description-ja
cursor-agent (Composer) への読み取り専用デリゲート。質問・調査・設計相談・敵対的視点(sanity check)用。worktree 不要、cherry-pick 不要、Lead diff review 不要。cursor は ask mode 固定で書き込み不可。Use when user…
argument-hint
[question]
user-invocable
true

cursor:ask — Read-Only Cursor Delegate

cursor-agent (Composer) に read-only で質問・調査・設計相談・敵対的レビューを委譲する軽量スキル。

cursor-companion.sh task は引数なしで --mode ask (hard read-only stop) が自動で付くため、--write を渡さない限り cursor 側は ファイル書き込み・コマンド実行ができない。これにより worktree 隔離・cherry-pick・Lead diff review がすべて不要になる。

Quick Reference

bash
cursor:ask "この設計判断、Composer 視点でどう思う?"
cursor:ask "TASK_BASE_REF からの diff を読んで、根拠のある見落としがあれば最大 3 つ挙げて"
cursor:ask "harness-mem の cross-project N-call、楽観的すぎる前提はある?"

用途:

ケース例
質問"この型エラーの根本原因は?"
調査"scripts/ 配下で curl を使ってる箇所を全部挙げて理由付きで"
設計相談"この abstraction、3 年後に保守できる?"
敵対的視点"この PR の最大の弱点を 1 つだけ挙げて"

Narration Rules (UX Contract)

敵は 冗長さ であって進捗報告ではない。起動時に何を聞くか・どう進めるかを簡潔に明示してから実行する。冗長な繰り返し・中身のない前置きだけを禁ずる。

起動時に必ず出すもの (banner + plan、3 行以内)
🚀 cursor / composer-2.5-fast / ask
これから: <質問の要点> を composer に投げて、結果を 3-5 行で要約

banner 1 行 + 計画 1-2 行。1 秒以内に出し、即 Step 2 へ。

進捗報告は出してよい
  • 委譲開始の 1 行 (→ composer に問い合わせ中)
  • 判断に必要な経緯を 1 行で
禁止 (= 冗長さ)
  • 同じ事実の 2 回言い換え: cursor-companion の結果を後段で再説明しない
  • 中身のない前置き: 「使い方を確認します」だけの行など tool call で自明な宣言
  • 3 行以上の経緯振り返り: 必要なら 1 行に圧縮
  • 起動シーケンス中の ★ Insight ブロック: Insight は最終要約で 1 回のみ

違反例 (冗長):

× 「cursor に質問を投げる準備をします」→ bash → 「投げます」(中身のない前置き + 言い換え)
× 「ask モードは読み取り専用なので安全です」と再説明(既知事実の繰り返し)
× ★ Insight ──── まず cursor の状態を確認します: ...

正常例 (簡潔 + 計画明示):

🚀 cursor / composer-2.5-fast / ask
これから: 設計の弱点を composer に問い、結果を 3-5 行で要約

Execution Flow

Step 0: 起動時 banner + plan

上記 Narration Rules に従い、banner + 計画 (3 行以内) を出してから Step 1 へ。

Step 1: banner 確認

Step 0 で banner + 計画 (3 行以内) は出し切っているので、ここでは banner 行が出ていることを確認する。banner は:

🚀 cursor / composer-2.5-fast / ask

以降は委譲開始の 1 行ステータス等で進捗を見せてよい。冗長な繰り返しのみ避ける。

composer-2.5-fast は scripts/model-routing.sh --host cursor --role worker --field model で解決される値の代表表記。実際の resolved model は cursor-companion 側のログに出る。

Step 2: helper root 解決 + cursor-companion 直接実行

$ARGUMENTS を質問文として渡す。--write は絶対に付けない。scripts/cursor-companion.sh を相対パスで呼ぶと consumer repo の cwd 直下に見えず exit するため、CLAUDE_PLUGIN_ROOT / HARNESS_PLUGIN_ROOT を hooks.json と同じ valid_root パターンで解決する (Issue #193 §2): 質問の目的、対象、既知の根拠を質問本文に添え、結論の理由と検証可能な証拠を求める。内部の思考過程は求めない。

bash
QUESTION="$ARGUMENTS"
if [ -z "$QUESTION" ]; then
  echo "ERROR: question required. Usage: cursor:ask \"<your question>\"" >&2
  exit 1
fi

bash -c '
  set -euo pipefail
  valid_root() {
    [ -n "${1:-}" ] && [ -f "$1/scripts/cursor-companion.sh" ] && { [ -f "$1/.claude-plugin/plugin.json" ] || [ -f "$1/.codex-plugin/plugin.json" ] || [ -f "$1/.cursor-plugin/plugin.json" ]; }
  }
  HARNESS_PLUGIN_ROOT="${HARNESS_PLUGIN_ROOT:-${CLAUDE_PLUGIN_ROOT:-}}"
  ROOT="$HARNESS_PLUGIN_ROOT"
  if ! valid_root "$ROOT"; then
    ROOT=""
    if [ -n "${CLAUDE_SKILL_DIR:-}" ]; then
      probe="$(cd "${CLAUDE_SKILL_DIR}" && pwd)"
      while [ "$probe" != "/" ] && ! valid_root "$probe"; do
        probe="$(cd "$probe/.." && pwd)"
      done
      valid_root "$probe" && ROOT="$probe"
    fi
  fi
  if ! valid_root "$ROOT"; then
    ROOT=""
    for c in "${CLAUDE_PROJECT_DIR:-}" "$PWD" \
             "$HOME/.claude/plugins/marketplaces/claude-code-harness-marketplace" \
             "$HOME/.claude/plugins/cache/claude-code-harness-marketplace/claude-code-harness/"*; do
      if valid_root "$c"; then ROOT="$c"; break; fi
    done
  fi
  if ! valid_root "$ROOT"; then
    echo "ERROR: claude-code-harness plugin root not found (no scripts/cursor-companion.sh)" >&2
    exit 2
  fi
  HARNESS_PLUGIN_ROOT="$ROOT"
  bash "${HARNESS_PLUGIN_ROOT}/scripts/cursor-companion.sh" task "$1"
' _ "$QUESTION"

これだけで cursor-agent 側は --mode ask (hard read-only stop) に locked される。--force / --yolo も付かない。

Step 3: 結果を host が 3-5 行で要約

cursor の出力をそのまま貼らない。host (Claude/Codex) が読んで 3-5 行に要約 する:

  • 結論
  • なぜそう言えるか (cursor が挙げた根拠の核)
  • 注意点 / 追加調査が必要な点
  • 次の一手 (もしあれば)

最終回答は実際の結論、参照箇所、未確認点を返す。「これから要約する」という予告だけで終了しない。 助言は現物と照合して採否を判断し、相談だけの依頼から実装を開始しない。

Trust Boundary

cursor は不透明なサブプロセスであり、Harness のガードレール (R01-R13) は内部に適用されない。read-only 委譲でも以下の前提条件を満たすこと。

Show full SKILL.md (159 more words)Show less
必須前提
項目内容設定場所
Secret 遮断.cursorignore で .env / *.pem / *.key / .ssh / .aws / .git を読取対象から除外repo root .cursorignore
Egress allowlist~/.claude/settings.json の sandbox.network.allowedDomains に *.cursor.sh を追加user settings
Filesystem allowlist同 sandbox.filesystem.allowWrite に ~/.cursor を追加 (cursor-agent が状態書込を行うため)user settings
permissions.json~/.cursor/permissions.json の terminalAllowlist / mcpAllowlist は read mode でも有効 (allowlist は best-effort、security boundary ではない)user config

詳細は .claude/rules/cursor-cli-only.md を参照。

ask mode で省略できるもの
通常の cursor 委譲で必要ask mode では不要理由
隔離 worktree不要cursor は書き込みできない
Lead diff review不要差分が生まれない
cherry-pick不要同上
worker-report.v1 / self_review 5 件不要実装をしないため
それでも残るリスク
  • 読み取り漏洩: .cursorignore を怠ると秘密ファイルが cursor 推論に渡る
  • 誤った情報の鵜呑み: cursor 出力は untrusted。Step 3 の要約で必ず host が判断軸を残す
  • allowlist 過信: Cursor 公式は "Allowlists are best-effort convenience. They are not a security guarantee." と明言。allowlist に依存しない

Topology

Lead (Claude/Codex) ──[cursor-companion.sh task]──> cursor-agent (--mode ask, locked read-only)
       │
       └──[Step 3: 3-5 行要約]──> User

Worker 介在なし。Reviewer 介在なし。worker-report.v1 / review-result.v1 契約は発生しない。

  • cursor-do — 書込タスク委譲(worktree + Lead review + cherry-pick の full containment)
  • breezing --cursor — Reviewer のみ cursor に逃がす lean second-opinion レーン
  • harness-review --cursor — レビューを cursor (composer-2.5-fast) に second-opinion として依頼
  • .claude/rules/cursor-cli-only.md — Cursor backend governance (trust boundary, prohibited flags)

© Chachamaru127, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cursor-ask of Chachamaru127/claude-code-harness.

Open the folder on GitHubat commit 2b2b748

Compare with similar skills

Cursor Ask next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cursor Ask compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cursor Ask this skillChachamaru127/claude-code-harness3.2k—~1.9kAutomated safety check: NotesMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Migrate Core Code to Submodulestinyhumansai/openhuman41k—~2.6kAutomated safety check: PassGPL-3.0
Finishing A Development Branchfarm-fe/farm5.6k33 repos~1.8kAutomated safety check: PassMIT
Git Worktree Cleanuplobehub/lobehub83k—~2.8kAutomated safety check: PassCustom licence
Keep Codex Fastvibeforge1111/keep-codex-fast1.6k—~3.1kAutomated safety check: PassMIT

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Migrate Core Code to Submodules

    tinyhumansai/openhuman

    Plans and carries out moving non-host-specific code and its tests from the OpenHuman core into vendored tiny submodule libraries, then releases the submodule and re-pins the host.

    41k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed
  • A skill your agent uses when implementation is complete, all tests pass, and you need to decide how to integrate the work - guides completion of development work by presenting structured options for…

    5.6k GitHub starsUsed in 33 repos~1.8k tokens
    DevelopmentAuto-check passed
  • Git Worktree Cleanup

    lobehub/lobehub

    Audits stale Git worktrees and branches with a bundled script, classifies each one, and deletes only after you approve the exact candidates.

    83k GitHub stars~2.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Keep Codex Fast

    vibeforge1111/keep-codex-fast

    A skill your agent uses when Codex feels slow or bloated, when local sessions/logs/worktrees/config have grown over time, or when a user wants safe maintenance for Codex Desktop/CLI state.

    1.6k GitHub stars~3.1k tokensUpdated 5 mo ago
    DevelopmentAuto-check passed
  • Pre-Release PR Triage

    jamiepine/voicebox

    Sorts a backlog of open pull requests into must-merge, candidate, superseded and deferred, writes a triage doc and works the merge loop before a release.

    57k GitHub stars~3.1k tokensUpdated today
    DevelopmentAuto-check passed

More from Chachamaru127/claude-code-harness

All 25 skills in this repo
  • CI Failure Triage and Repair

    Chachamaru127/claude-code-harness

    Diagnoses failing CI pipelines and tests, deciding first whether the test or the implementation is at fault, and hands hard cases to a dedicated fixer subagent.

    3.2k GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check: notes
  • Cursor Composer Task Delegate

    Chachamaru127/claude-code-harness

    Hands one implementation task to Cursor Composer in an isolated git worktree, then reviews its diff and cherry-picks the result into the main branch.

    3.2k GitHub stars~4.4k tokensUpdated 2 days ago
    Auto-check: notes
  • Acceptance Demo Generator

    Chachamaru127/claude-code-harness

    Renders a single HTML page showing each acceptance criterion as verified or not, with a ship, wait, or reject recommendation for non-engineers.

    3.2k GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check: notes
  • Harness Long-Running Task Loop

    Chachamaru127/claude-code-harness

    Repeats a long task as a series of scheduled wake-ups, each re-entering with fresh context and calling harness-work for one task per cycle.

    3.2k GitHub stars~2.3k tokensUpdated 2 days ago
    Auto-check: notes
  • Harness Plan

    Chachamaru127/claude-code-harness

    Creates and maintains Plans.md task plans with a spec delta, updates task markers and syncs plan progress with the implementation.

    3.2k GitHub stars~3.7k tokensUpdated 2 days ago
    Auto-check: notes
  • Harness Release

    Chachamaru127/claude-code-harness

    Runs a release for any project that keeps a Keep a Changelog file on GitHub, from version bump to merge, tag and GitHub Release after a single approval.

    3.2k GitHub stars~4.4k tokensUpdated 2 days ago
    Auto-check: notes

Categories

Questions about Cursor Ask

What does Cursor Ask do?

Read-only delegate to cursor-agent (Composer) for questions, investigation, design discussion, and adversarial sanity checks. Cursor Ask is an agent skill from Chachamaru127/claude-code-harness. Read-only delegate to cursor-agent (Composer) for questions, investigation, design discussion, and adversarial sanity checks.

When should I use Cursor Ask?

Cursor Ask fits situations like: user says: ask cursor; Cursor sanity check; get a second opinion; adversarial review.

How do I install Cursor Ask in Claude Code?

Run `npx skills add Chachamaru127/claude-code-harness --skill cursor-ask -a claude-code`. Or copy the skill folder (skills/cursor-ask in Chachamaru127/claude-code-harness) into .claude/skills/cursor-ask in your project. Claude Code loads it when a task matches its description.

How do I install Cursor Ask in Codex?

Run `npx skills add Chachamaru127/claude-code-harness --skill cursor-ask -a codex`. Or copy the skill folder (skills/cursor-ask in Chachamaru127/claude-code-harness) into .agents/skills/cursor-ask in your project. Codex loads it when a task matches its description.

Can I use Cursor Ask in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Chachamaru127/claude-code-harness --skill cursor-ask -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cursor-ask, .gemini/skills/cursor-ask, .github/skills/cursor-ask and .opencode/skills/cursor-ask in your project.

What does Cursor Ask need to run?

Going by SKILL.md and its folder, Cursor Ask needs the command-line tools its instructions call (bash). Its frontmatter pre-approves these tools: Read, Bash.

Does Cursor Ask access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cursor Ask safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Cursor Ask use?

Cursor Ask is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cursor Ask use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cursor Ask?

Skills that share tags, products or a category with Cursor Ask: Finishing a Development Branch (obra/superpowers, 296k stars), Migrate Core Code to Submodules (tinyhumansai/openhuman, 41k stars), Finishing A Development Branch (farm-fe/farm, 5.6k stars) and Git Worktree Cleanup (lobehub/lobehub, 83k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cursor Ask?

Chachamaru127 (a GitHub user) maintains it in Chachamaru127/claude-code-harness, which has 3,153 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on October 5, 2026.

Source: Chachamaru127/claude-code-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.