Cursor Agent Poisoning
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Server capabilities have not been inspected yet.
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| say_helloD | |
| anythingD | |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 2 tools
The two tools have completely different and unclear purposes. 'anything' has a vague description suggesting it's just for ambiance, while 'say_hello' contains encoded instructions and demands to be read. There is no clear functional distinction between them, making them highly ambiguous and likely to cause misselection.
The naming is inconsistent with mixed conventions. 'anything' uses a generic noun with no verb, while 'say_hello' uses a verb_noun pattern. This lack of a predictable naming pattern makes the tool set confusing and harder for agents to understand.
With only 2 tools, the server feels thin and under-scoped for any meaningful domain. The tools do not appear to work together coherently, suggesting an insufficient tool surface that limits agent capabilities.
The server lacks a clear domain or purpose, making it impossible to assess coverage meaningfully. The tools do not form a complete or logical set, with 'anything' being trivial and 'say_hello' containing hidden instructions, resulting in severe incompleteness for any practical use.