IAF Agent Bridge
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| IAF_PERMISSION_MODE | No | Reject force-push, history rewrite, destructive SQL, deletes outside the project, and secret staging unless you explicitly set IAF_PERMISSION_MODE=allow-all. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| delegateA | Send a prompt to Cursor Agent and wait until that Cursor turn is terminal, including tool work and any sub-agent follow-up Cursor performs before it stops. Returns Cursor's reply and the sessionId to reuse. A second call for a session that is still running is rejected. You decide CONTINUE, COMPLETE, or BLOCKED. Do not shell out to the agent binary. |
| cancelA | Cancel an in-flight Cursor turn by sessionId. Status is cancelled, killed, not-running (the turn ended and the session can still be resumed), or not-found. |
| doctorA | Report Node, bridge version, Cursor CLI discovery, authentication state without secrets, and an optional ACP handshake. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 3 tools
Each tool has a clearly distinct purpose: delegate runs a Cursor turn, cancel aborts an in-flight turn, and doctor reports environment/diagnostic state. There is no overlap in verbs or resources, so misselection is essentially impossible.
All three tools use a consistent single-verb, lowercase naming convention (delegate, cancel, doctor). The pattern is uniform and readable throughout.
Three tools is a lean but defensible surface for a delegation bridge covering run, abort, and diagnose. It is slightly thin, since there is no explicit session-listing or status-inspection tool, but nothing feels redundant.
The core lifecycle is covered: start a turn (delegate), stop one (cancel), and verify the environment (doctor), with sessionId reuse enabling resume. Minor gaps exist around listing/inspecting existing sessions and reading history without re-delegating.