Skip to main content
Glama

reply_run

DestructiveIdempotent

Continue an ended Cursor Agent session while preserving its agent ID; pass only task scope and target locations so Cursor reads the workspace itself.

Instructions

在已结束的 Cursor Agent 会话中续接运行并保留 agentId;只传目标位置与任务范围,禁止源码正文,由 Cursor 自行读取。

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
taskYes任务或审查范围与验收要求;禁止传源码正文、代码块或补丁,由 Cursor 在获授权工作区自行读取。
modelNo
timeoutMsNoCursor 任务总预算(毫秒);普通任务省略即可使用 24 小时默认值,硬上限同为 24 小时。
permissionNo
parentRunIdYes
idempotencyKeyYes
targetLocationsNo工作区内的文件、目录或行号位置列表,仅传位置不传内容;省略表示由 Cursor 按任务范围在工作区内定位。
codexAllowedToolsNo本次续接由 Codex 主进程决定的额外工具放行;省略时继承父运行,传空数组可撤销。
workspaceApprovalTokenNo
confirmedDangerousPermissionNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed7 schema fields changedv0.1.2
    • addedInput schema / properties / codexAllowedTools
      Added value: +{
      +  "description": "本次续接由 Codex 主进程决定的额外工具放行;省略时继承父运行,传空数组可撤销。",
      +  "items": {
      +    "enum": [
      +      "delete",
      +      "task",
      +      "mcp",
      +      "generateImage"
      +    ],
      +    "type": "string"
      +  },
      +  "maxItems": 4,
      +  "type": "array"
      +}
    • addedInput schema / properties / targetLocations
      Added value: +{
      +  "description": "工作区内的文件、目录或行号位置列表,仅传位置不传内容;省略表示由 Cursor 按任务范围在工作区内定位。",
      +  "items": {
      +    "maxLength": 500,
      +    "minLength": 1,
      +    "type": "string"
      +  },
      +  "maxItems": 100,
      +  "type": "array"
      +}
    • addedInput schema / properties / task / description
      Added value: +"任务或审查范围与验收要求;禁止传源码正文、代码块或补丁,由 Cursor 在获授权工作区自行读取。"
    • addedInput schema / properties / task / maxLength
      Added value: +4000
    • addedInput schema / properties / timeoutMs / description
      Added value: +"Cursor 任务总预算(毫秒);普通任务省略即可使用 24 小时默认值,硬上限同为 24 小时。"
    • changedInput schema / properties / timeoutMs / maximum
      Previous value: -9007199254740991New value: +86400000
    • changedInput schema / properties / timeoutMs / minimum
      Previous value: --9007199254740991New value: +1000
  2. First observedv0.1.0

TDQS

B3.1/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare destructive=true, idempotent=true, openWorld=true, so the safety profile is partly covered. The description adds two useful facts: the agentId is retained and source code must not be inlined (Cursor reads it). It says nothing about permissions, approval tokens, or what a continuation actually mutates.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single dense sentence, front-loaded with the core action and followed by the key constraint. No filler, though the semicolon-packed style condenses several ideas that could be separated for scanability.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a destructive, open-world tool with 10 parameters, nested objects, permission modes, an approval token and a danger-confirmation flag, and no output schema, the description is far too thin. It leaves permission handling, idempotency behavior and danger escalation entirely undescribed.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is only 40% across 10 parameters, and the description touches only implicitly on task and targetLocations. Critical parameters (permission, workspaceApprovalToken, confirmedDangerousPermission, codexAllowedTools inheritance, idempotencyKey) get no explanation in either the description or the schema, so it does not compensate for the coverage gap.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource: '续接运行' on an '已结束的 Cursor Agent 会话', and names a distinguishing trait (retains agentId). It is clearly separable from start_run/open_run by the 'already-ended session' scope, though it never names those siblings explicitly.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives a condition of use (only for already-ended sessions) and a content rule (pass only locations/scope, never source code). It does not, however, say when to prefer a sibling like start_run or open_run, nor state any exclusion beyond the source-code prohibition.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.