
IAF Agent Bridge
io.github.francescoveryra-dotv1.0.1Updated Oct 3, 2026
MCP server that sends work to Cursor Agent over ACP and returns the session id needed to continue.
Overview
Lets a stdio MCP host such as Codex or Claude Code delegate coding work to a local Cursor Agent and resume the same session.
- What it does
- The bridge forwards prompts from an MCP host to the local Cursor Agent over ACP and returns the session id needed to continue the same Cursor conversation. Its tools are delegate, which sends a prompt and waits for that Cursor turn to finish, cancel, which stops an in-flight turn while keeping the session resumable, and doctor, which checks Node, the bridge, the Cursor CLI and authentication. The supervisor host reads Cursor's reply and decides whether to continue, mark the work complete, or report it blocked.
- When to use it
- Use it when you want an MCP host to act as supervisor while Cursor Agent performs implementation work in a repository, including multi-turn work that must continue in one Cursor session. It is not meant to be installed into the Cursor MCP configuration of a repository Cursor itself is editing, since that loop is refused.
- Requirements
- Node.js 20 or newer (22 for the test suite), the Cursor CLI available on PATH as agent, and agent login completed on that machine. It runs locally over stdio, typically via npx -y [email protected], and no OpenAI API key is required. Desktop only.
Installation
In SourceWeft
- Open IAF Agent Bridge in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
IAF Agent Bridge
MCP server that lets Codex, Claude Code, or another stdio host send work to Cursor Agent and continue the same Cursor session until the requested work is done.
The bridge carries the prompt, the session, and Cursor's reply. The supervisor decides what happens next. Cursor does the implementation.
delegate returns only after that Cursor turn is finished. A message that says the work is complete does not end the call while Cursor is still running tools, sub-agents, or a follow-up. Cursor keeps control of that internal work. The supervisor sees one result, then chooses CONTINUE, COMPLETE, or BLOCKED.
Status: npm [email protected] is the current public package. GitHub Release v1.0.2 matches it. v1.0.1 and v1.0.0 remain published. The Official MCP Registry entry is io.github.francescoveryra-dot/iaf-agent-bridge version 1.0.2.
[CI] [npm] [GitHub Release] [License: MIT] [Node]
Cursor Agent is the only production executor. Codex and Claude Code are supervisors. Do not install this server into the Cursor MCP config of a repository that Cursor itself is editing. That loop is refused.
What you can do
- Start a Cursor session from an MCP host and resume it with
sessionId. - Let ordinary development continue without approving every tool call.
- Reject force-push, history rewrite, destructive SQL, deletes outside the project, and secret staging unless you explicitly set
IAF_PERMISSION_MODE=allow-all. - Use a Master Prompt when the repository has one. A repository without one works normally.
Prerequisites
- Node.js 20 or newer. Running the test suite needs Node.js 22.
- The Cursor CLI on your
PATHasagent. agent logincompleted on that machine.
No OpenAI API key is required.
Install
Manual MCP configuration remains the fallback. See docs/installation.md and docs/hosts.md.
Quick start
doctor should show the Cursor executable and Authenticated: true. It does not print your account.
Point an MCP host at the published package:
A source checkout can use node and dist/cli.js after npm run build. Then ask the supervisor to implement the work with Cursor and to call delegate again with the returned sessionId while requested work remains.
Install by host
npm install (npx -y iaf-agent-bridge) installs 1.0.2. See docs/installation.md and docs/release.md.
Tools
Example follow-up: the first delegate returns "sessionId": "...". The next call uses that id and a prompt that names what is still missing.
How the supervisor should behave
Read result as if you had pasted Cursor's reply into the conversation. Then choose one state:
- CONTINUE when requested work remains and Cursor can still do it. This is the normal result. Plans, TODOs, mocks, and missing layers are CONTINUE.
- COMPLETE when the requested work is actually present.
- BLOCKED only for a real external decision, secret, or irreversible authorization.
The bridge does not demand a new lint run, end-to-end suite, or coverage gate after every turn. Details: docs/supervisor-loop.md.
If the repository contains MASTER_PROMPT.md or the other project files listed in docs/supervisor-loop.md, the first result names them. If it does not, nothing is created.
Configuration and troubleshooting
Environment variables: docs/configuration.md.
If doctor says Cursor was not found, install the CLI and open a new shell. If it says not authenticated, run agent login. More cases: docs/troubleshooting.md.
Security
The bridge can ask Cursor to edit the workspace you name and to run commands there. Read SECURITY.md and docs/security-model.md.
Report vulnerabilities privately: Security advisories. Do not open a public issue that contains a token, a credential, or a working exploit.
Contributing
CONTRIBUTING.md. Issues and pull requests are welcome. Support routes are in SUPPORT.md.
License
MIT. See LICENSE.
Source: README.md at commit 49b258e
Tools
0Version history
1- v1.0.1LatestOct 3, 2026


