npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@pungrumpy/cursor-action

v1.0.3

Published

Run cursor-agent in CI pipelines using the official @cursor/sdk

Readme

Cursor Action

Run Cursor agents in GitHub Actions using the official @cursor/sdk. An independent project, not affiliated with or endorsed by Cursor.

CI Release

Quickstart

  1. Add a repository secret named CURSOR_API_KEY.
  2. Use the action in a workflow job.
  3. Read steps.<id>.outputs.summary for the model response.
- name: Run Cursor Agent
  id: cursor
  uses: PunGrumpy/cursor-action@v1
  with:
    api-key: ${{ secrets.CURSOR_API_KEY }}
    prompt: "Review this PR for security issues and summarize your findings."

- name: Print summary
  env:
    SUMMARY: ${{ steps.cursor.outputs.summary }}
  run: echo "$SUMMARY"

The action runs on ubuntu-latest, windows-latest, and macos-latest.

Reference

Inputs

| Input | Required | Default | Description | | --- | --- | --- | --- | | cursor-version | ❌ | latest | (Deprecated) The SDK automatically manages the agent version. | | api-key | ✅ | — | Cursor API key for authentication | | prompt | ✅ | — | Prompt to pass to cursor-agent | | model | ❌ | default | Model id for the agent (e.g. default, composer-2). The Cursor SDK does not accept auto. | | working-directory | ❌ | . | Working directory for the agent to operate in | | permissions | ❌ | read-only | Validated but NOT enforced: 'read-only' does not stop the agent from editing files or running shell commands. Wired to the SDK in v2. | | timeout | ❌ | 300 | Timeout in seconds for the agent run |

Outputs

| Output | Description | | --- | --- | | summary | Text summary returned by the cursor-agent | | exit-code | Exit code from the cursor-agent process | | status | Run status returned by the cursor-agent (finished, error, or cancelled) | | duration-ms | Execution duration in milliseconds | | total-tokens | Total tokens consumed by the agent run | | input-tokens | Input tokens consumed by the agent run | | output-tokens | Output tokens generated by the agent run |

[!WARNING]

permissions does not restrict the agent today. The value is validated and then discarded — tool access follows whatever your API key and account allow, so read-only does not stop the agent from editing files or running shell commands. It is wired to the SDK's tool restrictions in v2.

[!IMPORTANT]

Treat summary as untrusted model output. Pass it through env: rather than interpolating ${{ steps.<id>.outputs.summary }} directly into a run: script or a github-script body — interpolation splices the text into the script before it executes.

Documentation

Worked examples, what the action does at runtime, and troubleshooting live in docs/, which is published as the documentation site. The tables above are generated from action.yml by the same script that generates the site's reference page, so neither can drift from the manifest.

Local development

Prerequisites

  • Node.js 24 (matches CI and release workflows)
  • Bun

Validate changes locally

bun install
bun run typecheck
bun run test
bun run build

dist/ is committed on purpose — GitHub Actions executes it straight from the tag. If you changed anything under src/, run bun run build and commit the result; CI fails when dist/ is out of date. The bundle only contains this repository's own code (a few KB); @actions/core and @cursor/sdk stay external and are installed by the action at runtime, so package-lock.json must stay in sync with package.json.

Work on the documentation site

bun run docs:reference   # regenerate the reference tables from action.yml
bun run docs:dev         # http://localhost:3000

docs/ is a separate Fumapress project with its own lockfile, so bun install at the repository root does not pull in its dependencies.

Run the action entrypoint locally

export GITHUB_STEP_SUMMARY="$(mktemp)"
export GITHUB_OUTPUT="$(mktemp)"

env "INPUT_API-KEY=$CURSOR_API_KEY" \
    "INPUT_PROMPT=Say 'smoke test passed' and nothing else." \
    "INPUT_MODEL=default" \
    "INPUT_PERMISSIONS=read-only" \
    "INPUT_TIMEOUT=60" \
    node dist/index.mjs

CI and release notes

  • CI runs typecheck, lint, test, build, and a dist/ freshness check on every push and pull request. The Docs job regenerates the reference from action.yml, typechecks the site, and builds it.
  • The Integration jobs install the action's runtime dependencies and run it with an invalid key on Ubuntu, Windows, and macOS. Being rejected at authentication is the pass condition: it proves the dependency tree resolves and the SDK reaches Cursor, without spending an agent run.
  • Smoke Test runs the action for real and needs a CURSOR_API_KEY on a paid plan, so it only runs from the Actions tab (workflow_dispatch).
  • Release runs Changesets on pushes to main to open a release PR or publish, then moves the v1 tag to the published version.
  • uses: PunGrumpy/cursor-action@v1 tracks the latest v1.x.x. Pin a full tag or a commit SHA if you want a frozen version.

Versioning

This project uses Changesets. See .changeset/README.md for the contribution workflow.

License

MIT © PunGrumpy