2 min lesson
Run one bounded lint-fix job
Run one write-enabled print job, validate its terminal event and review its diff and test result.
Step 1 of 2
Create a dedicated branch for the job. In .cursor/cli.json, allow reads and writes only under src/pricing, allow the needed test command and deny secret files and destructive shell commands. Keep CURSOR_API_KEY in the CI secret store. Run Agent with -p, --force and stream-json, writing standard output to a protected artifact. Parse the initialization event to confirm cwd and permissionMode. Then require exit code zero and a terminal result event marked successful. Inspect the changed paths and rerun the pricing test before opening a pull request. Treat the stream as sensitive because tool events can include prompts and file content.
Learn more
Optional practice
Test yourself on Run one bounded lint-fix job
QWhich evidence is enough to accept the headless lint-fix job?