TRACE FORMAT · Profile revision 1

Cursor Agent Trace

A vendor-neutral JSON record for attributing AI-generated code alongside human authorship in version-controlled files.

vendorformatcoding-agentcode-attributionprovenance

Why it is in the map

It contributes concrete file-modification and code-provenance semantics absent from general span formats, while remaining clearly narrower than an execution trace.

Tracevity boundary

A documented field can support reconstruction, but its presence alone does not prove completeness, authenticity, authorization, or external settlement.

Profile findings

What the documentation can—and cannot—establish

Each row distinguishes source evidence from Tracevity's bounded interpretation. “Not documented” describes the reviewed sources; it does not prove an implementation cannot record the artifact.

01

System identity

Partially documented

Tool/model attribution and VCS-linked record identity are documented.

Tracevity interpretation

This supports code-attribution context, not a complete agent instance, definition, session, or subagent identity model.

Limit

Product/runtime identity and stable agent relationships are incomplete.

Primary evidence (1)
02

Principal and delegation

Partially documented

High-level authorship category is documented.

Tracevity interpretation

Authorship category is not authenticated identity or delegated authority.

Limit

Identity-provider and authorization evidence require separate records.

Primary evidence (1)
03

Instruction and context

Not documented

Instruction and context contents are not standardized.

Tracevity interpretation

A link is not proof that referenced context remains available, versioned, complete, or unchanged.

Limit

Context reconstruction depends on external referenced systems.

Primary evidence (1)
04

Decision artifacts

Not documented

Decision artifacts are outside the format.

Tracevity interpretation

None may be inferred from attributed file ranges.

Limit

The format is intentionally focused on code attribution rather than execution reasoning.

Primary evidence (1)
05

Model activity

Partially documented

A model identifier is representable.

Tracevity interpretation

Model attribution is partial and does not reconstruct inference activity.

Limit

No model request/response sequence or usage evidence is provided.

Primary evidence (1)
06

Tool and MCP activity

Not documented

Tool execution activity is not standardized beyond contributor-tool attribution.

Tracevity interpretation

Tool provenance must not be expanded into execution reconstruction.

Limit

MCP and arbitrary external tool activity remain outside the format.

Primary evidence (1)
07

Effects

Partially documented

A specialized file-modification attribution artifact is documented.

Tracevity interpretation

This can support code-change attribution but does not prove runtime execution, deployment, or external settlement.

Limit

Other effect types and independently verified resulting state are outside the RFC.

Primary evidence (1)
08

Human control

Partially documented

Contribution composition can identify human involvement at a high level.

Tracevity interpretation

Mixed or human authorship does not establish authorization, approval timing, or intervention.

Limit

Operational human-control events require another trace source.

Primary evidence (1)
09

Outcome

Partially documented

A code-attribution outcome is representable.

Tracevity interpretation

Attributed code does not establish that a requested action succeeded, ran, deployed, or changed another system.

Limit

Partial, failed, ambiguous, rollback, and compensation outcomes are outside the format.

Primary evidence (1)
10

Trace integrity

Partially documented

Limited content/revision linkage is documented.

Tracevity interpretation

An optional hash or VCS reference is not full-record signing, immutable custody, or independent verification.

Limit

Clock provenance, hash requirements, storage mutability, and origin authenticity remain unspecified.

Primary evidence (1)
11

Portability

Documented

A versioned, machine-readable JSON interchange format is documented.

Tracevity interpretation

Syntax is portable, while mapping to execution traces and preservation through history rewrites remain unresolved.

Limit

Storage, import destinations, conversions, semantic loss, merge, and rebase behavior are not standardized.

Primary evidence (1)
12

Privacy

Not documented

Privacy lifecycle controls are not documented by the format.

Tracevity interpretation

Storage is implementation-defined, so sensitive-data handling and custody must remain unknown.

Limit

Prompt/output/tool retention, secrets, PII, code retention, screenshots, and deletion require implementation-specific evidence.

Primary evidence (1)

Reconstruction reading

Do not collapse these findings into one score.

This profile describes documented evidence surfaces. Whether they are sufficient depends on the reconstruction question and the other identity, authorization, tool, and destination records available.

Potentially useful evidence

  • Identity: Tool/model attribution and VCS-linked record identity are documented.
  • Principal: High-level authorship category is documented.
  • Models: A model identifier is representable.
  • Effects: A specialized file-modification attribution artifact is documented.
  • Human control: Contribution composition can identify human involvement at a high level.

Explicit gaps or uncertainty

  • Context: Context reconstruction depends on external referenced systems.
  • Decisions: The format is intentionally focused on code attribution rather than execution reasoning.
  • Tools: MCP and arbitrary external tool activity remain outside the format.
  • Privacy: Prompt/output/tool retention, secrets, PII, code retention, screenshots, and deletion require implementation-specific evidence.

Source register

1 reviewed primary sources

  1. Agent Trace - A standard format for tracing AI-generated codeCursor · OFFICIAL REPOSITORY · observed August 28, 2026 · current
    Open source ↗

Next question

What evidence does your use case require?

Move from documented field presence to an explicit reconstruction target, or examine selected directional format mappings without changing this system's documentation posture.

Trace Reconstruction Requirements Explore compatibility evidence