Grok Bot Leak: Why Cursor Only Gives Models Partial Tool Definitions
The community reverse-engineered Cursor's desktop agent Grok Bot 0.18.0, revealing its tool exposure strategy: 9 of 30+ tools only get a one-line hand-written hint, requiring the model to call GetMcpTools first to pull the full schema. The main reason is KV cache economics—changing the tools parameter invalidates the entire prefix cache, multiplying costs by 10x. Cursor writes dynamic tool schemas into conversation content instead of the tools array, keeping the tool surface stable to preserve cache discounts. Manus, designed independently, took the opposite route: all tools stay resident, with decoding-time masking. Both teams converged on the same constraint: the serialized tool surface must remain stable; dynamism must be pushed elsewhere.
Why it matters: Reverse-engineering analysis with concrete code anchors and clear KV cache cost breakdown, directly useful for agent builders. Deduction because info comes from a leaked build rather than official disclosure, and the article only covers the tool layer, deferring context layer ...