04

Cursor Hackathon: warren

Rooms for coding agents. One scoped tree of rooms for your Claude Code, a colleague’s Codex and every Cursor session, with each @mention pushed into the right running session. Built in a four-and-a-half-hour sprint at Cursor Hackathon Prague, then kept going.

five-person team4.5 hoursdevtools · MCP · multi-agent

// evidence

build sprint
4.5 hours
team
five people
storage
one SQLite file
protocols
MCP, A2A inbound
A teammate pitching warren on stage in front of a slide with QR codes for the live site and the GitHub repository
Vojta, a teammate, on the pitch. Live site and repo on the slide.

// The event

Cursor Hackathon Prague: Forge the Stack, at Productboard. The brief was tools developers actually need. Seventy-four people, one afternoon, a build sprint from half past one to six.

// The problem it picks

Five agents in parallel, coordinated through one shared PLAN.md. Every agent reads the whole file, including everything that is not its job. Nobody is told when something changes. And it stops at your laptop: a colleague’s agents cannot join without seeing everything.

// How it works

A tree of rooms
One room per project, a subroom per task, each with its own markdown context. An agent loads its branch, not the whole plan.
Scoped invites
An invite grants one subroom and everything under it. Another company’s agent invited into the API contract never sees the checkout UI.
@mentions decide who wakes
Delivery is pushed into the live Claude Code session, resumes a Codex or Cursor session, or lands in an MCP inbox. Untagged chatter wakes nobody.
Claims
An agent claims a task together with the files it will touch, and an overlapping claim is refused. The locks are advisory: an agent that never calls claim is not stopped.

// Agents from other companies

Messages crossing an organisation are treated as requests, not orders. Secrets are masked, suspicious messages are held for a person to release or reject, a room can require contract changes to wait for a person of the agent’s own org, and every one of those decisions lands in an audit log.

The injection check is a set of regexes, and the README says plainly that a determined attacker can phrase around it. Scoping and the human release are the real controls; the heuristics only decide when to ask.

// After the sprint

The sprint produced the hub with scoped rooms and invites, the bridge, the brand and a live landing page. Work continued over the following week: persistent accounts with invite links, named leased sessions so two terminals of the same agent can be addressed separately, and an end-to-end suite covering the hub, the bridges, the safety controls and restarts.

Self-hosted as one container and one SQLite file. The hosted dashboard stays closed on purpose; the public site serves the landing page, a waitlist and a browser-only demo sandbox.

// from the room

Four people gathered at one workstation during the build sprint, one pointing at a monitor
Mid-sprint, at one workstation.
Participants seated with laptops listening to the opening talks at Productboard
The room before the sprint opened.
A group of participants posing on stage, one of them held horizontally across the others’ arms
End of the evening, on stage.

Photographs courtesy of the Cursor Hackathon Prague organisers. Thank you.