# Review-Gate holds one Cursor request open until you type TASK_COMPLETE

> A Cursor IDE rule paired with an MCP server that opens a popup, takes text, voice or images, and hands control back to the agent until a sentinel string is typed. It is a request-lifecycle trick with a real dependency footprint, and its headline multiplier is never measured anywhere in the repository.

**LakshmanTurlapati/Review-Gate** — Review-Gate V2 is a powerful rule for the Cursor IDE that helps you get up to 5x more value from your monthly requests. It creates an interactive loop where the AI waits for your follow-up commands—via text, voice, or image upload—allowing you to perform deep, iterative work all within a single request.

- Repository: https://github.com/LakshmanTurlapati/Review-Gate
- Website: https://www.youtube.com/watch?v=mZmNM-AIf4M
- Stars: 1,528 · Forks: 156
- Language: JavaScript
- License: not declared
- Published: 2026-09-18 · Updated: 2026-09-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/lakshmanturlapati-review-gate

## The loop is one MCP tool and one sentinel string

The mechanism is small and the wording is precise about it. You give Cursor a task. The agent does its main work, spends some of the tool calls available to that request, and then calls an MCP tool named review_gate_chat. That call opens a popup inside Cursor. You reply by typing, by speaking, or by uploading an image. The agent reads your reply, acts on it using more of the same request's tool call budget, answers in the main chat, and opens the popup again. The loop ends when, and only when, you type TASK_COMPLETE in the popup.

So the mechanism does not make Cursor patient. It inserts a human turn into the middle of a single request so that follow-up work is charged to the request that started it, rather than to a new one. Nothing enforces patience on the agent side either. There is no timeout in the description and no state machine; the only documented stop condition is the string you type, and if the popup never opens because the agent forgot to call the tool, nothing in the design notices.

The diagram of the flow and the six numbered steps agree with each other on that point: the only exit from the loop is the same string.

## The 5x figure appears in the title, the diagram and nowhere else

The headline is a conversion promise: turn your 500 Cursor requests into 2500. The parenthetical under it concedes the problem immediately, saying maybe not always a perfect 5x but you get the idea. The flow diagram ends on a node labelled as a single request delivering 5x value. Three appearances, and not one measurement anywhere in the repository to support any of them.

The two numbers the multiplier depends on are both stated as the author's own plan figures rather than as properties of the tool: a budget of roughly 500 requests a month, and roughly 25 tool calls available per request. So the entire claim rests on how many tool calls a Cursor request exposes on the plan you are on, which is a number this repository does not set and does not measure. A user on a plan with a smaller per-request budget gets a smaller ceiling, and a user whose tasks finish in three tool calls has nothing to multiply.

None of that makes the mechanism wrong. It makes the multiplier a slogan attached to a loop whose real ceiling is set somewhere else entirely.

## The installer reaches for a package manager, SoX and Python packages

One script, four jobs. The macOS path is short:

```bash
# Clone repository and navigate to V2 subdirectory
git clone https://github.com/LakshmanTurlapati/Review-Gate.git
cd Review-Gate/V2

# Run the magical one-click installer
./install.sh
```

The Windows path is the same three lines with a different script, and it notes that it may need administrator privileges:

```powershell
# Clone repository and navigate to V2 subdirectory
git clone https://github.com/LakshmanTurlapati/Review-Gate.git
cd Review-Gate/V2

# Run PowerShell installer (may need admin privileges)
./install.ps1
```

What runs after that is the part worth reading closely. The installer handles dependencies, which it names as package managers Homebrew or Chocolatey, SoX for speech, and Python packages. It performs a global installation of the MCP server with configuration. It installs the Cursor extension that draws the popup. So the footprint is not just files in a repository: it is a package manager invocation, a system audio tool, a Python environment, a globally registered MCP server, and an editor extension, all from one shell script.

Speech-to-text is described as local, using Whisper, and named in one place as local Faster-Whisper AI. That is the one privacy claim the guide makes about your voice, and it is the reason SoX and the Python packages are in the dependency list at all.

## The configuration write is a merge, not an overwrite

Among the four things the installer does, one is described with unusual care: MCP integration setup that preserves existing MCP configuration by merging only the review-gate-v2 entry.

That single sentence is the difference between an installer you can run on a machine that already has MCP servers configured and one you cannot. Most tools that register themselves with an editor append to or rewrite a shared config block, and a mistake there breaks every other server on the list. This one is scoped by name, so a second run should update its own entry and leave the rest byte-identical.

It is worth checking rather than assuming. The guide states the intent; it does not show a before-and-after of the resulting configuration file, and the merge is done by the same script that installs packages system-wide. If you have MCP servers you depend on, diff that config after the install and keep a copy before.

## The canonical VSIX filename carries the version inside it

The release surface is pinned rather than conventional. One file is treated as the only canonical release file: V2/review-gate-v2-2.7.3.vsix. The version appears in the tag, inside the filename, and in a manifest, V2/release-manifest.json, which both packaging commands read. The rule file itself is fixed too, with V2/ReviewGateV2.mdc named as the supported one.

Both paths to build that artifact are documented, and the two live in different directories:

```bash
# From the repo root
python3 scripts/package_review_gate_vsix.py --check

# From V2/cursor-extension
npm run package
```

Running them from the wrong place is the likely failure, since one script path is relative to the repository root and the npm script is relative to the extension directory inside V2. The check mode of the Python script is what a maintainer would use to validate an existing artifact rather than rebuild it.

A version stamped into the artifact filename is convenient for humans and awkward for automation, because every release renames the file that the previous release published. The manifest is what keeps the two in step.

## The V1 generation is still in the tree beside V2

The repository carries two generations of the same idea, and the comparison table is the clearest statement of what changed. V1 was a terminal-based Python script, text input only, installed manually as a rule, running on macOS and Linux, with no speech, no image upload and no status indicator. V2 is a native MCP tool with a popup, text plus voice plus images, a one-click installer, all three desktop platforms, and a local Whisper pipeline for transcription.

That is a genuine migration rather than a repackage, but the tree still shows the older generation's artefacts at the top level. ReviewGate.mdc sits at the root next to AGENTS.md, while the V2 rule is V2/ReviewGateV2.mdc inside the subdirectory the installer tells you to change into. Two rule files with similar names, at different depths, and the guide names only one of them as supported.

There is also a .planning directory at the root. Nothing in the writing says what lives there or who reads it, which makes it the one top-level entry whose purpose has to be guessed.

## The CI walkthrough stops in the middle of a filename

Packaging is automated in .github/workflows/build-vsix.yml, running on pushes to main, on pull requests, and on manual dispatch. Four steps are written out: validate V2/release-manifest.json, run the release-surface regression suite, build the canonical VSIX with npm run package, and upload the artifact.

The fourth step is the one that stops. The text ends on the opening of a backtick and the first part of a path, V2/review-gate-v, with no closing and no destination named. The artifact's full name does appear earlier in the packaging section, as the canonical VSIX path under V2, so the information is recoverable, but the CI section itself never finishes the sentence.

That is a small thing, and it points at something useful. The workflow is not a black box: the validation step, the regression suite and the build command are all named as concrete invocations, and the suite has its own flag, release-surface, which suggests the checks are split by surface rather than run as one blob. It is also the only place in the guide where the project describes testing its own release path.

## No declared licence, and a ten-month jump between the last two tags before the newest one

Two facts about where this sits right now. The first is licensing. The badge row at the top of the guide links to a LICENSE file, and no file of that name appears among the top-level entries, which are .github/, .gitignore, .planning/, AGENTS.md, ReviewGate.mdc, V2/, assets/, readme.md, scripts/ and tests/. No licence text is quoted anywhere either. For a project whose install path asks you to run a shell script that pulls a package manager, a Python environment and a global MCP server, that is the first gap worth closing.

The second is timing. The newest tag is v2.7.3, dated 2026-04-02, and the last recorded push carries the same date. Before it come v2.1.3 from 2025-06-22 and v2.1.2 from 2025-06-11, so the gap between the second and third newest tags is close to ten months, and the jump from 2.1.3 to 2.7.3 skipped six minor versions at once. The last change to this repository is dated 2026-04-02, and nothing since then tells you whether the popup, the installer or the MCP server still matches the Cursor versions in circulation now.

The homepage for the project is a single YouTube video rather than a documentation site, and the documentation entry point is a file inside the repository, V2/INSTALLATION.md, which is named as the starting point for the full V2 experience.

## Conclusion

Read this one as a request-lifecycle experiment rather than a productivity system, and judge the installer before the loop: ./install.sh brings in a package manager, SoX and Python packages and installs an MCP server globally, and no licence is declared anywhere in the tree. If you do try it, the parts worth keeping are the config merge, which touches only its own entry, and the release manifest, which pins exactly one VSIX path. Skip it if your work is sensitive enough that a global Python process and a popup that intercepts every agent turn are not worth the convenience, and treat the 5x figure as a claim with no measurement behind it.

## FAQ

### What does Review-Gate do inside Cursor?

It adds an MCP tool named review_gate_chat that the agent calls before treating a request as finished. A popup opens for text, voice or image input, the agent acts on your reply using the same request's tool call budget and reopens the popup, and the loop ends only when you type TASK_COMPLETE.

### Does Review-Gate send voice input anywhere outside the machine?

The guide describes speech-to-text as local, naming Whisper and local Faster-Whisper AI, and the installer installs SoX for capture along with Python packages. Nothing in the guide states that audio is sent off the machine.

### What licence does Review-Gate use?

None is declared. The badge row links to a LICENSE file, and no file of that name appears among the top-level entries, which hold .github/, .gitignore, .planning/, AGENTS.md, ReviewGate.mdc, V2/, assets/, readme.md, scripts/ and tests/. No licence text is quoted in the guide.

### How is Review-Gate installed on macOS and on Windows?

Clone the repository, change into the Review-Gate/V2 directory, and run ./install.sh on macOS or ./install.ps1 on Windows. The Windows script notes it may need administrator privileges, and the installer handles package managers, SoX, Python packages, a global MCP server install and the Cursor extension.

### When was Review-Gate last changed?

The last recorded push is dated 2026-04-02, the same day as the newest tag v2.7.3. The two tags before it are v2.1.3 from 2025-06-22 and v2.1.2 from 2025-06-11, so the repository went about ten months between tags before that jump.

## Sources

- [Issues](https://github.com/LakshmanTurlapati/Review-Gate/issues)
- [LakshmanTurlapati/Review-Gate on GitHub](https://github.com/LakshmanTurlapati/Review-Gate)
- [Project website](https://www.youtube.com/watch?v=mZmNM-AIf4M)
- [README](https://github.com/LakshmanTurlapati/Review-Gate/blob/main/README.md)
- [Releases](https://github.com/LakshmanTurlapati/Review-Gate/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/lakshmanturlapati-review-gate
