You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A discussion dedicated to the Zed module. Share your thoughts, questions, and feedback here.
Module Scorecard
Presentation & Onboarding
IDE Integration
Credential Hygiene
Restricted-Environment Readiness
Engineering Quality
Overall
12 / 17
19 / 19
12 / 20
2 / 2
7 / 10
76 / 100
Drilldown
Presentation & Onboarding — 12 / 17
Criterion
Max
Score
Notes
Configuration-mode examples
12
12
README documents five examples: default, folder, display_name/order, agent_name, and settings (with MCP server config). Each major mode has a working snippet with sensible defaults.
Visual preview
5
0
No image, GIF, or video embedded in the README. The frontmatter icon field references an SVG file, which does not count per calibration.
Credential Hygiene — 12 / 20
Criterion
Max
Score
Notes
Secrets marked sensitive
16
8
The settings variable accepts arbitrary JSON that can carry API keys for MCP servers (as shown in the README example with context_servers), yet it is not marked sensitive = true. README examples avoid inline literal secrets, but the potential secret carrier lacks the flag.
Non-hardcoded auth path
4
4
README explicitly documents the auth path: "Zed needs you to either have Coder CLI installed with coder config-ssh run or Coder Desktop." The coder_app uses external = true with a zed://ssh/ URL, relying on Coder's SSH auth rather than pasted keys.
Module downloads and installs nothing. It only creates a coder_app URL and optionally writes a settings file. No download URL exists to override.
Bring-your-own binary
10
N/A
Module does not install Zed or any tool. It assumes Zed is already present in the image. No install step to disable.
Egress transparency
3
N/A
Module downloads nothing and contacts no external endpoints at install or runtime. The only interaction is writing a local file and registering a coder_app URL.
Runs without sudo
2
2
The coder_script uses only mkdir -p, base64 -d, jq, printf, mktemp, and mv—all user-space commands writing to $HOME/.config/zed/ or $XDG_CONFIG_HOME/zed/. No sudo invocation anywhere in the script.
Engineering Quality — 7 / 10
Criterion
Max
Score
Notes
Input quality
6
3
All eight variables have clear description fields and sensible defaults. However, no validation block is present on any variable. The settings variable (a JSON string) and order (a number) would benefit from validation to catch malformed input early.
Test coverage
4
4
zed.tftest.hcl covers URL construction (default, folder, agent_name), base64 encoding of settings, and the empty-settings no-op case. main.test.ts runs end-to-end container tests verifying file write, JSON merge with jq, and script absence when settings is empty. Clear separation of business-logic and e2e tests.
IDE Integration — 19 / 19 (6 pts N/A)
Criterion
Max
Score
Notes
Dashboard entry point
7
7
coder_app resource with external = true, proper slug, display_name, icon, order, and group. Launches via zed://ssh/ deep-link protocol.
Managed configuration
6
6
settings input accepts JSON, base64-encodes it into a coder_script that writes/merges into ~/.config/zed/settings.json. README documents MCP server configuration with a full example.
Configurable folder or workdir
6
6
folder variable appends a path to the zed://ssh/ URL. README shows folder = "/home/coder/project" example.
Pre-installed extensions
6
N/A
Zed is a native desktop application launched via zed:// protocol with external = true, not a web IDE. Criterion applies only to web IDEs.
Overall — 76 / 100
Raw 52 / 68 → round(52 / 68 × 100) = 76
Scored against SCORECARD.md on 2026-09-28 with solstice-1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the Zed module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Presentation & Onboarding — 12 / 17
folder,display_name/order,agent_name, andsettings(with MCP server config). Each major mode has a working snippet with sensible defaults.iconfield references an SVG file, which does not count per calibration.Credential Hygiene — 12 / 20
settingsvariable accepts arbitrary JSON that can carry API keys for MCP servers (as shown in the README example withcontext_servers), yet it is not markedsensitive = true. README examples avoid inline literal secrets, but the potential secret carrier lacks the flag.coder config-sshrun or Coder Desktop." Thecoder_appusesexternal = truewith azed://ssh/URL, relying on Coder's SSH auth rather than pasted keys.Restricted-Environment Readiness — 2 / 2 (18 pts N/A)
coder_appURL and optionally writes a settings file. No download URL exists to override.coder_appURL.coder_scriptuses onlymkdir -p,base64 -d,jq,printf,mktemp, andmv—all user-space commands writing to$HOME/.config/zed/or$XDG_CONFIG_HOME/zed/. Nosudoinvocation anywhere in the script.Engineering Quality — 7 / 10
descriptionfields and sensible defaults. However, novalidationblock is present on any variable. Thesettingsvariable (a JSON string) andorder(a number) would benefit from validation to catch malformed input early.zed.tftest.hclcovers URL construction (default, folder, agent_name), base64 encoding of settings, and the empty-settings no-op case.main.test.tsruns end-to-end container tests verifying file write, JSON merge withjq, and script absence when settings is empty. Clear separation of business-logic and e2e tests.IDE Integration — 19 / 19 (6 pts N/A)
coder_appresource withexternal = true, properslug,display_name,icon,order, andgroup. Launches viazed://ssh/deep-link protocol.settingsinput accepts JSON, base64-encodes it into acoder_scriptthat writes/merges into~/.config/zed/settings.json. README documents MCP server configuration with a full example.foldervariable appends a path to thezed://ssh/URL. README showsfolder = "/home/coder/project"example.zed://protocol withexternal = true, not a web IDE. Criterion applies only to web IDEs.Overall — 76 / 100
Raw 52 / 68 → round(52 / 68 × 100) = 76
Scored against SCORECARD.md on 2026-09-28 with
solstice-1.All reactions