You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A discussion dedicated to the Kiro IDE module. Share your thoughts, questions, and feedback here.
Module Scorecard
Presentation & Onboarding
IDE Integration
Credential Hygiene
Restricted-Environment Readiness
Engineering Quality
Overall
12 / 17
19 / 19
12 / 20
2 / 2
7 / 10
76 / 100
Drilldown
Presentation & Onboarding — 12 / 17
Criterion
Max
Score
Notes
Configuration-mode examples
12
12
README documents three major modes: default launch, folder-specific launch, and MCP server configuration (with coder_external_auth). Sensible defaults are in place (folder = "", open_recent = false, mcp = ""). Minor toggles (open_recent, order, group) lack dedicated examples but are not major modes.
Visual preview
5
0
No image, GIF, or video is embedded in the README. The icon frontmatter field references a static SVG icon, which does not count as a visual preview of the module in action.
Credential Hygiene — 12 / 20
Criterion
Max
Score
Notes
Secrets marked sensitive
16
8
The mcp variable (a JSON string that can embed Bearer tokens in headers.Authorization) is not marked sensitive = true in main.tf. The README example avoids inline literal secrets by referencing data.coder_external_auth.github.access_token, satisfying the second half of the criterion. Half credit for the missing sensitive flag on a variable that demonstrably carries credentials.
Non-hardcoded auth path
4
4
README explicitly documents using coder_external_auth (GitHub OAuth) to inject the access token into the MCP header, avoiding any raw key pasting into templates.
Module downloads and installs nothing. It generates a kiro:// URL and optionally writes an MCP config file. No tool binary is fetched.
Bring-your-own binary
10
N/A
No install step exists; Kiro IDE runs on the user's local machine.
Egress transparency
3
N/A
No artifacts are downloaded; the module's only runtime action is writing a local file.
Runs without sudo
2
2
The coder_script (kiro_mcp) uses mkdir -p "$HOME/.kiro/settings", `echo …
Engineering Quality — 7 / 10
Criterion
Max
Score
Notes
Input quality
6
3
All six variables carry clear description strings and sensible defaults (or are required). However, no validation blocks are present: agent_id lacks a non-empty check, order has no non-negative constraint, and mcp has no JSON-format guard. Half credit for missing validation.
Test coverage
4
4
kiro.tftest.hcl covers URL construction (default, folder, folder+open_recent) and MCP script content via strcontains/base64encode assertions—solid business-logic coverage. main.test.ts runs full terraform apply, verifies the coder_app resource, and executes the MCP script inside a real Alpine container to confirm ~/.kiro/settings/mcp.json is written correctly—proper end-to-end coverage.
IDE Integration — 19 / 19 (6 pts N/A)
Criterion
Max
Score
Notes
Dashboard entry point
7
7
Module creates a coder_app (via vscode-desktop-core submodule) with display_name = "Kiro AI IDE", a custom icon, slug kiro-ai, and configurable order/group. TypeScript test asserts the app resource exists with correct attributes.
Managed configuration
6
6
The mcp input writes ~/.kiro/settings/mcp.json on workspace start via a coder_script. README documents this with a full example including GitHub MCP server and external-auth token injection.
Configurable folder or workdir
6
6
folder variable sets the directory Kiro opens; open_recent allows falling back to the last workspace. Both are documented in README examples and covered by tests.
Pre-installed extensions
6
N/A
Kiro is a desktop IDE (launched via kiro:// URL scheme), not a web IDE. Criterion applies only to web IDEs.
Overall — 76 / 100
Raw 52 / 68 → round(52 / 68 × 100) = 76
Scored against SCORECARD.md on 2026-09-28 with solstice-1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the Kiro IDE module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Presentation & Onboarding — 12 / 17
folder-specific launch, and MCP server configuration (withcoder_external_auth). Sensible defaults are in place (folder = "",open_recent = false,mcp = ""). Minor toggles (open_recent,order,group) lack dedicated examples but are not major modes.iconfrontmatter field references a static SVG icon, which does not count as a visual preview of the module in action.Credential Hygiene — 12 / 20
mcpvariable (a JSON string that can embed Bearer tokens inheaders.Authorization) is not markedsensitive = trueinmain.tf. The README example avoids inline literal secrets by referencingdata.coder_external_auth.github.access_token, satisfying the second half of the criterion. Half credit for the missingsensitiveflag on a variable that demonstrably carries credentials.coder_external_auth(GitHub OAuth) to inject the access token into the MCP header, avoiding any raw key pasting into templates.Restricted-Environment Readiness — 2 / 2 (18 pts N/A)
kiro://URL and optionally writes an MCP config file. No tool binary is fetched.coder_script(kiro_mcp) usesmkdir -p "$HOME/.kiro/settings", `echo …Engineering Quality — 7 / 10
descriptionstrings and sensible defaults (or are required). However, novalidationblocks are present:agent_idlacks a non-empty check,orderhas no non-negative constraint, andmcphas no JSON-format guard. Half credit for missing validation.kiro.tftest.hclcovers URL construction (default, folder, folder+open_recent) and MCP script content viastrcontains/base64encodeassertions—solid business-logic coverage.main.test.tsruns fullterraform apply, verifies thecoder_appresource, and executes the MCP script inside a real Alpine container to confirm~/.kiro/settings/mcp.jsonis written correctly—proper end-to-end coverage.IDE Integration — 19 / 19 (6 pts N/A)
coder_app(viavscode-desktop-coresubmodule) withdisplay_name = "Kiro AI IDE", a custom icon, slugkiro-ai, and configurableorder/group. TypeScript test asserts the app resource exists with correct attributes.mcpinput writes~/.kiro/settings/mcp.jsonon workspace start via acoder_script. README documents this with a full example including GitHub MCP server and external-auth token injection.foldervariable sets the directory Kiro opens;open_recentallows falling back to the last workspace. Both are documented in README examples and covered by tests.kiro://URL scheme), not a web IDE. Criterion applies only to web IDEs.Overall — 76 / 100
Raw 52 / 68 → round(52 / 68 × 100) = 76
Scored against SCORECARD.md on 2026-09-28 with
solstice-1.All reactions