You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A discussion dedicated to the Kiro IDE module. Share your thoughts, questions, and feedback here.
Module Scorecard
Presentation & Onboarding
IDE Integration
Credential Hygiene
Restricted-Environment Readiness
Engineering Quality
Overall
12 / 17
19 / 19
12 / 20
2 / 2
10 / 10
81 / 100
Drilldown
Presentation & Onboarding — 12 / 17
Criterion
Max
Score
Notes
Configuration-mode examples
12
12
README documents three examples: default launch, folder for a specific directory, and mcp with coder_external_auth for GitHub. These cover the major behavioral modes. Minor options (open_recent, order, group) lack dedicated examples but are fine-tuning parameters, not distinct modes.
Visual preview
5
0
No image, GIF, or video embedded in the README. The frontmatter references an SVG icon file, but that is the module icon, not a preview of the module in action.
Credential Hygiene — 12 / 20
Criterion
Max
Score
Notes
Secrets marked sensitive
16
8
The mcp input (a JSON string that can embed API keys/tokens in headers) is not marked sensitive = true. No other variable carries secret material. README examples avoid inline secrets by referencing data.coder_external_auth.github.access_token rather than pasting a literal key, but the unmarked mcp variable caps this at half.
Non-hardcoded auth path
4
4
README explicitly documents using coder_external_auth (GitHub OAuth) to supply the Bearer token for the MCP server, avoiding raw key pasting into templates.
The module downloads and installs no tool. Kiro IDE is a desktop application the user already has; the module only generates a coder_app URL and optionally writes a local config file.
Bring-your-own binary
10
N/A
No binary is downloaded or installed by this module.
Egress transparency
3
N/A
No download or install step exists; the module's only external interaction is the Kiro desktop client connecting to the Coder deployment, which is outside the module's scope.
Runs without sudo
2
2
The sole script (coder_script.kiro_mcp) uses mkdir -p "$HOME/.kiro/settings", base64 -d, and chmod 600—all operating within the user's home directory with no sudo invocation.
Engineering Quality — 10 / 10
Criterion
Max
Score
Notes
Input quality
6
6
All six variables have clear description fields and sensible defaults ("", false, null). Types are appropriate. No validation blocks, but the inputs are simple enough (string paths, bool, number, JSON string) that Terraform-level validation adds little value.
Test coverage
4
4
kiro.tftest.hcl covers URL construction logic (default, folder, open_recent, MCP script content) via plan-time assertions. main.test.ts performs full terraform apply and verifies the coder_app resource, URL outputs, and executes the MCP script in a real Alpine container to confirm the file is written correctly. Clear separation of business-logic vs. end-to-end testing.
IDE Integration — 19 / 19 (6 pts N/A)
Criterion
Max
Score
Notes
Dashboard entry point
7
7
The module creates a coder_app (via vscode-desktop-core) with display name "Kiro AI IDE", icon, slug, order, and group. README's primary example shows the one-click button. Tests assert the coder_app resource exists with correct attributes.
Managed configuration
6
6
The mcp input writes ~/.kiro/settings/mcp.json on workspace start. README has a dedicated "Configure MCP servers for Kiro" section with a full example using external auth.
Configurable folder or workdir
6
6
The folder variable is documented with a "Open in a specific directory" example (folder = "/home/coder/project"). The open_recent variable provides an additional fallback behavior.
Pre-installed extensions
6
N/A
Kiro IDE is a desktop application, not a web IDE. This criterion applies only to web IDEs.
Overall — 81 / 100
Raw 55 / 68 → round(55 / 68 × 100) = 81
Scored against SCORECARD.md on 2026-10-05 with solstice-1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the Kiro IDE module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Presentation & Onboarding — 12 / 17
folderfor a specific directory, andmcpwithcoder_external_authfor GitHub. These cover the major behavioral modes. Minor options (open_recent,order,group) lack dedicated examples but are fine-tuning parameters, not distinct modes.Credential Hygiene — 12 / 20
mcpinput (a JSON string that can embed API keys/tokens in headers) is not markedsensitive = true. No other variable carries secret material. README examples avoid inline secrets by referencingdata.coder_external_auth.github.access_tokenrather than pasting a literal key, but the unmarkedmcpvariable caps this at half.coder_external_auth(GitHub OAuth) to supply the Bearer token for the MCP server, avoiding raw key pasting into templates.Restricted-Environment Readiness — 2 / 2 (18 pts N/A)
coder_appURL and optionally writes a local config file.coder_script.kiro_mcp) usesmkdir -p "$HOME/.kiro/settings",base64 -d, andchmod 600—all operating within the user's home directory with nosudoinvocation.Engineering Quality — 10 / 10
descriptionfields and sensible defaults ("",false,null). Types are appropriate. Novalidationblocks, but the inputs are simple enough (string paths, bool, number, JSON string) that Terraform-level validation adds little value.kiro.tftest.hclcovers URL construction logic (default, folder, open_recent, MCP script content) via plan-time assertions.main.test.tsperforms fullterraform applyand verifies thecoder_appresource, URL outputs, and executes the MCP script in a real Alpine container to confirm the file is written correctly. Clear separation of business-logic vs. end-to-end testing.IDE Integration — 19 / 19 (6 pts N/A)
coder_app(viavscode-desktop-core) with display name "Kiro AI IDE", icon, slug, order, and group. README's primary example shows the one-click button. Tests assert thecoder_appresource exists with correct attributes.mcpinput writes~/.kiro/settings/mcp.jsonon workspace start. README has a dedicated "Configure MCP servers for Kiro" section with a full example using external auth.foldervariable is documented with a "Open in a specific directory" example (folder = "/home/coder/project"). Theopen_recentvariable provides an additional fallback behavior.Overall — 81 / 100
Raw 55 / 68 → round(55 / 68 × 100) = 81
Scored against SCORECARD.md on 2026-10-05 with
solstice-1.All reactions