call-cursor-agent
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill accepts untrusted input through a task description variable and passes it directly to an autonomous agent tool. This creates a surface where malicious instructions in the input could influence the behavior of the cursor-agent.
- Ingestion points: The
{task_description}variable in SKILL.md is populated at runtime. - Boundary markers: The input is wrapped in a shell here-doc (
<<EOT), which provides basic delimitation but does not prevent the agent from following instructions embedded within the text. There are no instructions to the agent to ignore malicious commands. - Capability inventory: The skill invokes
cursor-agent, an autonomous tool capable of making changes to files and performing system tasks. - Sanitization: No validation, escaping, or sanitization is performed on the task content before passing it to the external tool.
- [COMMAND_EXECUTION]: The skill executes the
cursor-agentCLI command. While this tool is common in developer environments, triggering an autonomous agent from within a skill context creates a recursive execution chain that increases the potential impact of prompt injection.
Audit Metadata