call-cursor-agent

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts untrusted input through a task description variable and passes it directly to an autonomous agent tool. This creates a surface where malicious instructions in the input could influence the behavior of the cursor-agent.
  • Ingestion points: The {task_description} variable in SKILL.md is populated at runtime.
  • Boundary markers: The input is wrapped in a shell here-doc (<<EOT), which provides basic delimitation but does not prevent the agent from following instructions embedded within the text. There are no instructions to the agent to ignore malicious commands.
  • Capability inventory: The skill invokes cursor-agent, an autonomous tool capable of making changes to files and performing system tasks.
  • Sanitization: No validation, escaping, or sanitization is performed on the task content before passing it to the external tool.
  • [COMMAND_EXECUTION]: The skill executes the cursor-agent CLI command. While this tool is common in developer environments, triggering an autonomous agent from within a skill context creates a recursive execution chain that increases the potential impact of prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:49 AM
Security Audit — agent-trust-hub — call-cursor-agent