skills/grahama1970/agent-skills/ccopy/Gen Agent Trust Hub

ccopy

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run to execute platform-specific clipboard management tools to handle the transfer of formatted chat history.
  • Evidence: scripts/ccopy/clipboard.py invokes commands such as pbcopy, clip.exe, xclip, xsel, and wl-copy. The implementation follows best practices by using shutil.which to verify the presence of these utilities before execution.
  • [EXTERNAL_DOWNLOADS]: The skill declares a dependency on a well-known Python library to provide its command-line interface.
  • Evidence: README.md and references/USAGE.md instruct the user to install the typer package via pip or uv.
  • [DATA_EXFILTRATION]: The skill accesses sensitive local files containing user conversation history from the Cursor editor.
  • Evidence: It reads from ~/.config/Cursor/User/ (SQLite databases) and ~/.cursor/projects/ (JSONL transcripts). This access is limited to reading the last complete user/assistant turn and transferring it to the local system clipboard, which is the primary intended function of the skill. No network activity or remote exfiltration patterns were observed.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — ccopy