ccopy
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocess.runto execute platform-specific clipboard management tools to handle the transfer of formatted chat history. - Evidence:
scripts/ccopy/clipboard.pyinvokes commands such aspbcopy,clip.exe,xclip,xsel, andwl-copy. The implementation follows best practices by usingshutil.whichto verify the presence of these utilities before execution. - [EXTERNAL_DOWNLOADS]: The skill declares a dependency on a well-known Python library to provide its command-line interface.
- Evidence:
README.mdandreferences/USAGE.mdinstruct the user to install thetyperpackage viapiporuv. - [DATA_EXFILTRATION]: The skill accesses sensitive local files containing user conversation history from the Cursor editor.
- Evidence: It reads from
~/.config/Cursor/User/(SQLite databases) and~/.cursor/projects/(JSONL transcripts). This access is limited to reading the last complete user/assistant turn and transferring it to the local system clipboard, which is the primary intended function of the skill. No network activity or remote exfiltration patterns were observed.
Audit Metadata