ccopy
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Mostly purpose-aligned local tooling for exporting Cursor chat history, with no visible network exfiltration or disproportionate credential requests. The main issue is trust: the core ccopy executable is a required local binary whose provenance cannot be verified from the provided material, so the skill is best classified as suspicious/high-risk from a supply-chain standpoint rather than malicious.
Confidence: 82%Severity: 78%
Audit Metadata