ccopy

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Mostly purpose-aligned local tooling for exporting Cursor chat history, with no visible network exfiltration or disproportionate credential requests. The main issue is trust: the core ccopy executable is a required local binary whose provenance cannot be verified from the provided material, so the skill is best classified as suspicious/high-risk from a supply-chain standpoint rather than malicious.

Confidence: 82%Severity: 78%
Audit Metadata
Analyzed At
Aug 26, 2026, 06:01 PM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fccopy%2F@c22e3b733335bdd3800120e0b664a19f89196af49b2f0ee9dab4f0db5a100ba6
Security Audit — socket — ccopy