cursor-agents

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses run.sh and sanity.sh as standard entry points to invoke its core Python logic and test suite. The implementation uses subprocess.run within the test environment to verify CLI behavior, which is a standard and safe testing pattern.
  • [EXTERNAL_DOWNLOADS]: The skill communicates exclusively with https://api.cursor.com/v1, which is the official endpoint for the Cursor service. This network activity is documented and essential for the skill's primary function of agent orchestration.
  • [CREDENTIALS_SAFE]: API keys are managed via standard environment variables (CURSOR_API_KEY). The code includes explicit logic to ensure these keys are not printed to the console or included in the JSON receipts generated during API calls, preventing accidental credential exposure.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill implements a 'receipt' system that records API request metadata and responses for debugging. These files are stored locally (e.g., in /tmp) and are designed to redact authorization headers, maintaining a secure boundary between operational data and sensitive secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — cursor-agents