cursor-advanced-composer
Pass
Audited by Gen Agent Trust Hub on May 5, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The instructions describe standard development workflows involving terminal commands such as
npm test,npm run build, andgit checkout. These are presented as manual or user-approved steps within the Cursor environment to verify code quality and handle rollbacks. - [INDIRECT_PROMPT_INJECTION]: The skill acts on codebase content, which is a potential ingestion point for untrusted data if the repository contains malicious instructions. However, the skill provides extensive 'Quality Control Workflows' and 'Pre-Apply Review Checklists' that instruct users to read every diff, verify types, and check for hallucinations before applying changes, effectively mitigating the risk of accidental obedience.
Audit Metadata