cursor-compliance-audit
Installation
SKILL.md
Cursor Compliance Audit
Overview
Assess a Cursor deployment against approved privacy, identity, source-code, and audit controls. This is an evidence-backed configuration review, not legal certification.
Prerequisites
- A named system owner, applicable controls, and authority to inspect tenant settings.
- Read-only admin evidence, current access roster, and redaction rules for audit artifacts.
- Legal/compliance review for regulated data, customer commitments, or PHI/PCI scope.
Instructions
- Define the tenant, repositories, data classes, and control period in scope.
- Compare privacy, retention, identity, access review, and
.cursorignoresettings to the approved baseline. - Record findings with evidence, owner, severity, due date, and verification method.
- Escalate suspected sensitive-code exposure before broad configuration changes.
Compliance and security auditing framework for Cursor IDE usage. Covers SOC 2, GDPR, and HIPAA assessment with audit checklists, evidence collection, and remediation guidance.