cursor-plugin-headroom

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent for a Headroom integration, and the recommended install path appears to be the project's official PyPI package. However, its whole function is to auto-start a third-party local proxy that intermediates later API traffic, so the main risk is data-flow interception and trust in that external runtime rather than obvious malware in the skill itself.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Aug 27, 2026, 04:46 PM
Package URL
pkg:socket/skills-sh/kunanonj%2Fai-skills-hub%2Fcursor-plugin-headroom%2F@cf792e6b9059bde10020b543e851cdff4d6f1a595d1a0a93fcc967d41fb21dd1
Security Audit — socket — cursor-plugin-headroom