cursor

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent with its stated purpose and uses an official npm package, so it does not look outright malicious. However, it centralizes authentication and API traffic through Membrane as an intermediary instead of direct Cursor endpoints, creating moderate third-party trust, credential-forwarding, and data-flow risk disproportionate to a simple Cursor integration.

Confidence: 82%Severity: 57%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcursor%2F@012e4d4845f28a783d37980656e78cc4ff8635df
Security Audit — socket — cursor