cursor-coding-agent

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned as a Cursor delegation guide, but it materially expands execution trust by routing coding tasks to an external proprietary agent, often with `--trust` and optional background execution. No clear credential harvesting or covert exfiltration is present, so this is not confirmed malware; the main concern is high operational/supply-chain risk from delegating repo access and actions to a largely unverifiable external CLI.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
Apr 14, 2026, 03:31 AM
Package URL
pkg:socket/skills-sh/patrick-fu%2Fawesome-skills%2Fcursor-coding-agent%2F@55d32358a34d88714f4d29c553f7a7db6aac447d
Security Audit — socket — cursor-coding-agent