cursor-agent
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute the
cursor-agentCLI tool using a shell command template:cursor-agent -p ... "<prompt>". Because<prompt>is derived from the user-supplied$taskargument, this pattern creates a surface for command injection if the agent interpolates shell metacharacters (such as backticks, semicolons, or subshell expansions) without proper escaping.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user input which is then used to direct the behavior of the agent and the external CLI tool.\n - Ingestion points: The
$taskargument defined in the frontmatter ofSKILL.md.\n - Boundary markers: The instructions do not define clear delimiters or "ignore previous instructions" warnings when passing the user's task to the shell or when enriching prompts for code reviews.\n
- Capability inventory: The skill has access to the
Bashtool with permissions to runcursor-agent,git diff,git log, andgit status. This grants it visibility into the local file system and repository history, as well as network communication via thecursor-agentbinary.\n - Sanitization: There are no instructions provided to sanitize, validate, or escape the user's input before it is interpolated into shell commands or prompt templates.
Audit Metadata