cursor-headless

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose matches its capabilities and the installer/auth flows are first-party Cursor, so it is not malware-like. Risk remains elevated because it installs an agentic CLI via curl|bash, disables sandboxing by default, and promotes autonomous headless execution with shell/MCP reach.

Confidence: 90%Severity: 62%
Audit Metadata
Analyzed At
Sep 4, 2026, 10:22 AM
Package URL
pkg:socket/skills-sh/wkuczkowski%2Fagent-skills%2Fcursor-headless%2F@7ceac4528362676de5a7e54fbd2b05e2e62ed21f14cba02ac2d48dad68f976ae
Security Audit — socket — cursor-headless