cursor-headless
Warn
Audited by Socket on Sep 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s purpose matches its capabilities and the installer/auth flows are first-party Cursor, so it is not malware-like. Risk remains elevated because it installs an agentic CLI via curl|bash, disables sandboxing by default, and promotes autonomous headless execution with shell/MCP reach.
Confidence: 90%Severity: 62%
Audit Metadata