cursor-composer-workflows

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Cursor Composer Workflows skill is conceptually aligned with its stated purpose of facilitating multi-file AI edits and scaffolding within a Cursor-based workflow. There are no evident credential, exfiltration, or malicious behaviors. The primary risk area lies in potential shell command execution via allowed Bash(cmd:*) if invoked by user prompts; otherwise, the footprint is consistent with a developer-focused productivity tool operating entirely within the local project workspace. Overall, the risk is low to moderate (securityRisk ~0.35) and considered benign with standard usage.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 12:00 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fcursor-composer-workflows%2F@e6b67bf8e46ced51e5b8f0d2781110cd81d19540