omega-cursor-cli

Warn

Audited by Socket on Mar 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is a legit-looking headless wrapper for the Cursor Agent CLI, but its design includes several risky patterns. The main concerns are autonomy abuse (explicit encouragement to bypass interactive approvals via --yolo and --trust), the ability to read and append local workspace memory files (which can be sent to Cursor), and runtime execution of third-party code (PATH discovery and npx fallback). These combine to create a realistic risk of unintended data disclosure or credential exposure to an external service (Cursor or any compromised cursor-agent package). There are no obvious signs of deliberately obfuscated or hardcoded malicious payloads in the provided text, but the operational choices (trust bypass, transitive execution) materially increase supply-chain and exfiltration risk. Recommend: require explicit user consent (avoid --yolo/--trust by default), avoid automatic npx fallsbacks or require pinned versions & checksums, and restrict what workspace files are read/sent. Treat this skill as medium-to-high security risk unless usage is explicitly controlled and audited.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 2, 2026, 04:35 AM
Package URL
pkg:socket/skills-sh/oimiragieo%2Fagent-studio%2Fomega-cursor-cli%2F@38792c11c77c9763ecde94f6cfaf1c35bdd50adb