cursor-ai

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent with its stated Cursor-configuration purpose and routes data to expected services, but it relies on unpinned npx-installed MCP servers and forwards sensitive tokens to third-party package code. This is better characterized as moderate supply-chain and credential-forwarding risk than clear malicious behavior.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Mar 13, 2026, 09:16 PM
Package URL
pkg:socket/skills-sh/TerminalSkills%2Fskills%2Fcursor-ai%2F@ccc5ff279b6e3d1ab00459be3ec53cf9df2e2482