use-cursorManage Cursor CLI tasks via tmux with security hardening
Install via ClawdBot CLI:
clawdbot install brucezhu888/use-cursorGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
rm -rf /Calls external URL not in known-safe list
https://github.com/openclaw/skills/tree/main/use-cursorAI Analysis
The skill's primary risk is the tmux pane execution model, which could theoretically allow shell command injection despite argument escaping. However, it explicitly declares its actions, implements security mitigations (escaping, literal mode), and does not send data to unauthorized external servers. The external URL is the skill's documented source repository.
Audited Apr 17, 2026 · audit v1.0
Generated Aug 14, 2026
A developer needs to refactor a large codebase without blocking their local environment. The skill spawns a Cursor CLI task in a tmux session, allowing the main agent to continue other work and check progress asynchronously.
In a continuous integration pipeline, automated code reviews or test generation can be triggered non-interactively. The skill's non-interactive mode with JSON output integrates into existing scripts for automated feedback.
During pair programming or rapid prototyping, a user can invoke Cursor directly for quick tasks like generating boilerplate or explaining code snippets, with the tmux management allowing session persistence.
In a corporate or shared development environment, the isolated mode restricts environment variables and path, reducing risk when processing untrusted code. This is useful for code review tools that handle external contributions.
For complex features or large migrations that take hours, the background mode allows starting a task, detaching from the session, and reattaching later. The interrupt/resume capabilities make it suitable for extensive refactors.
Offer a platform that integrates this skill to provide AI-assisted coding automation as a service, charging subscription fees for usage-based computing and enhanced features.
Open-source the skill, offering advanced management features, security hardening, and dedicated support at a premium tier for enterprises.
Provide consulting to integrate this skill into existing development workflows, including custom scripts, containerization, and training.
💬 Integration Tip
Ensure tmux and the Cursor CLI are pre-installed and authenticated, and set the CURSOR_API_KEY environment variable to avoid interactive login prompts.
Scored May 31, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST sc...