Get a demo — 30 minutes →
Skill scan report

reproduce-and-fix-issues

View on GitHub
35 Medium Automated analysis flagged 2 potential risk patterns.

What this skill does

The skill 'reproduce-and-fix-issues' is designed to reproduce triaged bugs in an app through a configured control adapter, verify existing fixes, and open a bounded draft pull request only after befor

github/cursor - Security Misconfiguration - 2.6k stars

ThreatsSecurity Misconfiguration Access Control

Threat analysis

Security Misconfiguration1 finding
Access Control1 finding

Skill info

Namecursor/reproduce-and-fix-issues
Registrygithub
Version9490cc1
PURLpkg:github/cursor/plugins@9490cc1?skill=reproduce-and-fix-issues
Stars2.6k

Assessments (2)

Security Misconfiguration1 finding HIGH
HIGH

Security Misconfiguration via local-llm-review

SKILL.md

The skill's `disable-model-invocation: true` setting may be a red flag if not properly justified. It could be an obfuscation technique to hide malicious behavior, or it could be a legitimate safety me
Access Control1 finding MEDIUM
MEDIUM

Access Control via local-llm-review

SKILL.md

The skill allows for 'fix-phase code workers' to edit code only when their environment 'provably excludes Slack credentials and every Slack write action.' This depends on the implementation of the env

Badge

Add the Anomity scan badge for reproduce-and-fix-issues to your README.

Anomity Skill Check badge

Markdown
[![Anomity Skill Check](https://anomity.ai/skills/badge.svg)](https://anomity.ai/skills/github/cursor/reproduce-and-fix-issues/)
HTML
<a href="https://anomity.ai/skills/github/cursor/reproduce-and-fix-issues/"><img src="https://anomity.ai/skills/badge.svg" alt="Anomity Skill Check"></a>
Image URL
https://anomity.ai/skills/badge.svg

How Anomity governs this at runtime

Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.

Book a 30-minute demo to see your own skill inventory.

Methodology and disputes

Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of reproduce-and-fix-issues? Report an issue or request a rescan.

Ask AI about Anomity
ChatGPT Claude Perplexity Google AI Grok