Agent skills need npm install, not copy-paste. I built ski to manage skills from Git across Claude, Codex, and Cursor with reproducible installs.
https://t.co/0qQjfyBSpJ
Delved into Cursor 3.0 -- turns out there's some interesting shenanigans going on....
"The most newsworthy finding is that "Cursor Agent" is a rebranded Claude Code running behind a local proxy with a find-and-replace engine that swaps "Claude"โ"Cursor" in system prompts and messages.
They bundle the full @anthropic-ai/claude-agent-sdk and @anthropic-ai/claude-code packages, plus a custom fine-tuned model (claude-3.7-sonnet-finetuned-cursor-20250514-v1)"
Full report https://t.co/AaGPQIxUNz
26 LLM routers are secretly injecting malicious tool calls and stealing creds. One drained our client $500k wallet.
We also managed to poison routers to forward traffic to us. Within several hours, we can directly take over ~400 hosts.
Check our paper: https://t.co/zyWz25CDpl