What is Cursor Plugins? A catalogue for agent extensions
Cursor plugin security: read permissions before installation
Review executable hooks, prompt files and MCP credentials as separate surfaces
What you will learn
- Inventory effects
- Scope the GitHub token
- Check licensing and updates
Before you start
- A disposable client profile
- One selected plugin
- The pinned repository revision
Turn a promising catalogue entry into a repeatable team decision
Key takeaways
- Hooks can execute local code.
- MCP connectors can transmit data to remote endpoints.
- Schema checks do not constitute a security audit.
Inventory effects
A plugin can package instructions, local hooks and external servers. The pinned continual-learning hook configuration runs a Bun script on `stop`; the GitHub integration uses an HTTP MCP endpoint.
A team should inspect executable files before installation, restrict repository access to plugin updates and test in a disposable profile. Schema validation does not make those effects safe by itself.
Scope the GitHub token
The GitHub manifest requires a personal access token. Its MCP configuration passes that token as a bearer header to the declared endpoint. Grant only the repository and operation scopes needed for the trial.
Do not commit the token or paste it into an article, screenshot or shared log. Review the remote service and the client’s storage path before using a real credential.
Check licensing and updates
The root README says MIT, and individual plugin directories can carry their own licenses. Read the selected plugin license and third-party terms, then pin the reviewed source revision.
This is a threat-model checklist. We did not install a plugin, trace network traffic, test client sandboxing or certify the upstream packages.
Decision guide
| Criterion | Option A | Option B |
|---|---|---|
| Best when | You need predictable behavior and easy auditing | You need adaptive optimization and have reliable telemetry |
| Main risk | May leave performance on the table | Can become difficult to explain or debug |
Implementation steps
- 1
List prompt, script and network surfaces.
- 2
Use a minimal test token only when necessary.
- 3
Pin and review each update before team rollout.
Copy-ready example
selected plugin -> local files and hooks
selected plugin -> MCP endpoint with scoped token
review -> allow, restrict or removeFrequently asked questions
Can I paste a broad GitHub PAT into the manifest?
Keep credentials in the client-supported secret store and scope a trial token narrowly.
Does MIT cover every external service?
No. Check the selected plugin and provider terms separately.
Sources
- Cursor Plugins / README.mdSource checked 2026-10-08
- Cursor Plugins / schemas/plugin.schema.jsonSource checked 2026-10-08
- Cursor Plugins / continual-learning/hooks/hooks.jsonSource checked 2026-10-08
- Cursor Plugins / third_party/github/.cursor-plugin/plugin.jsonSource checked 2026-10-08
- Cursor Plugins / third_party/github/mcp.jsonSource checked 2026-10-08