Skarn plugin for Cursor: the session and config audit skill, the local skarn MCP server declaration, and the pre-execution guard hooks. Generated at each Skarn release; do not hand-edit.
A Cursor plugin that carries three things: the skarn-audit skill, the pre-execution guard hooks in audit mode, and a declaration for the local skarn MCP server. It carries no binary, no detection rules, and no detection engine. Install the skarn binary separately; everything here invokes it from your PATH.
Or download the release for your platform from https://github.com/skarn-security/skarn-dist/releases/latest and put it on your PATH. Confirm it with skarn --version.
Once the listing is approved, install it from the Cursor Marketplace. Until then, and for development, put this repository where Cursor reads local plugins:
If you already have a checkout, copy it there instead; a symlink does not work, because Cursor refuses a local plugin whose symlink target lies outside ~/.cursor/plugins/local (measured on Cursor 3.17.19, which logs loadUserLocalPlugin skarn rejected: symlink target ... is outside):
The local directory does not exist on a profile that has never installed a local plugin, which is why both forms create it first.
Then run Developer: Reload Window. Settings Tools & MCPs lists skarn under Plugin MCP Servers as 4 tools enabled, and its Configure dialog shows Local Connected with scansessions, vetconfigs, listsessions, and sessionstats. Cursor loads plugin MCP servers only while you are signed in to a Cursor account: signed out, every plugin server (not only this one) shows Error - Show Output with [unauthenticated] Error in the output panel, before the binary is ever looked for.
From the project README.
Add the radar badge to your README — it shows your project was picked up by MCP Radar and links to this page:
[](https://mcp.liqiwa.com/s/skarn-security--cursor-plugin.html)
The top new MCP servers of the week, every Monday. No spam, unsubscribe anytime.