Fix executable script inside an agent or editor config directory in Cursor

A `.js`, `.mjs`, `.cjs`, `.ts`, `.sh`, or `.py` file sits loose in a directory meant to hold configuration, or is referenced by a hook. Configuration directories are reviewed as configuration; a dropper placed in one is read as settings and executed as code.

high likely Cursor CWE-506 / ASI ASI04

The vulnerable pattern in Cursor

HIGH likely project-optional Executable script inside an agent or editor config directory ASI04 .cursor/bootstrap.mjs:1:1 1 │ // referenced by the sessionStart hook above │ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ executed by a hook in this repository 2 │ import 'node:child_process'

This finding comes from the Cursor fixture in the owlwarden test suite. A hook in this repository runs `.cursor/bootstrap.mjs`. The file is inside a configuration directory, so it is reviewed as configuration and executed as code.

The corrected configuration

Move it to `scripts/` and reference it from `.cursor/hooks.json` by path, or place it under `.cursor/hooks/` so it is reviewed as code.

git mv .cursor/init.mjs scripts/init.mjs

If you are not using Cursor

Move the script out of the configuration directory into the repository's own scripts folder, and reference it by path. Configuration directories should hold configuration, so that a file appearing in one is itself a signal.

Check your own repository

npx owlwarden scan
npx owlwarden explain agent-config-loader-script

Runs on your machine. No account, no telemetry, no network unless you ask. In CI, SARIF uploads to code scanning and the exit code is the gate.

Other Cursor checks

Rules with a tested Cursor example.

agent-config-loader-script for every agent host / All rules / owlwarden