---
title: "skarn"
description: "Skarn for Cursor: audit your AI coding sessions and assistant configs for leaked credentials and risky configuration, and run the pre-execution guard. Backed by the Skarn detection engine on your machine; the skarn binar"
canonical: https://agentpluginsdirectory.com/plugins/skarn
last-updated: 2026-10-11
---

# skarn
Skarn for Cursor: audit your AI coding sessions and assistant configs for leaked credentials and risky configuration, and run the pre-execution guard. Backed by the Skarn detection engine on your machine; the skarn binary is installed separately. It declares one local MCP server, named skarn, with four tools (scan_sessions, vet_configs, list_sessions, session_stats): every tool is read-only, none of them writes or changes a file, none of them makes a network call, and every matched value comes back masked.
- Slug: skarn
- Publisher: Skarn
- Repository: https://github.com/skarn-security/cursor-plugin
- Manifest: plugin.json
- Version: 0.33.0
- License: MIT
- Category (editorial): security
- Skills: 1 (skarn-audit)
- MCP servers: 1 (skarn)
- Stars: 23
- Repository created: 2026-08-25
- Repository last pushed: 2026-10-04
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/skarn
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## What skarn does, in the publisher's words

A Cursor plugin that carries three things: the skarn-audit skill, the pre-execution guard hooks in audit mode, and a declaration for the local skarn MCP server. It carries no binary, no detection rules, and no detection engine. Install the skarn binary separately; everything here invokes it from your PATH.

Pick one:

Or download the release for your platform from https://github.com/skarn-security/skarn-dist/releases/latest and put it on your PATH. Confirm it with skarn --version.

- deny: the action leaks a secret into an exfiltration channel (including a secret pasted into a prompt, which heads to the model provider), installs a likely malicious or typosquatted package, completes a multi-phase attack chain, or trips a critical rule.
- ask: a secret is present but the destination is ambiguous (Cursor prompts the user; shell and MCP only).

From the project README, punctuation lightly normalized. Full text: https://raw.githubusercontent.com/skarn-security/cursor-plugin/HEAD/README.md

## Skills

- skarn-audit: Audit this machine's AI coding sessions and assistant configs with skarn. Use when the user says scan this with skarn, run skarn, or skarn audit; asks whether a secret leaked into an AI coding session; wants an assistant config (hooks, MCP servers, permissions, plugins) vetted; or asks whether a Cl…

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.

## MCP servers

- skarn: transport: stdio; command: skarn mcp

Read from the plugin's own mcp.json. Environment variable names only, never values.
