github.com / egoist
egoist/ cursor-openai-api
TypeScript·17 files·commit 0f87b81·scanned 1h ago·cached ✓
11/100
LOW RISK
Minor findings consistent with the project type. Nothing reachable from install hooks.
verdict accurate?
CLI tool detected
threat-state: lowlive
FINDINGS ░▒▓
warningHigh-entropy string literalsFound 3 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.src/proxy.ts+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.src/proxy.ts+3
Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.
10 files scanned @ 0f87b81 | 9/25/2026 | heuristic scan — always review manually
risk by category
code execution2
network & exfiltration0
file system access0
obfuscation6
supply chain0
owasp / injection0
telemetry
files 10/17rules hit 3engine v6commit 0f87b81
github
egoist/cursor-openai-api
A standalone CLI that serves Cursor's API as an OpenAI-compatible endpoint.
38
6
189d
17 files
10 scanned(59%)
0f87b81
architecture░▒▓
entry (0) flagged (1) pkg (3)
11 nodes · 12 edgesscroll to zoom · click node to jump to finding