Agent skill

Cursor Compliance Audit

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Compliance and security auditing for Cursor IDE usage: SOC 2, GDPR, HIPAA assessment, evidence collection, and remediation.

MITAuto-check: notesLegal & Compliance

Install Cursor Compliance Audit

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill cursor-compliance-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace cursor-compliance-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/cursor-compliance-audit .claude/skills/cursor-compliance-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cursor-compliance-audit
GitHub stars
2.8k
Token cost
~2.3k tokens
SKILL.md length
498 words
Files
8 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Compliance and security auditing for Cursor IDE usage: SOC 2, GDPR, HIPAA assessment, evidence collection, and remediation.

  • Works in 4 steps: Define the tenant, repositories, data… → Compare privacy, retention, identity,… → Record findings with evidence, owner,… → …
  • Cursor compliance
  • SKILL.md covers Overview, Prerequisites, Instructions and Cursor Security Posture, plus 9 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Cursor Compliance Audit is an agent skill from jeremylongshore/tons-of-skills-marketplace. Compliance and security auditing for Cursor IDE usage: SOC 2, GDPR, HIPAA assessment, evidence collection, and remediation. Triggers on "cursor compliance", "cursor audit", "cursor security review", "cursor soc2", "cursor gdpr", "cursor data governance".

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `references/audit-procedures.md`, `references/audit-tools.md` and `references/compliance-by-framework.md`). Compatibility notes: Designed for Claude Code

It sits in Legal & Compliance, covering SOC 2 and security compliance, Privacy and GDPR and Healthcare and finance regulation. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Cursor compliance
  • Cursor security review
  • Cursor data governance

Example prompts

  • “cursor compliance”
  • “cursor audit”
  • “cursor security review”
  • “/cursor-compliance-audit”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash(cmd:*)

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Define the tenant, repositories, data classes, and control period in scope.
  2. Compare privacy, retention, identity, access review, and .cursorignore settings to the approved baseline.
  3. Record findings with evidence, owner, severity, due date, and verification method.
  4. Escalate suspected sensitive-code exposure before broad configuration changes.

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash(cmd:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cursor.com
    • docs.cursor.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Cursor Compliance Audit loads about 2.3k tokens when it runs, and up to ~4.1k if it reads all its reference files. Until then it costs about 70 tokens; SKILL.md has 498 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~70
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:230
    2. Add patterns for: .env*, secrets/, credentials/, PII directories

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 498 words, ~2,343 tokens.

Download SKILL.mdSave it as .claude/skills/cursor-compliance-audit/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
cursor-compliance-audit
description
Compliance and security auditing for Cursor IDE usage: SOC 2, GDPR, HIPAA assessment, evidence collection, and remediation. Triggers on "cursor compliance", "cursor audit", "cursor security review", "cursor soc2", "cursor gdpr", "cursor data governance".
allowed-tools
Read, Write, Edit, Bash(cmd:*)
compatibility
Designed for Claude Code
version
1.19.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, cursor, security, compliance, audit

Cursor Compliance Audit

Overview

Assess a Cursor deployment against approved privacy, identity, source-code, and audit controls. This is an evidence-backed configuration review, not legal certification.

Prerequisites

  • A named system owner, applicable controls, and authority to inspect tenant settings.
  • Read-only admin evidence, current access roster, and redaction rules for audit artifacts.
  • Legal/compliance review for regulated data, customer commitments, or PHI/PCI scope.

Instructions

  1. Define the tenant, repositories, data classes, and control period in scope.
  2. Compare privacy, retention, identity, access review, and .cursorignore settings to the approved baseline.
  3. Record findings with evidence, owner, severity, due date, and verification method.
  4. Escalate suspected sensitive-code exposure before broad configuration changes.

Compliance and security auditing framework for Cursor IDE usage. Covers SOC 2, GDPR, and HIPAA assessment with audit checklists, evidence collection, and remediation guidance.

Cursor Security Posture

Certifications and Attestations
CertificationStatusNotes
SOC 2 Type IICertifiedAnnual audit, report available on request
Penetration testingAnnualResults shared under NDA (Enterprise)
Encryption at restAES-256All stored data
Encryption in transitTLS 1.2+All API communications
Zero data retentionAvailableVia Privacy Mode
GDPR complianceYesEU data processing supported
HIPAA BAANot available (as of early 2026)See HIPAA section
Data Processing Architecture
Developer Machine
    │
    ├─► Cursor Client ──► Cursor API (US/EU) ──► Model Provider
    │   (local)           (routing + auth)        (OpenAI/Anthropic)
    │                           │
    │                           └─► Zero retention agreement
    │
    ├─► Codebase Index ──► Embedding API ──► Turbopuffer (vectors)
    │                      (no plaintext stored)
    │
    └─► Local Settings (API keys, preferences)
        (never transmitted)

Audit Checklist: SOC 2

CC6.1 — Logical Access Controls
[ ] SSO (SAML/OIDC) configured and enforced
[ ] MFA enabled at Identity Provider level
[ ] RBAC roles assigned: Owner, Admin, Member
[ ] Inactive users deprovisioned (SCIM or manual)
[ ] Access review completed (quarterly)

Evidence:
  - SSO configuration screenshot from admin dashboard
  - IdP MFA policy documentation
  - User list export from Cursor admin
  - SCIM sync logs (if applicable)
CC6.6 — System Boundaries
[ ] Privacy Mode enforced at team level
[ ] .cursorignore configured for sensitive files
[ ] Data classification aligned with .cursorignore patterns
[ ] Model provider data retention agreements documented
[ ] BYOK configuration documented (if applicable)

Evidence:
  - Privacy Mode enforcement screenshot
  - .cursorignore file contents (committed to git)
  - Cursor data use policy acceptance
  - API key provider agreements
CC6.7 — Data Transmission Security
[ ] All Cursor API calls use TLS 1.2+
[ ] Corporate proxy configured with valid certificates
[ ] No self-signed certificates or TLS bypasses
[ ] Network firewall rules documented

Evidence:
  - Network architecture diagram showing Cursor data flows
  - Firewall rules for cursor.com domains
  - Proxy configuration settings
CC7.2 — Monitoring
[ ] Admin dashboard usage analytics reviewed monthly
[ ] Anomalous usage patterns investigated
[ ] Seat utilization tracked for access reviews

Evidence:
  - Monthly usage report screenshots
  - Incident response log for anomalies
  - User activity summary

Audit Checklist: GDPR

Data Mapping
Data Category: Source code snippets
Processing Purpose: AI-assisted code generation
Legal Basis: Legitimate interest (developer productivity)
Data Location: In-transit only (zero retention with Privacy Mode)
Sub-processors: OpenAI, Anthropic, Turbopuffer (embeddings)
Retention: None (Privacy Mode) or per provider policy (no Privacy Mode)
Individual Rights
RightCursor Support
Right to accessAccount settings at cursor.com/settings
Right to erasureAccount deletion removes all server-side data
Right to portabilitySettings export (settings.json)
Right to restrictionPrivacy Mode limits processing
Right to objectPrivacy Mode + .cursorignore
GDPR Compliance Checklist
[ ] Data Processing Agreement (DPA) signed with Cursor (Enterprise)
[ ] Privacy Mode enabled for all EU team members
[ ] Sub-processor list reviewed (cursor.com/privacy)
[ ] Data protection impact assessment (DPIA) completed
[ ] Team briefed on not pasting PII into Chat/Composer

Evidence:
  - Signed DPA
  - Privacy Mode enforcement confirmation
  - DPIA document
  - Team training records

HIPAA Assessment

Current status: Cursor does not offer a Business Associate Agreement (BAA) as of early 2026.

Mitigations for Healthcare Organizations
If your organization handles PHI:

1. Enable Privacy Mode (mandatory)
2. Configure .cursorignore to exclude ALL PHI-containing files:
   .cursorignore:
     **/patient-data/
     **/medical-records/
     **/hl7/
     **/fhir-resources/
     **/*.hl7
     **/*.ccda

3. Consider BYOK through Azure with BAA:
   - Azure OpenAI has HIPAA BAA option
   - Route Cursor AI requests through Azure
   - Azure handles data governance

4. Train developers: NEVER paste PHI into Chat or Composer
5. Code review policy: verify no PHI in AI-generated code

6. CRITICAL: Consult your compliance team before any Cursor
   usage with systems that process PHI

Remediation Playbook

Finding: Privacy Mode Not Enforced
Severity: High
Risk: Code may be retained by model providers for training

Remediation:
1. Admin Dashboard > Privacy > Enable enforcement (immediate)
2. Notify all team members (email)
3. Verify enforcement: check each member's status in dashboard
4. Document: date of enforcement, approval authority
Finding: No .cursorignore
Severity: Medium
Risk: Sensitive files may be included in AI context

Remediation:
1. Create .cursorignore at project root
2. Add patterns for: .env*, secrets/, credentials/, PII directories
3. Commit to git (PR review required)
4. Verify: Cursor Settings > Codebase Indexing > View included files
5. Confirm sensitive files absent from indexed list
Show full SKILL.md (199 more words)Show less
Finding: Unmanaged API Keys (BYOK)
Severity: Medium
Risk: Shared or unrotated API keys

Remediation:
1. Audit which team members use BYOK keys
2. Verify keys are personal (not shared team keys)
3. Implement quarterly key rotation schedule
4. Document key management policy
5. Consider centralizing through Azure gateway (Enterprise)
Finding: No Access Review
Severity: Medium
Risk: Former employees retaining Cursor access

Remediation:
1. Export current member list from admin dashboard
2. Cross-reference with HR active employee list
3. Deactivate accounts for departed employees
4. Enable SCIM for automatic deprovisioning
5. Schedule quarterly access reviews

Enterprise Considerations

  • SOC 2 report: Request directly from Cursor (Enterprise plan) or via your account manager
  • Vendor risk assessment: Use Cursor's security page (cursor.com/security) as starting input
  • Third-party audit: Cursor's SOC 2 report covers their controls; your audit covers your configuration
  • Continuous monitoring: Set calendar reminders for quarterly access reviews and annual policy updates

Output

  • A dated audit record with redacted evidence and control-by-control status.
  • A remediation register with owners, deadlines, and verification criteria.

Error Handling

ConditionSafe response
Admin evidence is incompleteMark the control unverified; do not infer compliance from plan level or screenshots alone.
Sensitive code may have been exposedActivate the incident process, restrict evidence distribution, and consult security/privacy owners.
A policy conflicts with tenant configurationKeep the restrictive policy in effect and escalate for a documented decision.

Examples

For a privacy-mode control, capture the enforced tenant setting and a sampled member status, redact personal identifiers, and record the reviewer and date. If enforcement is absent, create a high-severity finding, assign the tenant admin, and verify again after the approved change.

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (references) in skills/.curated/cursor-compliance-audit of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/audit-procedures.md
  • references/audit-tools.md
  • references/compliance-by-framework.md
  • references/errors.md
  • references/examples.md
  • references/remediation.md
  • references/security-audit-checklist.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Cursor Compliance Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cursor Compliance Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cursor Compliance Audit this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2.3kAutomated safety check: NotesMIT
Implementing Complianceancoleman/ai-design-components525—~4kAutomated safety check: PassMIT
Cometchat Compliancecometchat/cometchat-skills132—~1.7kAutomated safety check: PassMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Security Compliancesangrokjung/claude-forge8522 repos~7.2kAutomated safety check: PassMIT
Ciso Advisoralirezarezvani/claude-skills28k1 repos~1.8kAutomated safety check: PassMIT

Similar skills

  • Implementing Compliance

    ancoleman/ai-design-components

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

    525 GitHub stars~4k tokensUpdated 10 mo ago
    Legal & ComplianceAuto-check passed
  • Cometchat Compliance

    cometchat/cometchat-skills

    Data governance & compliance for CometChat — pick the data-residency region, satisfy GDPR/CCPA (right-to-erasure and data export), plan message retention & purge, and produce audit / eDiscovery…

    132 GitHub stars~1.7k tokensUpdated 6 days ago
    Legal & ComplianceAuto-check passed
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Security Compliance

    sangrokjung/claude-forge

    Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

    852 GitHub starsUsed in 2 repos~7.2k tokens
    Legal & ComplianceAuto-check passed
  • Ciso Advisor

    alirezarezvani/claude-skills

    Security leadership for growth-stage companies. An agent skill from alirezarezvani/claude-skills.

    28k GitHub starsUsed in 1 repo~1.8k tokens
    Legal & ComplianceAuto-check passed
  • Data Breach Blast Radius

    github/awesome-copilot

    Official

    Pre-breach impact analysis: inventories sensitive data (PII, PHI, PCI-DSS, credentials), traces data flows, scores exposure vectors, and produces a regulatory blast radius report with fine ranges…

    40k GitHub starsUsed in 1 repo~3.6k tokens
    Legal & ComplianceAuto-check: notes

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Cursor Compliance Audit

What does Cursor Compliance Audit do?

Compliance and security auditing for Cursor IDE usage: SOC 2, GDPR, HIPAA assessment, evidence collection, and remediation. Cursor Compliance Audit is an agent skill from jeremylongshore/tons-of-skills-marketplace. Compliance and security auditing for Cursor IDE usage: SOC 2, GDPR, HIPAA assessment, evidence collection, and remediation.

When should I use Cursor Compliance Audit?

Cursor Compliance Audit fits situations like: Cursor compliance; Cursor security review; Cursor data governance.

How do I install Cursor Compliance Audit in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill cursor-compliance-audit -a claude-code`. Or copy the skill folder (skills/.curated/cursor-compliance-audit in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/cursor-compliance-audit in your project. Claude Code loads it when a task matches its description.

How do I install Cursor Compliance Audit in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill cursor-compliance-audit -a codex`. Or copy the skill folder (skills/.curated/cursor-compliance-audit in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/cursor-compliance-audit in your project. Codex loads it when a task matches its description.

Can I use Cursor Compliance Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill cursor-compliance-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cursor-compliance-audit, .gemini/skills/cursor-compliance-audit, .github/skills/cursor-compliance-audit and .opencode/skills/cursor-compliance-audit in your project.

What does Cursor Compliance Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Cursor Compliance Audit is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(cmd:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Cursor Compliance Audit access the network?

SKILL.md names 2 domains. As links in the text: cursor.com and docs.cursor.com. This is read from the text; nothing was executed.

Is Cursor Compliance Audit safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Cursor Compliance Audit use?

Cursor Compliance Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cursor Compliance Audit use?

About 2.3k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.

What are the alternatives to Cursor Compliance Audit?

Skills that share tags, products or a category with Cursor Compliance Audit: Implementing Compliance (ancoleman/ai-design-components, 525 stars), Cometchat Compliance (cometchat/cometchat-skills, 132 stars), Audit Report (harness/harness-skills, 115 stars) and Security Compliance (sangrokjung/claude-forge, 852 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cursor Compliance Audit?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.