Skip to content

Security: GatienBoquet/pi-cursor-cloud-api

Security

SECURITY.md

Security

API keys

Never commit a Cursor API key or place one in a pi-subagents agent profile. Use CURSOR_API_KEY or CURSOR_CLOUD_API_KEY in the environment that launches Pi.

Runner options are persisted by pi-subagents and may appear in diagnostics. This package therefore does not accept session environment variables, inline MCP credentials, or other secrets in runner options.

Reporting a vulnerability

Open a private security advisory through the repository's GitHub Security tab. Do not include active credentials, private repository contents, or Cursor run output in a public issue.

There aren't any published security advisories