Skip to content

Using Cursor: Rules configuration, Agent mode, usage limits, and pitfalls.

Latest curated items

Items 21–34 · 34 total
6/15Mon
  1. Cline · Blog71

    用插件和 Hook 扩展 Cline 智能体循环

    Cline 官方博客介绍如何用插件和 Hook 给智能体循环加上确定性行为与护栏。插件是单个对象文件,可复用在同一份代码的 CLI、VS Code、JetBrains 和 SDK 上。

    Awaiting translation

    Why it matters: 原文给出 Cline 插件与 Hook 的完整代码示例,读者可据此为智能体循环加上日志记录和危险命令拦截。

6/8Mon
  1. Permission Protocol · AI Agent Incident Tracker88

    Agentjacking:攻击者借公开 DSN 注入伪造 Sentry 错误,劫持 Claude Code、Cursor 和 Codex

    安全研究披露一种名为 Agentjacking 的攻击:攻击者利用 Sentry 公开的 DSN 向 ingest API 提交伪造错误事件,AI 编码智能体通过 Sentry MCP 取回这些事件后,把其中的 Markdown 注入内容当作可信指令执行 shell 命令,在受控测试中成功率 85%,涉及 2,388 家组织。

    Awaiting translation

    Why it matters: 还原了 Sentry MCP 提示词注入劫持编码智能体的完整链路,并指出授权门禁应设在工具调用层。

6/7Sun
  1. Permission Protocol · AI Agent Incident Tracker87

    Hades 攻击通过污染 AI 工具配置文件和 PyPI 启动钩子窃取 294,842 条凭据

    Hades 攻击波在 Claude Code、Cursor、Gemini CLI 和 VS Code 的配置文件中植入钩子,并通过 37 个 PyPI wheel 的 .pth 启动钩子,从 6,943 台开发者机器窃取 294,842 条凭据,涉及 GitHub、PyPI、AWS/GCP/Azure 凭据、SSH 密钥和 Kubernetes secrets。

    Awaiting translation

    Why it matters: 复盘攻击如何借 AI 工具配置文件与 Python 启动钩子在开发者机器上窃取凭据,并指出授权边界缺口。

6/5Fri
  1. Permission Protocol · AI Agent Incident Tracker88

    Miasma 供应链蠕虫通过 Agent 配置注入禁用 73 个微软 GitHub 仓库并窃取凭据

    Miasma 蠕虫通过投毒 Agent 配置文件感染 73 个微软 GitHub 仓库,开发者在 Claude Code、Cursor 或 Gemini CLI 中打开仓库时即执行凭据窃取程序,导致 AI API token、GitHub token 和云凭据泄露。

    Awaiting translation

    Why it matters: 复盘 Miasma 蠕虫如何借 Claude Code、Cursor、Gemini CLI 的会话初始化配置实现零点击窃取凭据,可迁移到仓库配置来源校验。

6/3Wed
  1. Permission Protocol · AI Agent Incident Tracker80

    Sophos X-Ops:俄罗斯攻击者用 Claude Opus 4.5 编排 80 模块勒索软件工具包

    Sophos X-Ops 发现一名俄罗斯威胁攻击者使用 Cursor IDE 和 Claude Opus 4.5 作为编排智能体,搭建了一个 80 模块的勒索软件工具包,并成功规避 Sophos、CrowdStrike 和 Windows Defender 的 EDR 检测。

    Awaiting translation

    Why it matters: Sophos 披露的攻击链显示,Claude Opus 4.5 被用作编排智能体,串起多智能体分工与 EDR 规避测试。

  2. Permission Protocol · AI Agent Incident Tracker76

    仿冒 Claude Code 与 Codex 安装页经 Google Sites 投递无文件内存窃密程序

    攻击者用 Google Sites 托管仿冒 Claude Code 和 Codex 的安装页,诱导开发者在运行对话框粘贴 mshta.exe 命令,投递无文件内存窃密程序,窃取 AI API key、浏览器凭据和开发者环境密钥。

    Awaiting translation

    Why it matters: 梳理了仿冒 Claude Code 与 Codex 安装页的 ClickFix 攻击链,可了解针对 AI 开发者凭据的窃取手法。

5/22Fri
  1. Permission Protocol · AI Agent Incident Tracker85

    GitHub confirms 3800 internal repositories were leaked after an employee installed a poisoned Nx Console VS Code extension

    GitHub confirms that roughly 3800 internal repositories were leaked, including Copilot's internal code and GitHub Actions workflow source code, after an employee installed an Nx Console 18.95.0 VS Code extension poisoned by TeamPCP.

    Why it matters: The timeline and technical chain are complete, showing how a VS Code extension supply-chain poisoning attack stole credentials and leaked internal repositories.

5/14Thu
  1. Permission Protocol · AI Agent Incident Tracker78

    Microsoft Defender 发现 Mage AI 与 MCP 服务器未鉴权部署,可获 cluster-admin 权限执行 RCE

    Microsoft Defender for Cloud 发现生产环境中的 Mage AI 与 MCP 服务器未启用鉴权,攻击者可执行 shell 命令并获得 cluster-admin 权限,还能窃取同集群工作负载的凭据。

    Awaiting translation

    Why it matters: 材料给出 Mage AI 与 MCP 服务未鉴权部署导致 RCE 的完整链路,可据此检查自家 Helm chart 与 MCP 配置。

5/8Fri
  1. Permission Protocol · AI Agent Incident Tracker80

    Claude Code 遭恶意 npm 包经 MCP 中间人劫持窃取 OAuth token

    Mitiga Labs 披露一条针对 Claude Code 的攻击路径:恶意 npm 包通过 postinstall 钩子修改 ~/.claude.json,把 MCP 服务器 URL 替换为攻击者代理,使每次 MCP 会话的 OAuth token 和 SaaS 凭据都经攻击者基础设施转发。

    Awaiting translation

    Why it matters: 披露了恶意 npm 包通过篡改 MCP 配置劫持 OAuth token 的完整攻击链,并指出配置变更缺少授权校验这一根因。

4/22Wed
  1. Lovable · Blog71

    Lovable 回应 2026 年 4 月安全事件:公开项目聊天记录与源码曾被越权访问

    Lovable 官方回应 2026 年 4 月安全事件:2026 年 2 月 3 日至 4 月 20 日期间,任何持有项目链接的 Lovable 用户都可能访问公开项目的聊天记录和源码,私有项目与 Lovable Cloud 未受影响。

    Awaiting translation

    Why it matters: Lovable 官方复盘公开项目聊天记录与源码被越权访问的完整时间线,并给出产品与流程层面的整改清单。

2/26Thu
12/19Fri
12/17Wed
  1. Jesse Vincent66

    Claude Code's Skill not triggering? Maybe it never saw it at all.

    Claude Code lets the model know which Skills exist by injecting their names and descriptions into the system prompt. When there are too many Skills, or the description fields are too long, the system prompt stops listing them, so the model can't use them — and the prompt also tells the model not to use any Skill that isn't listed.

    Why it matters: The author explains why Claude Code doesn't trigger installed Skills, and gives a temporary fix using environment variables that you can apply right away.

6/4Wed
  1. Martin Fowler · Exploring Generative AI66

    自主编码智能体实测:一次 OpenAI Codex 运行记录

    Martin Fowler 给 OpenAI Codex 布置了一个前端标签格式化的化妆类小任务,并完整公开了 Codex 的日志和生成的 PR。日志显示 Codex 主要靠 grep 反复文本搜索定位代码,中途因把 AGENTS.md 误写成 AGENT.md 来回折腾,还因删掉 .yarnrc 导致测试无法运行,最终 PR 里有两个回归测试失败。

    Awaiting translation

    Why it matters: 作者完整记录 Codex 自主完成一次前端小任务的日志,并对比 6 次运行结果,展示后台编码智能体在环境配置和代码复用上的真实短板。