Skip to content

Support Cursor and Windsurf hook systems #1

@kobzevvv

Description

@kobzevvv

Cursor and Windsurf have programmable hook systems similar to Claude Code PreToolUse. Windsurf Cascade hooks support pre_run_command, pre_write_code, pre_mcp_tool_use with the same exit-code-2-to-block architecture. 94 unpatched CVEs affect Cursor and Windsurf (1.8M developers). Proposal: create install-hooks-windsurf.mjs, add Cursor allowlist integration, auto-detect which agents are installed. References: CVE-2026-22708 (Cursor sandbox bypass via shell builtins), IDEsaster research (30+ CVEs across all major IDEs).

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions