Skip to content

src/cursor_mcp_plugin/code.js:75 is the clearest consequential seam in the repo. #162

@Onechan

Description

@Onechan

This is not a vulnerability report.

I reviewed grab/cursor-talk-to-figma-mcp and would tighten one path first.

src/cursor_mcp_plugin/code.js:75 is the clearest consequential seam in the repo.

A vendor-side action often becomes consequential at the final request or checkout step, not at task start.

I would start by guarding the click or checkout path itself before widening anything else.

I can send the exact first patch if useful.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions