<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>OAuth Scopes on SoloSoft</title><link>https://www.solosoft.dev/tags/oauth-scopes/</link><description>Recent content in OAuth Scopes on SoloSoft</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 02 Oct 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://www.solosoft.dev/tags/oauth-scopes/index.xml" rel="self" type="application/rss+xml"/><item><title>Auditing cursor/plugins: 96 Official Plugins, 9,320 Stars, 2.4% Config — and a CI Gate That Passed an Inline `curl | bash` Hook</title><link>https://www.solosoft.dev/post/cursor-plugins-marketplace-audit/</link><pubDate>Fri, 02 Oct 2026 00:00:00 +0000</pubDate><guid>https://www.solosoft.dev/post/cursor-plugins-marketplace-audit/</guid><description>&lt;p&gt;Cursor&amp;rsquo;s plugin ecosystem lives in one repository: &lt;code&gt;cursor/plugins&lt;/code&gt;, &amp;ldquo;Official Cursor plugins for popular developer tools, frameworks, and SaaS products.&amp;rdquo; I cloned it at commit &lt;code&gt;2eb7ed46&lt;/code&gt; on 1 October 2026 and measured everything I could measure — every manifest, every &lt;code&gt;mcp.json&lt;/code&gt;, every hook script, every licence file, and its own validation gate, which I ran locally and then deliberately attacked with four mutations. Some of what came back is normal for a young monorepo. Some of it is worth knowing before you click Install.&lt;/p&gt;
&lt;p&gt;Here is the headline set: &lt;strong&gt;96 plugins, 887 files, 6,381,913 bytes (6.09 MiB) excluding &lt;code&gt;.git&lt;/code&gt;&lt;/strong&gt; — of which &lt;strong&gt;65.5% is images&lt;/strong&gt;, &lt;strong&gt;19.2% markdown&lt;/strong&gt; and &lt;strong&gt;2.4% JSON&lt;/strong&gt;. 80 of the 96 plugins are remote MCP integrations to third-party SaaS vendors on &lt;strong&gt;70 distinct hosts&lt;/strong&gt;. The repository has 9,320 stars, 883 forks, 41 watchers, 433 commits and a stated MIT licence with &lt;strong&gt;no &lt;code&gt;LICENSE&lt;/code&gt; file at its root&lt;/strong&gt; (GitHub&amp;rsquo;s API reports &lt;code&gt;license: null&lt;/code&gt;).&lt;/p&gt;</description></item></channel></rss>