Repository navigation
v0.6.6: security fix for Cursor on Windows
Update now if you use Cursor on Windows. Cursor on Windows sends hook events with a UTF-8 byte-order mark. Squidbrake's hook couldn't read them and answered "allow" without checking, so Cursor's agent commands went through unchecked. The hooks now read events with or without the mark (and in any console code page), and an event they can't read is now blocked, not allowed.
Also: squidbrake doctor reads Cursor's own hooks log and says plainly that the agent (not you, typing in the terminal) has to run a command for the hook to be used.
To update: run the install command from your start page again, then squidbrake doctor.