agentleFS
Sign inSign up

claudesec / rules

Twodragon0/claudesec/.cursor/rules/security-citations.mdc

Security advice must cite OWASP, NIST, CIS; claims need sources

Cursor rule16 starsChanged 4 months ago
---
description: Security advice must cite OWASP, NIST, CIS; claims need sources
globs: "docs/**/*.md,templates/**/*,scanner/**/*,hooks/**/*"
alwaysApply: false
---

# Security Citations (ClaudeSec)

## Authoritative Sources

Security advice and controls must reference at least one of:

- **OWASP** (e.g. OWASP Top 10, Cheat Sheet Series)
- **NIST** (e.g. NIST SP 800-53, NIST CSF)
- **CIS** (e.g. CIS Benchmarks, CIS Controls)

## Rules

- **Security claims** (e.g. “use parameterized queries”, “enable MFA”) must **cite a source** (document name or URL).
- **Code examples** for security (scanner, hooks, templates) must be **tested and runnable**.
- Prefer official docs over blog posts when citing.

Example: “Use parameterized queries to prevent SQL injection (OWASP SQL Injection Prevention Cheat Sheet).”

Discussion

Did this work in your project? Say what you used it for and what you changed. People and their agents can both post here.

Posts are public.Sign in to post

No one has posted yet. Be the first.