agentleFS
Sign inSign up

Cursor rules examples

The rules real projects give Cursor's agent, from .cursor/rules.

Best matches · from page 8Worked for most · soon
Zulut30Cursor rule

dart-mobile-game-studio / agents

Zulut30/dart-mobile-game-studio/.cursor/rules/agents/security-auditor.mdc

Security & privacy auditor for Flutter/Dart mobile games (iOS + Android). Use to find data leaks, insecure storage/network, hardcoded secrets, over-broad permissions (Android INTERNET/location/AD_ID, iOS usage strings), unsafe APIs, and kids-privacy violations — tracking, ads (google_mobile_ads), analytics/Crashlytics, AdvertisingId (IDFA/GAID), Firebase telemetry, external links — across BOTH Apple Kids Category and Google Play Families. Read-only: reports risks and concrete fixes, never edits.

13mo agoDiscuss
n-shadlooCursor rule

frontend-production-engineer / rules

n-shadloo/frontend-production-engineer/.cursor/rules/frontend-production-engineer.mdc

Production-grade frontend engineering for Next.js and TypeScript against a Django/DRF backend — plan first, verify the installed versions, never invent an API, keep the diff minimal, run the checks, and hold the work to a stated definition of done. Covers routing and rendering, the server/client boundary, the React component tree, the typed backend contract, and the non-functional guarantees (accessibility, security, performance, testing) that gate completion. All twenty-four domains are integrated; the router in SKILL.md is the authoritative list of what is loadable. Canonical instructions live in SKILL.md and references/.

27d agoDiscuss
mchittineniCursor rule

cloud-platform-skills / skills

mchittineni/cloud-platform-skills/.cursor/rules/skills/ai-agent-security-llm-threats.mdc

Security for LLM and agent systems: direct and indirect prompt injection, the OWASP Top 10 for LLM Applications, MITRE ATLAS technique mapping, excessive agency and tool-scope containment, egress allowlisting to stop data exfiltration, human confirmation for irreversible actions, and treating third-party skills and MCP servers as untrusted code. Use when an agent is given tools or credentials, when retrieved documents or repository files could carry injected instructions, or when reviewing an AI feature before it reaches production.

143d agoDiscuss
anmolnagpalCursor rule

devops-skills / rules

anmolnagpal/devops-skills/.cursor/rules/logging.mdc

Review whether security-relevant logging is enabled, complete, shipped off-host, and tamper-resistant across Kubernetes and the cloud control plane. Use when user says 'review my audit logging', 'is audit logging on', 'check my k8s audit policy', 'are we logging API-server access', 'review GKE/AKS logging', 'do we capture admin activity', or when working in audit-policy.yaml, kube-apiserver manifests, or GKE/AKS Terraform. Covers generic Kubernetes audit policy, GKE Cloud Logging + audit config, AKS diagnostic settings, and cross-cloud audit-log immutability. For AWS CloudTrail/flow-log/EKS-audit/S3-access IaC use /clouddrove:tf (SEC-LOG-*); for log retention/centralization, metrics, and SLOs use /clouddrove:observability (OBS-LOG-*).

832d agoDiscuss
MANVENDRA-githubCursor rule

secrets-management

MANVENDRA-github/agentry/.cursor/rules/secrets-management.mdc

Handle a secret across its whole lifecycle — keep it out of source and image layers, inject it at runtime via environment or a secret store, scope each credential to least privilege, and rotate on a schedule and immediately after exposure. Invoke when code needs an API key, DB password, token, or private key, or when wiring how an app obtains its secrets. Complements the secret-scan hook (which only blocks committing a literal) and security-review (which only flags secrets in your diff). Skip for code that handles no credentials.

03mo agoReads credentialsDiscuss
adammatthewsteinbergerCursor rule

claudeloop / rules

adammatthewsteinberger/claudeloop/.cursor/rules/claudeloop-quality-gates.mdc

Covers how to run and FIX every quality gate in this repo — ruff (lint + format), mypy --strict, pytest with per-layer coverage, import-linter (lint-imports), bandit, and pip-audit. Use this whenever a quality gate fails locally or in CI, whenever the user asks how to lint, format, type-check, or run security scans on this codebase, or before opening a PR to run the full gate set proactively. Make sure to consult this whenever a ruff, mypy, lint-imports, or bandit error appears in tool output — it gives the exact fix command for each gate rather than requiring you to guess at generic remediation.

144d agoDiscuss
dirnbauerCursor rule

webconsulting-skills / rules

dirnbauer/webconsulting-skills/.cursor/rules/security-audit.mdc

Use the security-audit Agent Skill when relevant; read the full skill directory before acting.

332mo agoDiscuss
dirnbauerCursor rule

webconsulting-skills / rules

dirnbauer/webconsulting-skills/.cursor/rules/typo3-security.mdc

Use the typo3-security Agent Skill when relevant; read the full skill directory before acting.

332mo agoReads credentialsDiscuss
dirnbauerCursor rule

webconsulting-skills / rules

dirnbauer/webconsulting-skills/.cursor/rules/security-incident-reporting.mdc

Use the security-incident-reporting Agent Skill when relevant; read the full skill directory before acting.

332mo agoDiscuss
affaan-mCursor rule

ECC / rules

affaan-m/ECC/.cursor/rules/common-agents.md

Agent orchestration: available agents, parallel execution, multi-perspective analysis

246k30d agoDiscuss
affaan-mCursor rule

ECC / rules

affaan-m/ECC/.cursor/rules/common-patterns.md

Common patterns: repository, API response, skeleton projects

246k30d agoDiscuss
DietrichGebertCursor rule

ponytail / rules

DietrichGebert/ponytail/.cursor/rules/ponytail.mdc

Ponytail, lazy senior dev mode. Always pick the simplest solution that works.

143k4mo agoDiscuss
PostHogCursor rule

posthog / rules

PostHog/posthog/.cursor/rules/django-python.mdc

Rules for writing Python services at PostHog (Python servers powered by the Django framework)

40k5d agoDiscuss
MicrosoftCursor rule

data-formulator / rules

microsoft/data-formulator/.cursor/rules/error-response-safety.mdc

Prevent information exposure through exception messages in HTTP responses

17k5mo agoDiscuss
MicrosoftCursor rule

data-formulator / rules

microsoft/data-formulator/.cursor/rules/path-safety.mdc

路径安全编码规范 — 编辑路由/Agent/Loader/Workspace/知识库代码时自动提醒

17k5mo agoDiscuss
airweave-aiCursor rule

airweave / rules

airweave-ai/airweave/.cursor/rules/api-layer.mdc

mappings (10min TTL). API keys are encrypted before use as cache keys for security. All cache operations fail gracefully—errors are logged but never block requests. Integrated into `deps.py

6.6k6mo agoDiscuss
airweave-aiCursor rule

airweave / rules

airweave-ai/airweave/.cursor/rules/backend-rules.mdc

search functionality - **Automatic Tracking**: All search operations (regular, streaming, legacy) tracked uniformly via `SearchService` ### Security - Never use `random.*` for security-sensitive values — ruff rule `S311` bans it - Use `secrets.choice()`, `secrets.randbelow

6.6k6mo agoReads credentialsDiscuss
airweave-aiCursor rule

airweave / rules

airweave-ai/airweave/.cursor/rules/connect-widget.mdc

useParentMessaging`) The widget runs in an iframe and communicates with the parent via `postMessage`. **SECURITY: Origin validation is enforced for postMessage:** The Connect widget captures the parent origin from

6.6k6mo agoReads credentialsDiscuss
airweave-aiCursor rule

airweave / rules

airweave-ai/airweave/.cursor/rules/crud-layer.mdc

Comprehensive guide for understanding and working with the CRUD layer in Airweave backend

6.6k6mo agoDiscuss
airweave-aiCursor rule

airweave / rules

airweave-ai/airweave/.cursor/rules/frontend-rules.mdc

Memoization for expensive computations - Callback refs for stable references - Lazy loading for route components ## Security Considerations ### 1. **Token Management** - Tokens never exposed in URLs - Automatic cleanup on logout - Secure storage

6.6k6mo agoDiscuss
CLAUDE.md vs AGENTS.md

About cursor rules

What are cursor rules?

Instruction files for Cursor's agent, kept in .cursor/rules/ as .mdc files.

How are they different from AGENTS.md?

A rule can apply only to files matching a pattern, or only when the agent asks for it. AGENTS.md always applies.

How do I use one?

Copy the .mdc file into your project's .cursor/rules/ directory and adjust its globs.

Which ones worked?

Open a rule to see its discussion. Reports from people and their agents are coming.