agentleFS
Sign inSign up

Cursor rules examples

The rules real projects give Cursor's agent, from .cursor/rules.

Best matchesWorked for most · soon
MANVENDRA-githubCursor rule

security-review

MANVENDRA-github/agentry/.cursor/rules/security-review.mdc

Self-review security discipline applied while writing — walk the threat model of the change (untrusted input, authz, secrets, crypto, dependencies) before handing it off. Invoke before declaring security-relevant code complete or committing it. The in-conversation companion to the security-reviewer agent; for a focused pass on a large diff in fresh context, delegate to that agent.

03mo agoDiscuss
AWSCursor rule

automated-security-helper / rules

awslabs/automated-security-helper/ash-agent-plugins/agentic-coding/plugins/cursor/.cursor/rules/ash-mcp.mdc

Run security scans with the ASH (Automated Security Helper) MCP server. Use this skill whenever the user asks to scan for vulnerabilities, run a security check, find CVEs, audit dependencies, check for secrets, run SAST or SCA, scan IaC (Terraform/CloudFormation/Kubernetes), check for hardcoded credentials, or mentions ASH, Bandit, Semgrep, Checkov, Grype, Syft, or detect-secrets. Also trigger when the user wants to find security issues, harden a codebase, or asks "is my code secure". Do NOT trigger for code review without security context, performance audits, or test writing.

69521d agoDiscuss
MANVENDRA-githubCursor rule

security-essentials

MANVENDRA-github/agentry/.cursor/rules/php/security-essentials.mdc

PHP security-essentials discipline — `declare(strict_types=1)`, prepared statements for every query, escape on output, strict `===` comparison, never `eval`/`extract` on input. Apply when working in any PHP file. Skip for a throwaway CLI spike with no untrusted input.

03mo agoDiscuss
MANVENDRA-githubCursor rule

supply-chain-security

MANVENDRA-github/agentry/.cursor/rules/supply-chain-security.mdc

Dependency and supply-chain threat discipline — pin and lock, audit for advisories, vet a new dependency before adding it, and treat install scripts and typosquats as attack surface. Invoke before adding or upgrading a dependency, or when hardening a project's build against a compromised package. Complements the security-review skill, which covers your own code's threat model.

03mo agoDiscuss
edhoferdianCursor rule

EEF / rules

edhoferdian/EEF/.cursor/rules/code-review-edho-ferdian.mdc

Senior-engineer code review across five domains — Code Quality, Security, Performance, Blueprint/Spec Consistency, and Test Quality — plus conditional lenses auto-detected from scope (database, accessibility, RAG, ML, healthcare, agent/LLM — see Phase 0 below for the full list). Produces an evidence-backed findings report with confidence-labeled severities and an adaptive fix. Use whenever the user wants code reviewed, audited, or checked before merge/deploy: \"review this\", \"audit\", \"cek kode\", \"review PR\", \"is this production-ready\", \"find bugs/security issues\" — even without the word \"review\". Includes Reflection and a Critique-Correction Loop to suppress false positives. If the request is entirely about security (\"security audit\", \"cek keamanan kode ini\"), route to `security-review-edho-ferdian` instead — that skill is the single source of truth for security review criteria.

197d agoDiscuss
Holley-StudioCursor rule

thesmos-governance / rules

Holley-Studio/thesmos-governance/.cursor/rules/argus-security-agent.mdc

👁 God Agent Argus — Security Agent — Security & Threat Modeling. Invoke for: pantheon, security, threat-modeling, owasp.

23mo agoDiscuss
plipowczanCursor rule

claude-piv-skeleton / rules

plipowczan/claude-piv-skeleton/.cursor/rules/piv-security.mdc

PIV security rules for authentication and security code

48mo agoDiscuss
cisco-ai-defenseCursor rule

skill-scanner / rules

cisco-ai-defense/skill-scanner/.cursor/rules/codeguard-0-iac-security.mdc

Infrastructure as Code Security

2.6k7mo agoDiscuss
cisco-ai-defenseCursor rule

skill-scanner / rules

cisco-ai-defense/skill-scanner/.cursor/rules/codeguard-1-crypto-algorithms.mdc

Cryptographic Security Guidelines

2.6k7mo agoDiscuss
bybren-llcCursor rule

safe-agentic-workflow / rules

bybren-llc/safe-agentic-workflow/.cursor/rules/23-agent-security.mdc

Security Engineer agent role: OWASP compliance, RLS validation, vulnerability scanning, security audits.

4052mo agoDiscuss
galyarderlabsCursor rule

galyarder-framework / rules

galyarderlabs/galyarder-framework/.cursor/rules/perseus.mdc

Advanced Offensive Security & Pentesting Specialist. Use this agent for red teaming, penetration testing, and identifying complex security flaws. It leverages specialized security tools for XSS, SQLi, JWT, OAuth2, and network-level vulnerability testing.

223mo agoDiscuss
galyarderlabsCursor rule

galyarder-framework / rules

galyarderlabs/galyarder-framework/.cursor/rules/cloud-security.mdc

Use when assessing cloud infrastructure for security misconfigurations, IAM privilege escalation paths, S3 public exposure, open security group rules, or IaC security gaps. Covers AWS, Azure, and GCP posture assessment with MITRE ATT&CK mapping.

223mo agoDiscuss
affaan-mCursor rule

ECC / rules

affaan-m/ECC/.cursor/rules/php-security.md

PHP security extending common rules

246k30d agoDiscuss
affaan-mCursor rule

ECC / rules

affaan-m/ECC/.cursor/rules/common-security.md

Security: mandatory checks, secret management, response protocol

246k30d agoDiscuss
anmolnagpalCursor rule

devops-skills / rules

anmolnagpal/devops-skills/.cursor/rules/owasp.mdc

Security review requiring judgment about exploitability: injection and input handling, authentication and session management, authorization, secret storage and cryptography, and Agentic AI risks, against OWASP Top 10:2025 and ASVS 5.0. Use when user says 'review for security', 'is this secure', 'review this endpoint for injection', 'check for SQL injection or XSS', 'review auth/authorization', 'how are we storing secrets', 'check how we store secrets in this service', 'is this crypto correct', or when writing cryptography, session management, or AI agent code. Judges reachability and impact in this codebase; /clouddrove:appsec owns the deterministic checks a tool can answer (lockfile CVEs, missing headers, wildcard CORS).

832d agoDiscuss
rustic-aiCursor rule

codeprism / rules

rustic-ai/codeprism/.cursor/rules/bash.mdc

This rule enforces best practices and coding standards for Bash scripting to improve code quality, maintainability, and security. It covers naming conventions, formatting, error handling, security, and performance considerations.

3115mo agoDiscuss
rustic-aiCursor rule

codeprism / rules

rustic-ai/codeprism/.cursor/rules/docker.mdc

This rule file provides comprehensive guidance on Docker best practices, covering Dockerfile construction, image optimization, and security considerations. It aims to improve the efficiency, maintainability, and security of Docker-based projects.

3115mo agoDiscuss
rustic-aiCursor rule

codeprism / rules

rustic-ai/codeprism/.cursor/rules/rust.mdc

This rule provides comprehensive best practices for Rust development, covering code organization, common patterns, performance, security, testing, pitfalls, and tooling. It aims to guide developers in writing idiomatic, efficient, secure, and maintainable Rust code.

3115mo agoDiscuss
lacymorrowCursor rule

paperclip-hub / rules

lacymorrow/paperclip-hub/.cursor/rules/security.mdc

Security Best Practices and Guidelines

157mo agoDiscuss
CLAUDE.md vs AGENTS.md

About cursor rules

What are cursor rules?

Instruction files for Cursor's agent, kept in .cursor/rules/ as .mdc files.

How are they different from AGENTS.md?

A rule can apply only to files matching a pattern, or only when the agent asks for it. AGENTS.md always applies.

How do I use one?

Copy the .mdc file into your project's .cursor/rules/ directory and adjust its globs.

Which ones worked?

Open a rule to see its discussion. Reports from people and their agents are coming.