tech

tech is a cursor rule for Cursor from BOXELS/cursor-rules. It costs 2,580 tokens per session, scanned A, original, MIT.

A template for recording a project’s programming language, framework, styling approach, backend service, naming conventions, file organisation, and import rules.

In plain words
What is it for?
It helps document the technology stack and decide how code should be structured and written.
Why use it?
It gives coding agents and developers shared technical conventions instead of leaving important choices implicit.

Cursor rule for Cursor

Written for Cursor: installed under .cursor/.

Good fit It helps document the technology stack and decide how code should be structured and written.

Compare 6 cursor rules from other repositories ↓
Install with agentmods
npx agentmods add rules/boxels/cursor-rules/tech
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Clone the repo
git clone --depth 1 https://github.com/BOXELS/cursor-rules

Made for: Cursor.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for tech

README.md
[![agentmods](https://agentmods.dev/badge/rules/boxels/cursor-rules/tech/github.svg)](https://agentmods.dev/rules/boxels/cursor-rules/tech)
Your own site
<a href="https://agentmods.dev/rules/boxels/cursor-rules/tech"><img src="https://agentmods.dev/badge/rules/boxels/cursor-rules/tech/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for tech

Your own site · 80×15
<a href="https://agentmods.dev/rules/boxels/cursor-rules/tech"><img src="https://agentmods.dev/badge/rules/boxels/cursor-rules/tech.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 2,580 This file is loaded in full into every session.
When invoked 2,580 The same file — it is already loaded in full.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.02580 $0.02580
Opus 5 $0.01290 $0.01290
Sonnet 5 $0.00516 $0.00516
Haiku 4.5 $0.00258 $0.00258

Measured yesterday against content hash 72e53ed1cc81, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-16, from the pricing page.

Security

Grade A, and why

tech scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/tech.mdc · 109 lines

How it starts

The opening of the file, as written. The whole thing — 109 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Tech Rules

Language and framework

  • [Primary language, e.g. "TypeScript strict mode", "Python 3.12+", "Go 1.22", "Rust stable"]. [Key constraint, e.g. "No 'any' types unless explicitly approved", "Type hints on all function signatures", etc.]
  • [Primary framework, e.g. "Next.js App Router", "Django 5", "Rails 7", "SvelteKit", "FastAPI"]. [Default pattern, e.g. "Server Components by default, 'use client' only when interactivity is needed", "class-based views unless logic is trivial", etc.]
  • [Styling approach, e.g. "Tailwind CSS utility classes", "CSS Modules", "styled-components", "SCSS with BEM"]. [Constraint, e.g. "Never write custom CSS unless the framework can't do it."]
  • [Primary backend service, e.g. "Supabase", "Firebase", "AWS Amplify", "self-hosted Postgres"]. Don't introduce alternative services without asking.

Code organization

  • File naming: [convention, e.g. "kebab-case for files, PascalCase for components", "snake_case for all files", "PascalCase for classes, camelCase for utilities"].
  • Group by [organization strategy, e.g. "feature, not by type", "module", "domain layer"].
  • Imports: [import convention, e.g. "absolute paths with @/ alias", "relative imports within modules, absolute across modules"]. Group by: external libs → internal modules → components → types. Separate groups with blank lines.
  • Functions should do one thing. If a function exceeds [threshold, e.g. "30 lines", "50 lines"], it should be split.

Data and state management

  • Validation: [validation library, e.g. "Zod", "Pydantic", "Joi", "class-validator"]. Never trust external data without validating. Validate at every trust boundary — client input, API params, webhook payloads, URL params. Prefer allowlists over denylists.
  • Data fetching: [approach, e.g. "TanStack Query for client-side, server components for initial loads", "SWR", "RTK Query", "built-in framework loaders"]. [Anti-pattern to avoid, e.g. "Never use useEffect for data fetching", "No raw fetch calls without error handling."]
  • State management: [approach, e.g. "React state + context for UI, server state libraries for async data", "Pinia for global state", "Zustand", "Redux Toolkit"]. [Constraint, e.g. "Never mix UI state and server state."]

Read the full file on GitHub · 109 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 109 lines · 2,580 tokens per session scan A 72e53ed1cc81

Subscribe to this mod's changes

tech is a cursor rule published in the GitHub repository BOXELS/cursor-rules (6 stars, last pushed yesterday), licensed MIT. It adds 2,580 tokens to every session, about $0.0129 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-15.