security-patterns

security-patterns is a cursor rule for Cursor from brendadeeznuts1111/betting-brain-v3. It costs 2,642 tokens per session, scanned A, original, MIT.

A set of coding rules for spotting common security risks, such as unsafe input handling, SQL injection, time-zone mistakes, and WebAssembly memory leaks. It includes code-search examples using ast-grep, a tool that finds matching code patterns.

In plain words
What is it for?
Use it to search a codebase for suspicious parsing, database queries, date handling, and WebAssembly exports, and to guide input-validation changes.
Why use it?
It helps developers find risky code patterns before they become vulnerabilities or production bugs. It also gives examples of validating user input safely.

Cursor rule for Cursor

Written for Cursor: installed under .cursor/.

Needs its repository: it reads a path above its own folder, which exists only inside the repository. The line is import { createLogger } from '../utils/logger';.

Install

Getting it into your agent

It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.

Clone the repo
git clone --depth 1 https://github.com/brendadeeznuts1111/betting-brain-v3
agentmods
npx agentmods add rules/brendadeeznuts1111/betting-brain-v3/security-patterns

Made for: Cursor.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for security-patterns

README.md
[![agentmods](https://agentmods.dev/badge/rules/brendadeeznuts1111/betting-brain-v3/security-patterns.svg)](https://agentmods.dev/rules/brendadeeznuts1111/betting-brain-v3/security-patterns)
Your own site
<a href="https://agentmods.dev/rules/brendadeeznuts1111/betting-brain-v3/security-patterns"><img src="https://agentmods.dev/badge/rules/brendadeeznuts1111/betting-brain-v3/security-patterns.svg" alt="Measured on agentmods" height="20"></a>
Per session 2,642 This file is loaded in full into every session.
When invoked 2,642 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.02642 $0.02642
Opus 5 $0.01321 $0.01321
Sonnet 5 $0.00528 $0.00528
Haiku 4.5 $0.00264 $0.00264

Measured 6d ago against content hash e00874a81637, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade A, and why

security-patterns scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/security-patterns.mdc · 423 lines

How it starts

The opening of the file, as written. The whole thing — 423 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Security Patterns

🔍 Code Searchability Patterns

Find security-patterns Issues with ast-grep

# Find parseFloat($$$)
# Find env.$DB.prepare(`SELECT $QUERY`)
# Find new Date()
# Find WASM.*exports
ast-grep --pattern 'parseFloat($$$)' src/
ast-grep --pattern 'env.$DB.prepare(`SELECT $QUERY`)' src/
ast-grep --pattern 'new Date()' src/
ast-grep --pattern 'WASM.*exports' src/
sg -p 'parseFloat($$$)' src/
sg -p 'env.$DB.prepare(`SELECT' src/
sg -p 'new' src/
sg -p 'WASM.*exports' src/

security-patterns Discovery Commands

sg search "parseFloat" src/
sg search "SELECT" src/
sg search "new Date()" src/
sg search "WASM" src/

Search Examples

# Find parseFloat usage (security risk)
sg search 'parseFloat($$$)' src/
# Find SQL injection risks
sg search 'env.$DB.prepare(`SELECT' src/
# Find timezone issues
sg search 'new' src/
# Find WASM memory leaks
sg search 'WASM.*exports' src/

Input Validation

Parameter Validation

// ✅ CORRECT: Validate all inputs
function validateInput(input: unknown): boolean {
  if (typeof input !== 'string') return false;
  if (input.length === 0) return false;
  if (input.length > 1000) return false;
  return true;
}

// ❌ WRONG: No validation
function processInput(input: unknown) {
  // Direct use without validation
  return input.toString();
}

SQL Injection Prevention

// ✅ CORRECT: Parameterized queries
const result = await env.ANALYTICS.prepare(`
  SELECT * FROM users WHERE id = ? AND status = ?
`).bind(userId, status).all();

// ❌ WRONG: String interpolation
const result = await env.ANALYTICS.prepare(`
  SELECT * FROM users WHERE id = '${userId}' AND status = '${status}'
`).all();

XSS Prevention

// ✅ CORRECT: Sanitize output
function sanitizeOutput(input: string): string {
  return input
    .replace(/&/g, '&amp;')
    .replace(/</g, '&lt;')
    .replace(/>/g, '&gt;')
    .replace(/"/g, '&quot;')
    .replace(/'/g, '&#x27;');
}

// ❌ WRONG: Direct output
function displayUserInput(input: string) {
  return `<div>${input}</div>`; // XSS risk
}

Read the full file on GitHub · 423 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago First seen · 423 lines · 2,642 tokens per session scan A e00874a81637

Subscribe to this mod's changes

security-patterns is a cursor rule published in the GitHub repository brendadeeznuts1111/betting-brain-v3 (8 stars, last pushed 11mo ago), licensed MIT. It adds 2,642 tokens to every session, about $0.0132 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.