Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/chand1012/cursorrules/ecmascriptgit clone --depth 1 https://github.com/chand1012/cursorrulesWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00642 |
| Opus 5 | $0.00000 | $0.00321 |
| Sonnet 5 | $0.00000 | $0.00128 |
| Haiku 4.5 | $0.00000 | $0.00064 |
Grade A, and why
ecmascript scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 43 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Modern Web Development Best Practices
JavaScript (ECMAScript 2020+)
- Utilize modern JavaScript features such as optional chaining (
?.), nullish coalescing (??), private class fields (#field), and top-level await. - Use ES modules with
importandexportstatements for better code organization and tree shaking. - Prefer
constandletovervarfor variable declarations to avoid scope-related issues. - Use arrow functions for concise syntax, especially in callbacks and methods.
- Implement asynchronous programming with
async/awaitfor improved readability and error handling. - Handle errors using try-catch blocks and consider creating custom error classes for specific error types.
CSS
- Leverage modern CSS features like container queries, the
:has()selector, and CSS nesting for flexible and maintainable styles. - Follow a consistent naming convention, such as BEM (Block Element Modifier), to avoid class name conflicts.
- Use CSS variables (e.g.,
--primary-color) for colors, fonts, and other reusable values to ensure consistency. - Design responsively using media queries, flexbox, and grid to adapt to various screen sizes.
- Optimize CSS for performance by minimizing file size, avoiding complex selectors, and using efficient properties.
HTML5
- Write semantic HTML using tags like
<header>,<nav>,<main>,<article>,<section>,<aside>, and<footer>to improve accessibility and SEO. - Ensure accessibility by providing alternative text for images (e.g.,
alt="description"), using ARIA attributes where necessary, and following WCAG guidelines. - Optimize performance by using lazy loading for images (e.g.,
loading="lazy"), minimizing DOM size, and avoiding unnecessary elements.
Module Imports with esm.sh
- Import libraries directly in the browser using esm.sh, e.g.,
import React from 'https://esm.sh/react'. - Specify the ECMAScript target for modern syntax, e.g.,
import React from 'https://esm.sh/react?target=es2024', to ensure compatibility with modern browsers. - Manage dependencies carefully by tracking versions and avoiding unnecessary imports to keep the bundle size small.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 43 lines · 642 tokens per session scan A 4d3748b2d4a8
ecmascript is a cursor rule published in the GitHub repository chand1012/cursorrules (13 stars, last pushed 9mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 642 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
webkit-browser
Cursor rule "webkit-browser" from duckduckgo/apple-browsers, covering webkit & browser development guidelines, webview configuration, basic webview setup, user scripts management and tab management.
cypress-e2e-testing-cursorrules-prompt-file
Cursor rules for Cypress development with E2E testing.
vasu-playwright-utils
../../templates/cursor-rules/vasu-playwright-utils.mdc.
dev-browser
Fallback browser automation with persistent Chrome state. Use only when Browser Use is unavailable or blocked.
node-dependencies
Enforce Node.js versioning and package management best practices.
security-standards
Cursor rule "security-standards" from wjgogogo/cursor-rules, covering 安全规范, 核心原则 [p0], 输入验证, xss 防护 and csrf 防护.