cursor_rules

A guide for writing Cursor rules, which are project instructions that shape how Cursor works with selected files or the whole codebase.

In plain words
What is it for?
Use it to create or maintain rules with descriptions, file patterns, application settings, implementation guidance, and code examples.
Why use it?
It helps keep AI-assisted coding consistent by defining required structure, file references, examples, and update practices.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/compozy/gograph/cursor_rules
Clone the repo
git clone --depth 1 https://github.com/compozy/gograph

Made for: Cursor.

Per session 790 This file is loaded in full into every session.
When invoked 790 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00790 $0.00790
Opus 5 $0.00395 $0.00395
Sonnet 5 $0.00158 $0.00158
Haiku 4.5 $0.00079 $0.00079

Measured 2d ago against content hash 5ed8a0287900, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

cursor_rules scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/cursor_rules.mdc · 129 lines

What it actually says

<rule_structure_requirements>

  • Required Rule Structure:

    ---
    description: Clear, one-line description of what the rule enforces
    globs: path/to/files/*.ext, other/path/**/*
    alwaysApply: boolean
    ---
    
    - **Main Points in Bold**
      - Sub-points with details
      - Examples and explanations
    

    </rule_structure_requirements>

<file_reference_guidelines>

  • File References:
    • Use [filename](mdc:path/to/file) (filename) to reference files
    • Example: prisma.mdc for rule references
    • Example: schema.prisma for code references </file_reference_guidelines>

<code_example_guidelines>

  • Code Examples:

    • Use language-specific code blocks
    // ✅ DO: Show good examples
    const goodExample = true;
    
    // ❌ DON'T: Show anti-patterns
    const badExample = false;
    

    </code_example_guidelines>

<content_guidelines>

  • Rule Content Guidelines:
    • Start with high-level overview
    • Include specific, actionable requirements
    • Show examples of correct implementation
    • Reference existing code when possible
    • Keep rules DRY by referencing other rules </content_guidelines>

<rule_update_criteria>

  • Rule Updates:

    • Add New Rules When:

      • A new technology/pattern is used in 3+ files
      • Common bugs could be prevented by a rule
      • Code reviews repeatedly mention the same feedback
      • New security or performance patterns emerge
    • Modify Existing Rules When:

      • Better examples exist in the codebase
      • Additional edge cases are discovered
      • Related rules have been updated
      • Implementation details have changed
    • Rule Deprecation:

      • Mark outdated patterns as deprecated
      • Remove rules that no longer apply
      • Update references to deprecated rules
      • Document migration paths for old patterns </rule_update_criteria>

<quality_checks>

  • Rule Quality Checks:
    • Rules should be actionable and specific
    • Examples should come from actual code
    • References should be up to date
    • Patterns should be consistently enforced
    • Use bullet points for clarity
    • Keep descriptions concise
    • Include both DO and DON'T examples
    • Reference actual code over theoretical examples
    • Use consistent formatting across rules </quality_checks>

<continuous_improvement>

  • Continuous Improvement:

    • Improvement Triggers:

      • New code patterns not covered by existing rules
      • Repeated similar implementations across files
      • Common error patterns that could be prevented
      • New libraries or tools being used consistently
      • Emerging best practices in the codebase
    • Analysis Process:

      • Compare new code with existing rules
      • Identify patterns that should be standardized
      • Look for references to external documentation
      • Check for consistent error handling patterns
      • Monitor test patterns and coverage
    • Documentation Updates:

      • Keep examples synchronized with code
      • Update references to external docs
      • Maintain links between related rules
      • Document breaking changes
      • Monitor code review comments
      • Track common development questions
      • Update rules after major refactors
      • Add links to relevant documentation
      • Cross-reference related rules </continuous_improvement>
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 129 lines · 790 tokens per session scan A 5ed8a0287900

Subscribe to this mod's changes

cursor_rules is a cursor rule published in the GitHub repository compozy/gograph (9 stars, last pushed 1y ago), licensed MIT. It adds 790 tokens to every session, about $0.0040 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.