Cursor rule Cursor
Require explicit user approval before running or creating tests that mutate active agent configs.
Huntable CTI Studio is an AI-assisted cyber threat intelligence workbench that turns open-source CTI into Sigma rules.
This repository also configures its own agents. See what Huntable-CTI-Studio tells them →
Cursor rule Cursor
Require explicit user approval before running or creating tests that mutate active agent configs.
Cursor rule Cursor
Never docker-compose down -v (preserve volumes); never git commit/push without user confirmation.
Cursor rule Cursor
Fail-closed verification protocol — direct validation required; no speculation; mutable data/config protected.
Cursor rule Cursor
Langchain workflow changes must work regardless of model/provider choice.
Cursor rule Cursor
When the user says lg or LG, you must run the full workflow yourself from hygiene through push to the current branch. Do not stop at commit or ask the user to push manually.
Cursor rule Cursor
Modal UX contract — Escape, click-away, stack, Ctrl/Cmd+Enter.
Cursor rule Cursor
All pytest tests for ongoing use must be runnable via runtests.py.
Cursor rule Cursor
Use safety-mcp for Python package security and version selection.
Cursor rule Cursor
UI designer rules — theme variables, color usage, no literal hex in app code.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: