security-guidelines

A set of security rules for building MCP servers, which let AI agents connect to external tools and services.

In plain words
What is it for?
Validating inputs and paths, restricting file and system access, securing network requests, limiting resource use, logging sensitive operations, and avoiding information leaks.
Why use it?
It highlights common risks when processing model inputs, handling files, running commands, making network connections, and reporting errors.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/ekakit/lightfast-mcp/security-guidelines
Clone the repo
git clone --depth 1 https://github.com/ekakit/lightfast-mcp

Made for: Cursor.

Per session 426 This file is loaded in full into every session.
When invoked 426 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00426 $0.00426
Opus 5 $0.00213 $0.00213
Sonnet 5 $0.00085 $0.00085
Haiku 4.5 $0.00043 $0.00043

Measured 2d ago against content hash 32c3d3981c7b, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

security-guidelines scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/security-guidelines.mdc · 58 lines

How it starts

The opening of the file, as written. The whole thing — 58 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Security Guidelines

Input Validation

  • Always validate inputs from AI models before processing
  • Sanitize file paths to prevent directory traversal attacks
  • Validate command parameters before executing system operations
  • Check parameter types and ranges according to tool specifications

File System Operations

  • Use appropriate permissions for file operations
  • Restrict file access to designated directories only
  • Validate file extensions and MIME types when applicable
  • Never execute user-provided file paths directly

System Operations

  • Be cautious with system-level operations that could affect the host
  • Use subprocess safely with proper argument validation
  • Limit resource usage to prevent DoS attacks
  • Implement timeouts for long-running operations

Network Security

  • Validate network endpoints before making connections
  • Use secure protocols when possible (HTTPS, secure WebSocket)
  • Implement rate limiting for resource-intensive operations
  • Log security-relevant operations for audit trails

Error Handling

  • Don't expose sensitive information in error messages
  • Use generic error messages for security-sensitive failures
  • Log detailed errors securely without exposing them to clients
  • Handle exceptions gracefully to prevent information leakage

Example Secure Tool Implementation

@mcp.tool()
async def secure_file_operation(filepath: str) -> str:
    """Securely operate on files with validation."""
    # Validate input
    if not filepath or not isinstance(filepath, str):
        raise ValueError("Invalid filepath provided")
    
    # Sanitize path
    safe_path = Path(filepath).resolve()
    allowed_dir = Path("/allowed/directory").resolve()
    
    # Check if path is within allowed directory
    if not str(safe_path).startswith(str(allowed_dir)):
        raise ValueError("Access denied: path outside allowed directory")
    
    # Proceed with secure operation
    return "Operation completed safely"

Read the full file on GitHub · 58 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 58 lines · 426 tokens per session scan A 32c3d3981c7b

Subscribe to this mod's changes

security-guidelines is a cursor rule published in the GitHub repository ekakit/lightfast-mcp (2 stars, last pushed 1y ago), licensed MIT. It adds 426 tokens to every session, about $0.0021 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.