cursorrules

Repository rules for the db-conn-mcp project, covering design choices, code quality, database safety, and consistency between instruction files. An MCP project uses the Model Context Protocol to expose tools or data to AI assistants.

In plain words
What is it for?
Use them when changing db-conn-mcp code, checking formatting and linting with Ruff, preserving read-only database behavior, or keeping CLAUDE.md, .cursorrules, and the canonical rules file synchronized.
Why use it?
They give coding agents clear boundaries for modifying the project, including avoiding unnecessary architecture and keeping database access rules in the database dialect. They also identify which documentation is canonical.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/idle-sync/db-conn-mcp/cursorrules
Clone the repo
git clone --depth 1 https://github.com/Idle-Sync/db-conn-mcp

Made for: Cursor.

Per session 1,662 This file is loaded in full into every session.
When invoked 1,662 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01662 $0.01662
Opus 5 $0.00831 $0.00831
Sonnet 5 $0.00332 $0.00332
Haiku 4.5 $0.00166 $0.00166

Measured yesterday against content hash 12edbe38d3bb, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

cursorrules scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursorrules · 64 lines

How it starts

The opening of the file, as written. The whole thing — 64 lines — stays where its author put it; the contents beside it link to each section on GitHub.

AI Agent Rules (CLAUDE.md / .cursorrules)

Welcome, AI Agent (Claude, Agy, Cursor, or otherwise)! When assisting the user with the db-conn-mcp project, please strictly adhere to the following rules to maintain the project's core philosophy.

Note: docs/AGENT_RULES.md is canonical. CLAUDE.md and .cursorrules at the repo root are exact copies — when you change a rule, update all three so they stay byte-identical.

1. Simplicity First (No Over-engineering)

  • DO NOT introduce complex architectures, custom OAuth servers, or JWT minting.
  • DO NOT use complex AST parsers to validate read vs. write queries.
  • DO rely on native database features. Read-only enforcement lives inside each dialect (for Postgres v1: set the session read-only with SET SESSION CHARACTERISTICS AS TRANSACTION READ ONLY;).

2. Code Quality & Standards (Production Grade)

  • Ruff: Use ruff as the strict standard for all linting and formatting. Ensure all code passes ruff check and ruff format.
  • SOLID & KISS: Code must be highly modular but radically simple. Follow SOLID principles to keep concerns separated (e.g., config parsing vs. database connection vs. MCP transport), but never at the expense of KISS (Keep It Simple, Stupid).
  • DevX & AgentX: The codebase must be highly readable and easy to modify for both human developers and AI agents. Keep files reasonably small, avoid deep nesting, and use explicit typing (typing module) everywhere.
  • Documentation: Well-documented from day one. Every class, module, and non-trivial function must have a clear Python docstring.

3. Configuration via JSON

  • The single source of truth for database connections is connections.json.
  • The schema is a top-level object { "connections": [ ... ] }; each connection has name, dsn, mode ("read" or "write"), an optional yolo (boolean, default false), and an optional fallback_ports (list of ints, probed in order when the primary port refuses — see README).
  • Feel free to programmatically read, update, or create connections.json for the user if they ask you to add a database.

Read the full file on GitHub · 64 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 64 lines · 1,662 tokens per session scan A 12edbe38d3bb

Subscribe to this mod's changes

cursorrules is a cursor rule published in the GitHub repository Idle-Sync/db-conn-mcp (2 stars, last pushed 19d ago), licensed MIT. It adds 1,662 tokens to every session, about $0.0083 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.