cursorrules

A compact set of Cursor rules for a software repository. Cursor is an AI coding editor, and these rules tell it what project information to read, what practices are forbidden and how to validate changes.

In plain words
What is it for?
Use it before editing code in the repository and when validating a change. It directs the agent to load current project context, follow the rule hierarchy and run the required checks on affected areas.
Why use it?
It reduces the risk of an AI agent inventing repository facts, bypassing checks or making changes that conflict with the project's architecture and security rules.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/ihabkhaled/clawai/cursorrules
Clone the repo
git clone --depth 1 https://github.com/ihabkhaled/ClawAI

Made for: Cursor.

Per session 708 This file is loaded in full into every session.
When invoked 708 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00708 $0.00708
Opus 5 $0.00354 $0.00354
Sonnet 5 $0.00142 $0.00142
Haiku 4.5 $0.00071 $0.00071

Measured yesterday against content hash 987a5d4fa7a9, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

cursorrules scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursorrules · 59 lines

How it starts

The opening of the file, as written. The whole thing — 59 lines — stays where its author put it; the contents beside it link to each section on GitHub.

ClawAI — Cursor rules (compact router)

Do NOT invent repository facts. Before editing, run: npm run knowledge:context -- --task="" and read .ai/local/current-context.md.

Canonical authority (higher wins): CLAUDE.md > rules/00-non-negotiable-rules.md > context/architecture-map.md > context/stack-and-toolchain.md > numbered rules/* > skills/* > context/* + memory/* > .ai/manifests/*.

Blockers (never): --no-verify / hook bypass; eslint-disable / @ts-ignore / any / as unknown as; cross-service DB access; logic in controllers; DB calls outside repositories; process.env outside AppConfig; console.log; logging/exposing secrets; user-facing text without i18n (13 locales); code without a test; shipping a change with no knowledge delta (docs/skills/rules/context in the SAME commit, rules/33); gating per-commit or all-workspace instead of once at the end, scoped (rules/34).

Validation (touched folders only): npm run affected:list cd && npm run typecheck && npm run lint && npm test && npm run build

Scoped rules live in .cursor/rules/*.mdc (by file glob). Full router: cursor.md + AGENTS.md.

Prompt packs / execution prompts — before ANY code, run the protocol in rules/26-prompt-pack-intake-protocol.md (runbook: skills/execute-prompt-pack.md): read the pack end to end; npm run knowledge:context; read governing docs in authority order; audit every deliverable done/partial/missing against the CODE (present is not wired — a repo method with no callers is scaffolding); review the constraint surface up front (eslint flat config, TS strict, prettier, coverage floors, security, i18n x9 + i18n.types.ts, the CLAUDE.md delivery checklist, and the gate topology incl. pre-commit/pre-push/CI/freshness); write the plan and state deviations — policy outranks the pack, never silently; then implement with scoped gates, one gated commit per change, each pushed before the next.

Communication style (MANDATORY)

Short. Plain. Concrete. A few lines max.

  • Blocked? One line: Blocked: <the actual thing>.
  • Working? Working — <what>. Progress? ~70/100.
  • Name the concrete cause: file, symbol, exact error. Never circle the problem.
  • Easy words over complex ones. Cut every reply in half before sending.

Read the full file on GitHub · 59 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 59 lines · 708 tokens per session scan A 987a5d4fa7a9

Subscribe to this mod's changes

cursorrules is a cursor rule published in the GitHub repository ihabkhaled/ClawAI (22 stars, last pushed yesterday), licensed Apache-2.0. It adds 708 tokens to every session, about $0.0035 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.