Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/mckruz/claude-code-mastery/securitygit clone --depth 1 https://github.com/MCKRUZ/claude-code-masteryWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00472 | $0.00472 |
| Opus 5 | $0.00236 | $0.00236 |
| Sonnet 5 | $0.00094 | $0.00094 |
| Haiku 4.5 | $0.00047 | $0.00047 |
Grade A, and why
security scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 46 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Security
Secrets Management
- NEVER hardcode secrets, API keys, tokens, or connection strings in code.
- Dev: User Secrets (
dotnet user-secrets). Prod: Azure Key Vault. - Frontend: NEVER put secrets in Angular/client-side code — backend proxies all external API calls.
- If a secret is exposed: rotate immediately, check Application Insights for exploitation.
Input Validation & Injection
- All user input validated at system boundaries (FluentValidation / Angular reactive forms).
- SQL: EF Core only (auto-parameterized). Raw SQL:
FromSqlInterpolatedonly — never string concatenation. - XSS: Angular auto-escapes by default. Use
DomSanitizeronly when unavoidable, with a comment explaining why. - CSRF protection enabled on all state-changing endpoints.
Authentication & Authorization
- Auth required on all endpoints. Rate limiting on public endpoints.
- JWT: ValidateLifetime=true, ClockSkew=Zero, validate issuer + audience + signing key.
- CORS: explicit allowlist only (
CorsAllowedOrigins), never wildcard in production.
HTTP Security Headers
- X-Frame-Options: DENY
- X-Content-Type-Options: nosniff
- Content-Security-Policy: restrictive default
- Strict-Transport-Security: max-age=31536000; includeSubDomains
- Error responses: never leak stack traces, internal paths, or sensitive data.
AI/LLM Security
- Validate and sanitize all LLM inputs and outputs — treat model output as untrusted.
- Content safety middleware on all agent endpoints.
- Tool permissions enforced via pipeline behavior — tools only accessible to authorized agents.
- Prompt injection defense: never embed raw user input directly into system prompts.
Supply Chain
- Run
dotnet list package --vulnerableandnpm auditbefore adding new dependencies. - Pin major versions. Review changelogs before upgrading.
If Security Issue Found
- STOP current work — security takes priority over all other tasks.
- Fix CRITICAL issues before resuming other work.
- Rotate any exposed secrets, audit logs for exploitation.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 46 lines · 472 tokens per session scan A e9d3c0badba8
security is a cursor rule published in the GitHub repository MCKRUZ/claude-code-mastery (11 stars, last pushed 4mo ago), licensed MIT. It adds 472 tokens to every session, about $0.0024 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
cursorrules
Cursor rule "cursorrules" from syf2211/ruledoctor, covering 订单服务项目规则(demo) and 硬性规则.
integrations
External integration rules — providers, idempotency, bulkhead, observability.
decomposition
File and folder decomposition rules — when and how to split.
architecture
FastAPI layer architecture rules — Router → Service → Repository with Protocol injection.
llm-layer
LLM provider implementation patterns.
050-plan
When the user types /plan or asks to create a project plan, feature PRD, or retrospective.