code-change-minimal

code-change-minimal is a cursor rule for Cursor from oakensoul/nextjs-cursor-prompts. It costs 22 tokens per session (1,432 once invoked), scanned A, original, MIT.

A rule for making only the smallest necessary change to an existing codebase.

In plain words
What is it for?
It guides targeted fixes and updates by requiring inspection of existing files and patterns before changing code.
Why use it?
It prevents unnecessary rewrites, unrelated edits, file moves, new dependencies, and architecture changes that could introduce risk.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/oakensoul/nextjs-cursor-prompts/code-change-minimal
Clone the repo
git clone --depth 1 https://github.com/oakensoul/nextjs-cursor-prompts

Made for: Cursor.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for code-change-minimal

README.md
[![agentmods](https://agentmods.dev/badge/rules/oakensoul/nextjs-cursor-prompts/code-change-minimal.svg)](https://agentmods.dev/rules/oakensoul/nextjs-cursor-prompts/code-change-minimal)
Your own site
<a href="https://agentmods.dev/rules/oakensoul/nextjs-cursor-prompts/code-change-minimal"><img src="https://agentmods.dev/badge/rules/oakensoul/nextjs-cursor-prompts/code-change-minimal.svg" alt="Measured on agentmods" height="20"></a>
Per session 22 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,432 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00022 $0.01432
Opus 5 $0.00011 $0.00716
Sonnet 5 $0.00004 $0.00286
Haiku 4.5 $0.00002 $0.00143

Measured 5d ago against content hash 9ccd305d5730, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

code-change-minimal scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/code-change-minimal.mdc · 160 lines

How it starts

The opening of the file, as written. The whole thing — 160 lines — stays where its author put it; the contents beside it link to each section on GitHub.


title: Minimal Change Hook description: Ensures focused, minimal changes that respect existing codebase and avoid unnecessary rewrites or assumptions tags: [prompt, minimal-change, focused-updates, code-preservation, incremental-changes] version: 1.0.0 lastUpdated: 2025-06-02 usage: Use as a prefix when making small updates or targeted changes to existing code audience: [claude, ai-assistants] scope: [code-preservation, minimal-changes, incremental-updates, existing-codebase-respect]

Minimal Code Change Rule

This rule applies to ANY development task. When referenced, you must follow these constraints regardless of the primary prompt.

🚫 FORBIDDEN ACTIONS:

  1. DO NOT rewrite existing working code unless explicitly required for the task
  2. DO NOT assume files don't exist - always analyze the current codebase first
  3. DO NOT change file structure or move files unless specifically requested
  4. DO NOT modify unrelated code or files outside the task scope
  5. DO NOT add new dependencies unless absolutely necessary for the task
  6. DO NOT change existing patterns or architecture without explicit need
  7. DO NOT refactor for the sake of refactoring - preserve working patterns
  8. DO NOT over-engineer simple requests into complex solutions

REQUIRED ACTIONS:

  1. ANALYZE the existing codebase thoroughly before any changes
  2. PRESERVE existing patterns and coding styles
  3. MAKE MINIMAL changes that accomplish the specific task
  4. USE existing utilities and helper functions where possible
  5. MAINTAIN consistency with current codebase architecture
  6. ASK for clarification if the task scope is ambiguous
  7. VERIFY file locations and existing implementations first

🔒 BUILT-IN SECURITY REQUIREMENTS:

  • Validate all inputs - sanitize user data and API parameters
  • Authenticate protected actions - verify user permissions before execution
  • Use secure defaults - HTTPS, secure cookies, proper CORS settings
  • Log security events - track authentication failures and suspicious activity
  • Escape output - prevent XSS in rendered content

Read the full file on GitHub · 160 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 160 lines · 22 tokens per session scan A 9ccd305d5730

Subscribe to this mod's changes

code-change-minimal is a cursor rule published in the GitHub repository oakensoul/nextjs-cursor-prompts (4 stars, last pushed 1y ago), licensed MIT. It adds 22 tokens to every session and 1,432 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.