Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/obviousworks/vibe-coding-ai-rules/cursorrulesgit clone --depth 1 https://github.com/obviousworks/vibe-coding-ai-rulesWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00573 | $0.00573 |
| Opus 5 | $0.00287 | $0.00287 |
| Sonnet 5 | $0.00115 | $0.00115 |
| Haiku 4.5 | $0.00057 | $0.00057 |
Grade A, and why
cursorrules scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 74 lines — stays where its author put it; the contents beside it link to each section on GitHub.
{{PROJECT_NAME}} - Cursor Rules
Project Overview
{{PROJECT_DESCRIPTION}}
Architecture: {{ARCHITECTURE_TYPE}} Language: {{PRIMARY_LANGUAGE}} Framework: {{PRIMARY_FRAMEWORK}}
Tech Stack
- Language: {{PRIMARY_LANGUAGE}} ({{LANGUAGE_VERSION}})
- Framework: {{PRIMARY_FRAMEWORK}}
- Database: {{DATABASE}}
- Testing: {{TESTING_FRAMEWORK}}
DO NOT Use
- {{BANNED_DEPENDENCY_1}} (use {{ALTERNATIVE_1}} instead)
- {{BANNED_DEPENDENCY_2}} (use {{ALTERNATIVE_2}} instead)
Core Principles
Clarify Before Coding
Understand requirements before writing code. Ask questions when intent is unclear. No code without clear goals.
Simplicity First
Choose the simplest viable solution. Complex patterns need explicit justification. Readable code over clever code.
Security By Default
Validate all inputs. No secrets in code. Defense in depth. Least privilege principle.
Test-Driven Thinking
Design all code to be testable from inception. Write tests alongside code. Verify before committing.
Code Style
Naming Conventions
- Files: {{FILE_NAMING}} (e.g., kebab-case.tsx, snake_case.py)
- Components: PascalCase
- Functions: camelCase with verb prefixes
- Variables: camelCase, booleans with is/has prefix
- Constants: UPPER_SNAKE_CASE
Readability
Code must be immediately understandable. Use descriptive naming. Maintain clear structure. Readable code over clever code.
Formatting
- Indentation: {{INDENTATION}}
- Line Length: {{LINE_LENGTH}} max
- Quotes: {{QUOTE_STYLE}}
- Semicolons: {{SEMICOLONS}}
Security Rules
- Validate ALL user input with schema validation
- NEVER concatenate SQL strings — use parameterized queries
- NEVER store secrets in source code
- Use environment variables for credentials
- Sanitize HTML before rendering
Testing Standards
- Arrange-Act-Assert pattern
- Descriptive names: "should [behavior] when [condition]"
- Mock external dependencies, not internal logic
- Critical paths: minimum 80% coverage
Workflow
- Atomic changes: small, self-contained modifications
- Conventional commits: type(scope): description
- Only modify files related to current task
- Never add new dependencies without explicit approval or compelling justification
- Use file-scoped commands. Reference docs instead of pasting. Optimize context window usage.
- Follow established conventions for the relevant language and tech stack
- Comment only complex logic or critical functions. Avoid documenting the obvious.
- After generating code, argue against your own solution. Check for redundancy, unnecessary complexity, or simpler alternatives.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 74 lines · 573 tokens per session scan A 5073a102d4e6
cursorrules is a cursor rule published in the GitHub repository obviousworks/vibe-coding-ai-rules (88 stars, last pushed 2mo ago), licensed MIT. It adds 573 tokens to every session, about $0.0029 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
tools
(none|read|write|network|exec) and risk (low|medium|high|critical). These drive the permission classifier — be honest.
ios-app-store-validator
App Store validation for iOS projects.
task_structure_example.mouse
TaskID: MOUSE#TASK0001 # Example. MUST be unique & sequential. Title: "Example Task: Process User Survey Data and Generate Insights Report" Description: | This task involves processing raw user survey data, performing analysis, and generating a comprehensive insights report.
Deep-Learning-Developer
You are an expert in deep learning, transformers, diffusion models, and LLM development, with a focus on Python libraries such as PyTorch, Diffusers, Transformers, and Gradio.
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.