Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/ratnesh-maurya/cursor-claude-personasWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/ratnesh-maurya/cursor-claude-personas/rules-js-hoist-regexp)<a href="https://agentmods.dev/rules/ratnesh-maurya/cursor-claude-personas/rules-js-hoist-regexp"><img src="https://agentmods.dev/badge/rules/ratnesh-maurya/cursor-claude-personas/rules-js-hoist-regexp/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/rules/ratnesh-maurya/cursor-claude-personas/rules-js-hoist-regexp"><img src="https://agentmods.dev/badge/rules/ratnesh-maurya/cursor-claude-personas/rules-js-hoist-regexp.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00294 |
| Opus 5 | $0.00000 | $0.00147 |
| Sonnet 5 | $0.00000 | $0.00059 |
| Haiku 4.5 | $0.00000 | $0.00029 |
Grade A, and why
rules--js-hoist-regexp scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Hoist RegExp Creation
Don't create RegExp inside render. Hoist to module scope or memoize with useMemo().
Incorrect (new RegExp every render):
function Highlighter({ text, query }: Props) {
const regex = new RegExp(`(${query})`, 'gi')
const parts = text.split(regex)
return <>{parts.map((part, i) => ...)}</>
}
Correct (memoize or hoist):
const EMAIL_REGEX = /^[^\s@]+@[^\s@]+\.[^\s@]+$/
function Highlighter({ text, query }: Props) {
const regex = useMemo(
() => new RegExp(`(${escapeRegex(query)})`, 'gi'),
[query]
)
const parts = text.split(regex)
return <>{parts.map((part, i) => ...)}</>
}
Warning (global regex has mutable state):
Global regex (/g) has mutable lastIndex state:
const regex = /foo/g
regex.test('foo') // true, lastIndex = 3
regex.test('foo') // false, lastIndex = 0
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 46 lines · 0 tokens per session scan A f9e9aef2f7c2
rules--js-hoist-regexp is a cursor rule published in the GitHub repository ratnesh-maurya/cursor-claude-personas (8 stars, last pushed 5mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 294 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other cursor rules, from other repositories
graphql-typescript-integration
A TypeScript rule for GraphQL operations that uses the API schema and queries to generate types. It helps type-check data and variables from the GraphQL server through to React components.
graphql-apollo-client-usage
A usage guide for fetching, changing, and subscribing to GraphQL data with Apollo Client in React. It covers loading and error states, cache updates, refetching, and reusable GraphQL fragments.
chakra-ui---component-composition
A React component-structure rule for composing Chakra UI components into reusable interfaces. It favors small custom components built from layout and interface pieces such as Box, Flex, and Stack.
react-general-preferences
A set of React preferences that favors function components with Hooks, which let functions use state and other React features.
react-functional-components-preference
A React style rule that prefers function components with Hooks such as useState and useEffect over class components. Hooks are React functions for managing state and other component behavior.
chakra-ui---accessibility-features
An accessibility rule for React interfaces built with Chakra UI, a component library. It covers semantic HTML, screen-reader labels, keyboard navigation, focus handling, and color contrast.