Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/renvia-code/best-cursor-rules/securitygit clone --depth 1 https://github.com/Renvia-code/best-cursor-rulesWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.01913 |
| Opus 5 | $0.00000 | $0.00957 |
| Sonnet 5 | $0.00000 | $0.00383 |
| Haiku 4.5 | $0.00000 | $0.00191 |
Grade A, and why
security scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 365 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Security Best Practices
Overview
| Area | Priority |
|---|---|
| Authentication | Critical |
| Authorization | Critical |
| Input Validation | Critical |
| Data Protection | High |
| API Security | High |
Authentication
Password Handling
// ✅ Use bcrypt or argon2 for password hashing
import bcrypt from 'bcrypt'
const SALT_ROUNDS = 12
async function hashPassword(password: string): Promise<string> {
return bcrypt.hash(password, SALT_ROUNDS)
}
async function verifyPassword(password: string, hash: string): Promise<boolean> {
return bcrypt.compare(password, hash)
}
// ❌ Never store plain text passwords
// ❌ Never use MD5 or SHA1 for passwords
// ❌ Never log passwords
JWT Tokens
import jwt from 'jsonwebtoken'
// ✅ Short-lived access tokens
const ACCESS_TOKEN_EXPIRY = '15m'
// ✅ Longer refresh tokens (stored securely)
const REFRESH_TOKEN_EXPIRY = '7d'
function generateAccessToken(userId: string): string {
return jwt.sign(
{ sub: userId, type: 'access' },
process.env.JWT_SECRET!,
{ expiresIn: ACCESS_TOKEN_EXPIRY }
)
}
// ✅ Always verify tokens
function verifyToken(token: string): JwtPayload {
return jwt.verify(token, process.env.JWT_SECRET!) as JwtPayload
}
Session Security
// ✅ Secure cookie settings
const sessionConfig = {
httpOnly: true, // Prevents XSS access to cookie
secure: true, // HTTPS only (in production)
sameSite: 'strict', // Prevents CSRF
maxAge: 24 * 60 * 60 * 1000, // 24 hours
}
Input Validation
Validate All Input
import { z } from 'zod'
// ✅ Define strict schemas
const userSchema = z.object({
email: z.string().email().max(255),
password: z.string().min(8).max(100),
name: z.string().min(1).max(100).regex(/^[a-zA-Z\s]+$/),
})
// ✅ Validate before processing
function createUser(input: unknown) {
const validated = userSchema.parse(input)
// Safe to use validated data
}
Prevent SQL Injection
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 365 lines · 0 tokens per session scan A bd3f801ca402
security is a cursor rule published in the GitHub repository Renvia-code/best-cursor-rules (12 stars, last pushed 9mo ago), licensed CC0-1.0. It costs nothing until one of its globs matches a file; then it loads 1,913 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
ankra-cli
Ankra CLI rules and best practices for managing Kubernetes clusters via the Ankra platform.
go-backend-scalability-cursorrules-prompt-file
Cursor rules for Go development with backend scalability.
cloudflare-email-telegram-cursorrules-prompt-file
Cursor rules for setting up email-to-Telegram forwarding via Cloudflare Email Routing and Workers using the mail2tg CLI.
flutter-riverpod-cursorrules-prompt-file
Cursor rules for Flutter Riverpod.
angular-novo-elements-cursorrules-prompt-file
Cursor rules for Angular development with Novo Elements UI library.
automl-hyperparameter-optimization
AutoML and hyperparameter optimization rules for Python ML projects using Ray Tune, Optuna, PyCaret, and time-series AutoML libraries.