CyberStrategyInstitute/ai-safe2-framework
Cursor rule Cursor
AI SAFE2 v3.0 Sovereign Security Rules for Cursor.
140 tagged compliance, measured the same way as everything else here.
Browse within: ai-governance 64csoai 52audit 38enterprise 37ai-gateway 34bedrock 34dach 15dpf 15fedramp 7meok 5
CyberStrategyInstitute/ai-safe2-framework
Cursor rule Cursor
AI SAFE2 v3.0 Sovereign Security Rules for Cursor.
Cursor rule Cursor
Foundational Agile V framework rules for traceable, verifiable AI-augmented engineering. Enforces requirements traceability (REQ-XXXX), independent verification (Build Agent + Red Team), and compliance-ready artifacts. Use for enterprise product development.
Cursor rule Cursor
Binding — code changes must update matching docs (architecture / feature / API / runbook / SDD) in the same diff.
Cursor rule Cursor
Self-audit before claiming work is complete (no defer / follow-up / mock).
Cursor rule Cursor
Canonical = OpenAI shape; each non-OpenAI adapter owns its bidirectional translation (8 binding rules from provider-adapter-architecture.md §3a).
oscal-compass-lab/compliance-trestle-skills
Cursor rule Cursor
Compliance Trestle repository rules.
oscal-compass-lab/compliance-trestle-skills
Cursor rule Cursor
Prefer Trestle markdown roundtrip over direct OSCAL JSON edits.
oscal-compass-lab/compliance-trestle-skills
Cursor rule Cursor
OSCAL import workspace guardrails.
Cursor rule Cursor
When you create or modify files in this project, stamp them with AKF trust metadata.
Cursor rule Cursor
Secure SDLC — automatically apply security practices at every phase of development.
Cursor rule
Use whenever code touches authentication, login, session management, audit logging, or application logging — even if the user's prompt doesn't mention DSGVO, GDPR, privacy, or "personal data". Triggers on bcrypt/argon2/scrypt, jsonwebtoken/jose, passport/next-auth/Auth.js/authjs/lucia, express-session/iron-session…
Cursor rule
Use whenever code touches newsletter, marketing-email, drip-campaign, re-engagement, win-back, lead-magnet, or any outbound email with promotional content — even if the user's prompt doesn't mention DSGVO, GDPR, UWG, privacy, or "personal data". Triggers on Mailchimp / @mailchimp/mailchimpmarketing, Brevo /…
Cursor rule
DSGVO Drittlandtransfer (Kapitel V, Art. 44-49). Use whenever code or infrastructure handles user data and touches a non-EU service or region — even if the user's prompt doesn't mention DSGVO/GDPR/privacy. Any user data (names, emails, IPs, user IDs, avatars, profile pictures, uploaded files, user-generated content…
Cursor rule Cursor
How to author a flagship in ks-cookbook.
Cursor rule Cursor
Python clean code for cookbook flagships and recipes.
Cursor rule Cursor
How to author a recipe in ks-cookbook.
Cursor rule
Saropa Lints project guidelines for AI agents.
Cursor rule Cursor
Project-wide conventions and ground rules.
Cursor rule Cursor
Security rules (always applied).
Cursor rule Cursor
Testing standards for test files.
SafetyMP/Autonomous-EHS-Management
Cursor rule Cursor
Corporate compliance & data governance for Autonomous EHS — retention, legal hold, PII/RAG, OSHA sidecar, Tier II, audit lifecycle; load the compliance skill when this applies.
SafetyMP/Autonomous-EHS-Management
Cursor rule Cursor
EHS IMS app — RBAC, data layer, tRPC, migrations, AI boundaries.
SafetyMP/Autonomous-EHS-Management
Cursor rule Cursor
Keep site work within the approved corporate handoff and evidence gates.
CSOAI-ORG/contract-review-ai-mcp
Cursor rule Cursor
When the user asks about contract review, use contract-review-ai-mcp tools: analyzecontract, extractclauses, identifyrisks, comparecontracts, summarizecontract.