Cursor rule
Safety boundaries for re-cursive improvement runs.
1,087 tagged Security, measured the same way as everything else here.
Browse within: Drupal 51cursorrules 51cursor-rules 39ai-governance 36best-practices 33claude-code-skills 30gemini-cli-extension 30compliance 26coding-best-practices 21javascript-coding-standards 21php-coding-standards 21ai-coding-assistant 16aiagents 16nextjs 15
Cursor rule
Safety boundaries for re-cursive improvement runs.
Cursor rule Cursor
Security facades and CSP, server-first performance, virtualization, accessibility, and i18n key discipline.
Cursor rule
Node.js & Express API security footguns — missing auth/authz middleware, IDOR, broken JWT verification, permissive CORS, SQL/NoSQL/command injection, missing rate limiting, mass assignment. Apply when reviewing, building, or shipping a Node/Express (or Fastify/Koa/Nest) backend.
Cursor rule
Stripe security footguns — unverified webhook signatures, trusting price/amount from the client, secret key exposure, missing idempotency, fulfilling on the wrong event. Apply when reviewing, building, or shipping payment or billing flows with Stripe.
Cursor rule
Supabase security footguns — Row Level Security disabled or too permissive, servicerole key exposed to the client, weak policies, public storage buckets, client-set privilege columns. Apply when the app uses Supabase (Postgres, Auth, Storage, Edge Functions).
TrevorEdris/fellowship-of-the-workflows
Cursor rule
AWS CDK construct authoring conventions: L1/L2/L3 construct selection, security defaults, stack and stage structure, cdk-nag security scanning, and assertions testing. Apply when cdk.json is present in the project.
TrevorEdris/fellowship-of-the-workflows
Cursor rule
CloudFormation and SAM template authoring conventions: intrinsic function usage, parameter security, stateful resource protection, cross-stack coupling, and change set discipline.
Cursor rule Cursor
Security Validator — check for hardcoded secrets, broken auth, and input handling issues.
Cursor rule Cursor
ArbiterX engineering discipline — enforces minimal, robust, unbreakable code.
Cursor rule Cursor
How to encrypt and manage secrets with ansible-vault in this project.
vaquarkhan/compliance-agent-skills
Cursor rule Cursor
Core compliance agent mission, PHI redaction gate, and audit lifecycle for HIPAA, PCI-DSS, and SOC 2.
vaquarkhan/compliance-agent-skills
Cursor rule Cursor
Enforce deterministic audit behavior — no invented controls, cite authoritative sources, emit traceable artifacts.
Cursor rule Cursor
A set of shell rules for handling files safely from the command line. It describes commands that should require confirmation or be blocked, commands that are allowed, and safer alternatives.
HermeticOrmus/linux-sysadmin-skills
Cursor rule Cursor
Linux sysadmin workflows for Debian/Ubuntu (apt, systemd, journalctl) covering security, performance, diagnose, monitor, maintain. Confirm before destructive operations.
Cursor rule Cursor
A set of security and TypeScript rules for Tauri applications. Tauri is a framework for building desktop apps with web technologies and Rust.
Cursor rule Cursor
SPCS deployment best practices and compliance checklist.
Cursor rule
Guard mysql-cli write/ddl/destructive operations; request human approval before running them.
LucasRocha179/mcp-vault-reader
Cursor rule Cursor
Please refer to the official Agent Guidelines in .agents/AGENTS.md for complete rules.
Cursor rule
dual-plane telegram mcp: read-only analytics + guarded actions with anti-spam and block-risk controls.
Cursor rule
Guide for authenticating with the AGNTCY Directory instance via dirctl — using the bundled binary or DIRECTORYDIRCTLPATH, never PATH scanning.
tealfabric/cursor-mcp-tealfabric
Cursor rule
Keep Tealfabric API credentials out of source control and logs.
Cursor rule
MCPKernel security rules for AI agent tool calls. Use when working with MCP tool servers, AI agents, or any code that makes autonomous tool calls.
Cursor rule Cursor
When the user asks about DORA (Digital Operational Resilience Act), ICT risk management, financial sector cybersecurity, third-party ICT risk, or Regulation (EU) 2022/2554, use the dora-compliance-mcp tools.
Cursor rule Cursor
When the user asks about SBOM, CycloneDX, SPDX, supply chain, EO 14028, VEX, use sbom-cyclonedx-mcp tools.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: