main

A set of coding rules for Rust projects that chooses guidance based on project complexity, such as a single package or a multi-package workspace.

In plain words
What is it for?
Use it when organizing Rust projects and choosing guidance for shared libraries, separate deployable parts, web frameworks, or database access.
Why use it?
It gives developers relevant structure and practices without applying the same rules to every Rust project.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/tyrchen/cursor-rust-rules/main
Clone the repo
git clone --depth 1 https://github.com/tyrchen/cursor-rust-rules

Made for: Cursor.

Per session 0 Nothing until a file matches its globs; then the whole rule loads.
When invoked 3,926 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.03926
Opus 5 $0.00000 $0.01963
Sonnet 5 $0.00000 $0.00785
Haiku 4.5 $0.00000 $0.00393

Measured 2d ago against content hash 77fc36acafe3, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

main scanned grade A with 0 findings against 26 rules in 11 categories โ€” prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency โ€” measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/rust/main.mdc ยท 416 lines

How it starts

The opening of the file, as written. The whole thing โ€” 416 lines โ€” stays where its author put it; the contents beside it link to each section on GitHub.

๐Ÿฆ€ RUST PROJECT RULE SET SYSTEM

TL;DR: This system provides comprehensive guidelines for Rust project development with complexity-based rule loading, following industry best practices for scalable, maintainable Rust code.

๐Ÿ” PROJECT COMPLEXITY DETERMINATION

graph TD
    Start["New Rust Project"] --> Analyze["Analyze Project Requirements"]
    Analyze --> Q1{"Multiple distinct<br>functional domains?"}
    Q1 -->|Yes| Q2{"Expected LOC<br>> 10,000?"}
    Q1 -->|No| Q3{"Single domain with<br>multiple components?"}

    Q2 -->|Yes| Complex["COMPLEX PROJECT<br>Multi-crate workspace"]
    Q2 -->|No| Q4{"Shared libraries<br>needed?"}
    Q4 -->|Yes| Complex
    Q4 -->|No| Simple["SIMPLE PROJECT<br>Single crate"]

    Q3 -->|Yes| Q5{"Need separate<br>deployable units?"}
    Q3 -->|No| Simple
    Q5 -->|Yes| Complex
    Q5 -->|No| Simple

    Complex --> LoadComplex["Load Complex Rules"]
    Simple --> LoadSimple["Load Simple Rules"]

    LoadComplex --> Features["Load Feature-Specific Rules"]
    LoadSimple --> Features

    Features --> Web{"Web Framework<br>needed?"}
    Features --> DB{"Database<br>access needed?"}
    Features --> CLI{"CLI interface<br>needed?"}
    Features --> GRPC{"gRPC/Protobuf<br>needed?"}
    Features --> Concurrent{"Heavy<br>concurrency?"}
    Features --> Config{"Complex config<br>or templating?"}
    Features --> Observability{"Metrics & tracing<br>needed?"}
    Features --> ConfigMgmt{"Dynamic config<br>management?"}

    Web -->|Yes| WebRules["Load Axum Rules"]
    DB -->|Yes| DBRules["Load Database Rules"]
    CLI -->|Yes| CLIRules["Load CLI Rules"]
    GRPC -->|Yes| GRPCRules["Load Protobuf & gRPC Rules"]
    Concurrent -->|Yes| ConcurrencyRules["Load Concurrency Rules"]
    Config -->|Yes| ToolsRules["Load Tools & Config Rules"]
    Observability -->|Yes| ObservabilityRules["Load Observability Rules"]
    ConfigMgmt -->|Yes| ConfigMgmtRules["Load Configuration Rules"]

    style Start fill:#4da6ff,stroke:#0066cc,color:white
    style Complex fill:#d94dbb,stroke:#a3378a,color:white
    style Simple fill:#4dbb5f,stroke:#36873f,color:white
    style LoadComplex fill:#ffa64d,stroke:#cc7a30,color:white
    style LoadSimple fill:#4dbbbb,stroke:#368787,color:white

Read the full file on GitHub ยท 416 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen ยท 416 lines ยท 0 tokens per session scan A 77fc36acafe3

Subscribe to this mod's changes

main is a cursor rule published in the GitHub repository tyrchen/cursor-rust-rules (27 stars, last pushed 1y ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 3,926 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.