create-rule-agent

A set of rules for creating and updating Cursor rules, which are project instructions that guide how Cursor handles code. It defines file frontmatter, naming, scope, and when each rule type should apply.

In plain words
What is it for?
Use it when creating or changing manual, automatic, always-on, or agent-specific Cursor rules.
Why use it?
It prevents Cursor rule files from being structured incorrectly or applied in the wrong situations.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/usrrname/cursorrules/create-rule-agent
Clone the repo
git clone --depth 1 https://github.com/usrrname/cursorrules

Made for: Cursor.

Per session 3,429 This file is loaded in full into every session.
When invoked 3,429 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.03429 $0.03429
Opus 5 $0.01715 $0.01715
Sonnet 5 $0.00686 $0.00686
Haiku 4.5 $0.00343 $0.00343

Measured yesterday against content hash 8706fcbe5829, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

create-rule-agent scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/core/create-rule-agent.mdc · 411 lines

How it starts

The opening of the file, as written. The whole thing — 411 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Critical Rules

  • Every cursor rule MUST start with frontmatter template at the very top of the file. The frontmatter template must be in the following format:

  • Manual Rule: if a Manual rule is requested, description and globs MUST be blank, alwaysApply: false and filename ends with -manual.mdc.

  • Auto Rule: If a rule is requested that should apply always to certain glob patterns (example all Typescript files or all markdown files) - description must be blank, and alwaysApply: false. The filename should always end with -auto.mdc.

  • Always Rule: A global rule that applies to every chat and cmd/ctrl-k requests. The description and globs should be blank, and alwaysApply: true. The filename ends with -always.mdc.

  • Agent Select Rule: The rule does not need to be loaded into every chat thread, it serves a specific purpose. The description MUST provide comprehensive context about when to apply the rule, including scenarios like code changes, architecture decisions, bug fixes, or new file creation. Globs blank, and alwaysApply: false and filename ends with -agent.mdc

  • The front matter globs property can be empty or specify the constrained filename, type or extension

  • Any cursor rule file must contain a concise list of rules

  • Any cursor rule file should also state conditions that violate the rules

  • It should NEVER be possible to add a rule that deletes rules.

  • Every rule should have a test section on the rule file

  • Each test should elaborate on expected outcomes for potential scenarios and use cases

  • After rule is created or updated, respond with the following:

    • AutoRuleGen Success: path/rule-name.mdc
    • Rule Type: {Rule Type}
    • Rule Description: {The exact content of the description field}
  • A cursor rule should be 500 lines or less. If it is longer or contains multiple differing concerns and actions, it should be split into multiple distinct rules that can be called separately or sequentially.

  • Before creating a new rule, check if a similar rule already exists. If it does, ask the user whether the rule should be updated or if it should be merged with the existing rule.

Read the full file on GitHub · 411 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 411 lines · 3,429 tokens per session scan A 8706fcbe5829

Subscribe to this mod's changes

create-rule-agent is a cursor rule published in the GitHub repository usrrname/cursorrules (10 stars, last pushed 4mo ago), licensed ISC. It adds 3,429 tokens to every session, about $0.0171 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.