cursorrules

A set of coding rules for JavaScript, Python, and Go projects. It says to create new data instead of changing existing data, keep files and functions focused, organise code by feature, and use clear names.

In plain words
What is it for?
Use it when writing or reviewing code, deciding how to organise files, naming variables and functions, updating collections, or keeping data changes immutable.
Why use it?
It reduces accidental side effects and makes code easier to understand, test, and maintain. It also sets boundaries that help prevent oversized files, deeply nested logic, and catch-all utility modules.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/versoxbt/claude-initial-setup/cursorrules
Clone the repo
git clone --depth 1 https://github.com/VersoXBT/claude-initial-setup

Made for: Cursor.

Per session 1,329 This file is loaded in full into every session.
When invoked 1,329 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin 95% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01329 $0.01329
Opus 5 $0.00665 $0.00665
Sonnet 5 $0.00266 $0.00266
Haiku 4.5 $0.00133 $0.00133

Measured yesterday against content hash a4b73332b67d, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

cursorrules scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

95% identical to claude-initial-setup — 6 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

.cursorrules · 190 lines

How it starts

The opening of the file, as written. The whole thing — 190 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Coding Standards

Immutability

Always create new objects instead of mutating. Use spread operators, structuredClone, or library solutions like immer.

// WRONG
user.name = name;
items.push(newItem);

// CORRECT
const updated = { ...user, name };
const added = [...items, newItem];
const removed = items.filter(x => x.id !== id);
const mapped = items.map(x => x.id === id ? { ...x, ...changes } : x);

Python: Use @dataclass(frozen=True) and replace(). Use tuples and frozensets for immutable collections. Go: Use value receivers and return new structs.

File Organization

  • 200-400 lines per file, 800 max
  • Organize by feature/domain, not by type
  • Co-locate tests next to source files
  • Move to shared/ only when used by 3+ features
  • No god files (utils.ts with 40 exports)

Functions

  • Under 50 lines each
  • No nesting deeper than 4 levels
  • Use early returns and guard clauses

Naming

  • Variables: describe WHAT (activeUsers), not HOW (data)
  • Booleans: is/has/can/should prefix (isActive, hasPermission)
  • Functions: verb + noun (getUserById, formatDate, validateEmail)
  • Collections: plural nouns (users, orderItems)
  • Constants: SCREAMING_SNAKE (MAX_RETRIES, API_BASE_URL)
  • Language casing: camelCase (JS/TS), snake_case (Python), PascalCase (Go exports)

Git Conventions

Commits

Format: <type>(<scope>): <description> Types: feat, fix, refactor, docs, test, chore, perf, ci Rules: imperative mood, lowercase, under 72 chars, no period

Branches

Format: <type>/<ticket>-<description> in kebab-case Types: feature/, fix/, hotfix/, release/

Pull Requests

  • Under 400 lines of changes
  • Include summary, changes, test plan
  • Squash merge for features, merge commit for releases
  • Never force-push during review

Testing

TDD Workflow

  1. RED: Write failing test
  2. GREEN: Write minimal code to pass
  3. REFACTOR: Clean up, keep tests green
  4. Target 80%+ coverage

Test Structure

  • Unit tests co-located: auth.ts / auth.test.ts
  • Integration tests: test/integration/
  • E2E tests: test/e2e/
  • Factories for dynamic data, fixtures for static data

Read the full file on GitHub · 190 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 190 lines · 1,329 tokens per session scan A a4b73332b67d

Subscribe to this mod's changes

cursorrules is a cursor rule published in the GitHub repository VersoXBT/claude-initial-setup (4 stars, last pushed 3mo ago), licensed MIT. It adds 1,329 tokens to every session, about $0.0066 per session on Opus 5. A static security scan graded it A with 0 findings. It is 95% identical to claude-initial-setup, differing in 6 lines, and is treated as a copy.