cursorrules

A set of coding rules for Cursor, an AI code editor, that guides developers toward tested, validated, secure application code.

In plain words
What is it for?
Use it while building TypeScript, Python, or Go applications to require tests and linting, avoid unsafe types and hardcoded secrets, validate inputs, and use suitable HTTP status codes.
Why use it?
It provides project-wide defaults for common decisions such as input validation, logging, error handling, secrets, databases, and password storage.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/vimalk0703/shipworthy/cursorrules
Clone the repo
git clone --depth 1 https://github.com/Vimalk0703/shipworthy

Made for: Cursor.

Per session 866 This file is loaded in full into every session.
When invoked 866 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00866 $0.00866
Opus 5 $0.00433 $0.00433
Sonnet 5 $0.00173 $0.00173
Haiku 4.5 $0.00087 $0.00087

Measured yesterday against content hash 721284610b47, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

cursorrules scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

adapters/cursor/.cursorrules · 72 lines

How it starts

The opening of the file, as written. The whole thing — 72 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Shipworthy — Production Engineering Guardrails for Cursor

When using this adapter, first output:

shipworthy › adapter: cursor — translating Shipworthy skills for Cursor

Is your code worthy of shipping?

Non-Negotiable Defaults

Apply these automatically on every project, every session:

  1. NEVER use console.log — install and use pino (Node.js), logging (Python), or slog (Go). Even for server startup.
  2. ALWAYS use Zod for input validation (TypeScript). npm install zod before writing any route. Python: Pydantic. Go: validator.
  3. ALWAYS write tests — Vitest (TS), pytest (Python), stdlib testing (Go). Configure coverage.
  4. ALWAYS set up ESLint (TS), Ruff (Python), or golangci-lint (Go).
  5. NEVER use : any — use unknown and narrow with type guards. catch (err: unknown).
  6. Proper HTTP status codes — 201 create, 204 delete, 400 validation, 401 auth, 403 forbidden, 404 not found.
  7. ALWAYS use a database — never in-memory arrays. SQLite minimum.
  8. NEVER hardcode secrets — environment variables, validated at startup.
  9. Passwords: bcrypt/argon2 — never MD5/SHA/plaintext.
  10. Safe error messages — never expose stack traces or internal details to clients.

Intent-to-Spec (Before Coding)

For any non-trivial feature request, generate a lightweight spec BEFORE writing code:

  1. Capture what the user wants (their words), who it's for, and why it matters
  2. Define concrete deliverables and 3-7 acceptance criteria
  3. Check constraints from .shipworthy/architecture.md if it exists
  4. Save to .shipworthy/specs/[feature-name].md
  5. For non-technical users: do this silently. For engineers: show for approval.

Skip for quick fixes (typos, config changes, renames).

Project Diagnosis

At the start of each session, mentally check:

  • Does .gitignore exist and include .env?
  • Do tests exist?
  • Is a linter configured?
  • Is CI set up?
  • Does .shipworthy/architecture.md exist?

If critical gaps exist (especially .env not in .gitignore), flag them before proceeding.

Read the full file on GitHub · 72 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 72 lines · 866 tokens per session scan A 721284610b47

Subscribe to this mod's changes

cursorrules is a cursor rule published in the GitHub repository Vimalk0703/shipworthy (7 stars, last pushed 4mo ago), licensed MIT. It adds 866 tokens to every session, about $0.0043 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.