gitruels

Git safety rules that tell a coding agent how to undo changes without accidentally deleting useful work. They require checking differences first and avoiding destructive Git commands without approval.

In plain words
What is it for?
Safely reviewing, undoing, or rejecting file changes in Git repositories, especially when only specific parts should be reverted.
Why use it?
They reduce the risk of permanently losing uncommitted code when reverting or cleaning up a project.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/waynesutton/markdown-site/gitruels
Clone the repo
git clone --depth 1 https://github.com/waynesutton/markdown-site

Made for: Cursor.

Per session 421 This file is loaded in full into every session.
When invoked 421 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00421 $0.00421
Opus 5 $0.00211 $0.00211
Sonnet 5 $0.00084 $0.00084
Haiku 4.5 $0.00042 $0.00042

Measured yesterday against content hash 12cc8d0ce610, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

gitruels scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/gitruels.mdc · 52 lines

What it actually says


description: Critical Git Safety Protocol globs: alwaysApply: true


Critical Git Safety Protocol

🚨 NEVER USE git checkout TO REVERT CHANGES 🚨

MANDATORY GIT SAFETY RULES:

  • NEVER run git checkout -- <file> without first examining what you're about to destroy
  • ALWAYS use git diff <file> to see exactly what changes will be lost
  • MANUALLY undo changes by editing files to revert specific problematic sections
  • Preserve valuable work — if user says changes are bad, ask which specific parts to revert
  • git checkout destroys ALL changes — this can eliminate hours of valuable progress
  • When user asks to "undo" changes: Read the current file, identify problematic sections, and manually edit to fix them

Why this matters: Using git checkout blindly can destroy sophisticated implementations, complex prompts, provider-specific logic, and other valuable work that took significant time to develop.

Git Safety Rules - CRITICAL

NEVER run these commands without explicit user approval:

  • git reset --hard - Destroys uncommitted changes permanently
  • git checkout -- . - Discards all working directory changes
  • git clean -fd - Deletes untracked files permanently
  • git stash drop - Deletes stashed changes

ALWAYS before any git operation:

  1. Run git status first to check for uncommitted changes
  2. If there are uncommitted changes, STOP and ASK the user before proceeding
  3. Suggest git stash to preserve changes if needed

If user asks to "revert" something:

  1. First clarify: revert committed changes or uncommitted changes?
  2. Show what will be affected before doing anything
  3. Get explicit confirmation for destructive operations

This rule exists because careless git operations destroyed 2 days of work.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 52 lines · 421 tokens per session scan A 12cc8d0ce610

Subscribe to this mod's changes

gitruels is a cursor rule published in the GitHub repository waynesutton/markdown-site (631 stars, last pushed 3mo ago), licensed MIT. It adds 421 tokens to every session, about $0.0021 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.