Cursor Rules ConfigSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| cursor | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: cursor-rules-config description: 'Configure Cursor project rules using .cursor/rules/*.mdc files and legacy .cursorrules. Triggers on "cursorrules", ".cursorrules", "cursor rules", "cursor config", "cursor project settings", ".mdc rules", "project rules". ' allowed-tools: Read, Write, Edit, Bash(cmd:*) version: 1.19.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - cursor - cursor-rules compatibility: Designed for Claude Code --- # Cursor Rules Config ## Overview Manage Cursor rules as versioned engineering policy that shapes AI context and behavior; rules must be specific, scoped, reviewed, and consistent with repository source of truth. ## Prerequisites - Repository owner approval, existing engineering/security standards, and a test workspace. - A reviewed ignore strategy for secrets, generated files, and sensitive data. ## Instructions 1. Write one clear rule per concern with scope, priority, and concrete acceptance behavior. 2. Keep shared rules in source control and use path-scoped rules for local conventions. 3. Test new rules on a non-sensitive fixture, inspect resulting behavior, and merge via normal review. 4. Periodically remove stale/conflicting rules and document any intentional exceptions. ## Output - A reviewed, versioned rule set with clear scope and a tested behavior example. ## Error Handling | Condition | Safe response | |---|---| | Rules conflict | Resolve to one authority and test the revised rule before rollout. | | Rule exposes sensitive content | Remove it, repair ignore controls, and assess the exposure. | | Rule is too broad | Scope it by path/task rather than disabling all shared governance. | ## Examples Add a path-scoped API rule that requires existing validation and tests, then test it on a sanitized fixture. Open a PR for the rule and verify it does not apply to unrelated frontend files before merging. Configure project-specific AI behavior through Cursor's rules system. The modern approach uses `.cursor/rules/*.mdc` files; the legacy `.cursorrules` file is still supported but deprecated. ## Rules System Architecture ### Modern Project Rules (.cursor/rules/*.mdc) Each `.mdc` file contains YAML frontmatter followed by markdown content: ```yaml --- description: "Enforce TypeScript strict mode and functional patterns" globs: "src/**/*.ts,src/**/*.tsx" alwaysApply: false --- # TypeScript Standards - Use `const` over `let`, never `var` - Prefer pure functions over classes - All functions must have explicit return types - Use discriminated unions over enums ``` **Frontmatter fields:** | Field | Type | Purpose | |-------|------|---------| | `description` | string | Concise rule purpose (shown in Cursor UI) | | `globs` | string | Gitignore-style patterns for auto-attachment | | `alwaysApply` | boolean | `true` = always active; `false` = only when matching files referenced | ### Rule Types by `alwaysApply` + `globs` Combination | alwaysApply | globs | Behavior | |-------------|-------|----------| | `true` | empty | Always injected into every prompt | | `false` | set | Auto-attached when matching files are in context | | `false` | empty | Manual only -- reference with `@Cursor Rules` in chat | ### File Naming Convention Use kebab-case with `.mdc` extension. Names should describe the rule's scope: ``` .cursor/rules/ typescript-standards.mdc react-component-patterns.mdc api-error-handling.mdc testing-conventions.mdc database-migrations.mdc security-requirements.mdc ``` Create new rules via: `Cmd+Shift+P` > `New Cursor Rule` ### Complete Project Rules Example **`.cursor/rules/project-context.mdc`** (always-on): ```yaml --- description: "Core project context and conventions" globs: "" alwaysApply: true --- # Project: E-Commerce Platform Tech stack: Next.js 15, TypeScript 5.7, Prisma ORM, PostgreSQL, Tailwind CSS 4. Package manager: pnpm. Monorepo with turborepo. ## Conventions - API routes in `app/api/` using Route Handlers - Server Components by default, `"use client"` only when needed - Error boundaries at layout level - All monetary values stored as integers (cents) - Dates stored as UTC, displayed in user timezone ``` **`.cursor/rules/react-patterns.mdc`** (glob-scoped): ```yaml --- description: "React component standards for TSX files" globs: "src/**/*.tsx,app/**/*.tsx" alwaysApply: false --- # React Component Rules - Export components as named exports, not default - Props interface named `{Component}Props` - Use `forwardRef` for components accepting `ref` - Colocate styles in `.module.css` files - Server Components: no `useState`, `useEffect`, or event handlers ```tsx // Correct pattern export interface ButtonProps { variant: 'primary' | 'secondary'; children: React.ReactNode; onClick?: () => void; } export function Button({ variant, children, onClick }: ButtonProps) { return ( <button className={styles[variant]} onClick={onClick}> {children} </button> ); } ``` ``` **`.cursor/rules/api-routes.mdc`** (glob-scoped): ```yaml --- description: "API route handler patterns" globs: "app/api/**/*.ts" alwaysApply: false --- # API Route Standards - Always validate request body with Zod - Return typed `NextResponse.json()` responses - Use consistent error response shape: `{ error: string, code: string }` - Wrap handlers in try/catch with structured logging ```ts import { NextRequest, NextResponse } from 'next/server'; import { z } from 'zod'; const CreateOrderSchema = z.object({ items: z.array(z.object({ productId: z.string().uuid(), quantity: z.number().int().positive(), })), }); export async function POST(req: NextRequest) { try { const body = await req.json(); const parsed = CreateOrderSchema.parse(body); const order = await createOrder(parsed); return NextResponse.json(order, { status: 201 }); } catch (err) { if (err instanceof z.ZodError) { return NextResponse.json( { error: 'Validation failed',
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__cursor-rules-config.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Cursor Rules Config skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Cursor Rules Config safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Cursor Rules Config access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Cursor Rules Config work with?
Its documentation mentions claude-code and cursor. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.