Papa Tech Solutions

Cursor rules example

Context

Cursor can attach a rule to every message, or only when certain files are open.

The problem

A long always-on rule uses the context window before the agent reads the code you asked it to change.

What you do

Keep one short always-on rule for the lines that must never be missed. Put form and privacy checks in a second rule that loads only for those files.

What this achieves

A chat about a button does not reload the consent rules. A chat that edits a form does.

Who reads it

Cursor loads .cursor/rules/*.mdc. alwaysApply: true is in every chat. A rule with globs loads when a matching file is in play, which keeps the always-on file small.

What it is for

The always-on rule repeats only what the agent must not forget. The longer explanation stays in AGENTS.md and in docs/.

A scoped rule is how you attach consent checks to forms without pasting them into every chat about a button color.

What goes in

Sample

.cursor/rules/project-guardrails.mdc

---
description: Short rules for every chat in this repo
alwaysApply: true
---

# Project guardrails

- Read AGENTS.md. Open a file in docs/ only when that file says the task needs it.
- Do not put secrets or customer data in prompts, client code, or logs.
- Do not load analytics, session replay, ads, or remote fonts before a real opt-in.
- A form that collects personal data needs an explicit consent checkbox, checked again on the server.
- Do not overwrite AGENTS.md, CLAUDE.md, or these rules to "tidy" them.
- If a change makes a doc in docs/ wrong, update that doc in the same change.

.cursor/rules/forms-and-privacy.mdc

---
description: Consent and privacy checks for forms and legal pages
globs: "**/{contact,privacy,terms,consent}*"
alwaysApply: false
---

# Forms and privacy pages

- The consent checkbox is unchecked by default and required before submit.
- The server rejects the submission unless consent is true.
- Do not describe data the product does not collect.
- These pages are drafts for a lawyer, not a legal opinion.

What stays out

Before launch, run the Vibe Coding Security Checklist. These files do not replace that audit. Open the Vibe Coding Security Checklist.