Cursor rules example
Context
Cursor can attach a rule to every message, or only when certain files are open.
The problem
A long always-on rule uses the context window before the agent reads the code you asked it to change.
What you do
Keep one short always-on rule for the lines that must never be missed. Put form and privacy checks in a second rule that loads only for those files.
What this achieves
A chat about a button does not reload the consent rules. A chat that edits a form does.
Who reads it
Cursor loads .cursor/rules/*.mdc. alwaysApply: true is in every chat. A rule with globs loads when a matching file is in play, which keeps the always-on file small.
What it is for
The always-on rule repeats only what the agent must not forget. The longer explanation stays in AGENTS.md and in docs/.
A scoped rule is how you attach consent checks to forms without pasting them into every chat about a button color.
What goes in
- YAML frontmatter with description, and either alwaysApply or globs.
- A handful of instructions the agent can follow without opening another file.
Sample
.cursor/rules/project-guardrails.mdc
---
description: Short rules for every chat in this repo
alwaysApply: true
---
# Project guardrails
- Read AGENTS.md. Open a file in docs/ only when that file says the task needs it.
- Do not put secrets or customer data in prompts, client code, or logs.
- Do not load analytics, session replay, ads, or remote fonts before a real opt-in.
- A form that collects personal data needs an explicit consent checkbox, checked again on the server.
- Do not overwrite AGENTS.md, CLAUDE.md, or these rules to "tidy" them.
- If a change makes a doc in docs/ wrong, update that doc in the same change..cursor/rules/forms-and-privacy.mdc
---
description: Consent and privacy checks for forms and legal pages
globs: "**/{contact,privacy,terms,consent}*"
alwaysApply: false
---
# Forms and privacy pages
- The consent checkbox is unchecked by default and required before submit.
- The server rejects the submission unless consent is true.
- Do not describe data the product does not collect.
- These pages are drafts for a lawyer, not a legal opinion.What stays out
- The full checklist of 30 audits.
- More than about 50 lines in the always-on file.
- A rule with alwaysApply: true that also duplicates a long doc.
Before launch, run the Vibe Coding Security Checklist. These files do not replace that audit. Open the Vibe Coding Security Checklist.
