Guide · 3 min
Install XploitScan rules in Cursor
Instead of only scanning AFTER Cursor generates vulnerable code, give Cursor rules that steer it away from the most common security mistakes at write-time. One file, zero ongoing effort.
Add the ruleset file
In your project, create .cursor/rules/xploitscan-security.mdc and paste in the ruleset from the /cursor page.
Put a frontmatter block like the one in the example below at the top of the file. alwaysApply: true tells Cursor to apply the rules automatically.
Verify the file exists
Check that the file landed where Cursor expects it. On macOS / Linux:
ls -la .cursor/rules/xploitscan-security.mdc
Should show the file. If it's missing, check the folder name: .cursor/rules, with the leading dot.
Restart Cursor (or reopen the project)
Cursor picks up new rule files on project load. If you were already in the project, either restart Cursor or close + reopen the workspace folder. You don't need to tell Cursor about the rules — they're auto-detected.
Test that it worked
Ask Cursor to generate a Stripe webhook handler. Without the rules, Cursor may hand you a handler that reads req.body directly. After the rules are in place, the same prompt should produce a handler that usesexpress.raw() and stripe.webhooks.constructEvent() with signature verification.
Try this prompt in Cursor chat
“Add a Stripe webhook handler at /api/webhooks/stripe that increments a user's credit balance on checkout.session.completed.”
The generated code should include stripe.webhooks.constructEvent and express.raw. If it doesn't, check the rules are loaded (restart Cursor) and try again.
What's in the ruleset
Twelve rules covering the patterns XploitScan catches most often in AI-generated code:
- Webhook signature verification (Stripe, Clerk, GitHub, Resend, SendGrid, and other providers)
- No hardcoded secrets — everything via
process.env - Explicit auth check on every API route; IDOR protection via ownership check
- Parameterized SQL queries — no string concatenation
- CORS allowlist, never wildcard-with-credentials
- SSRF protection — reject private CIDRs on user-controlled URLs
- Session tokens in HttpOnly cookies, never localStorage
- No eval / new Function / exec with user input
- Security headers by default (CSP, HSTS, X-Frame-Options)
- DOMPurify before dangerouslySetInnerHTML / v-html
- jwt.verify with pinned algorithms, never jwt.decode
- Strip secrets / tokens before logging
The full ruleset to copy is on the /cursor page.
What the .mdc file looks like
For reference — an abridged excerpt of .cursor/rules/xploitscan-security.mdc:
--- description: XploitScan security rules for AI-generated code globs: - "**/*.js" - "**/*.ts" - "**/*.py" alwaysApply: true --- # XploitScan Security Rules 1. WEBHOOKS MUST BE SIGNATURE-VERIFIED - Stripe: use stripe.webhooks.constructEvent with the raw body - Never trust event.type from req.body 2. NO HARDCODED SECRETS - Read from process.env at runtime ...
Troubleshooting
“Command not found: npx”
Install Node 20.11 or later from nodejs.org, then retry.
Cursor doesn't seem to pick up the rules
Fully quit Cursor (Cmd-Q, not just close the window) and reopen the project. The rule files are loaded at project-open time.
I'm on an older Cursor version without .mdc support
Paste the same rules into a
.cursorrulesfile at the project root instead.
Rules are in place. Now run a scan to catch anything Cursor wrote before you installed them:
Next: Scan from the terminal →