New Cursor Rules

I’m new to Cursor and trying to figure out cursor rules for some security features I’d like to include. I’ve got a branch here where I’m trying to add new OWASP Top Ten rules for Drupal and JavaScript, but I can’t seem to get the rules to work. The repo will be open source, I’m hoping I can get some tips, maybe on some of the JavaScript focussed Top Ten rules to help me finish these off, GitHub - salsadigitalauorg/cursorrules at feat/addtional-js-owasp-rules.