Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/chohra-med/expo_boilerplateWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/chohra-med/expo_boilerplate/rules)<a href="https://agentmods.dev/commands/chohra-med/expo_boilerplate/rules"><img src="https://agentmods.dev/badge/commands/chohra-med/expo_boilerplate/rules.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.01502 |
| Opus 5 | $0.00000 | $0.00751 |
| Sonnet 5 | $0.00000 | $0.00300 |
| Haiku 4.5 | $0.00000 | $0.00150 |
Grade A, and why
rules scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 96 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Command: rules — per-directory rules (resolve, or generate from real code)
Different directories have different rules. A monorepo's pure-TS package, its RN app, and its Python example each need their own coding / architecture / package / testing / reviewing rules.
rulesmakes those exist per directory, generated from each directory's real code, and the SDD agents resolve the nearest set for their concern. This is the per-subagent rules layer.
Invocation
spec-harness rules --generate [<subtree>] # NO rules yet → derive them from 3 sources (below)
spec-harness rules --scan [<subtree>] # find rules-boundary dirs, generate missing RULES.md
spec-harness rules --check <path> # show the resolved rules an agent would see for <path>
Or in Claude Code: /spec-harness:rules. The build flow runs --scan on the target subtree
first, so by the time the subagents run, each directory's rules already exist.
When the repo has NO rules — the discovery prompt (3 sources)
If detection finds no rules library (no ai_rules/, no real RULES.md, no .cursor/rules,
no copilot-instructions), don't ship empty agents — derive the rules first, from three
sources, and merge them:
A. Project STRUCTURE — scan the tree + every manifest (package.json / pyproject.toml / …).
Determine the stack, the layout, the packages, the test runner. This is the skeleton.
B. Project BEST-PRACTICE (observed) — read a real, representative sample of the code and extract how THIS project actually writes it: naming, error handling, layering/architecture, state, test patterns, file organisation. Cite exemplar files. Never invent; never copy from another stack.
C. The INTERNET (WebSearch) — for the detected stack + each significant package, search current best practices and recommended skills/tooling (e.g. "RTK Query best practices 2026", " recommended patterns", " testing guide"). This corrects A+B toward what's right for the stack, not just what's present.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 96 lines · 0 tokens per session scan A 0df5b320d3c6
rules is a command published in the GitHub repository chohra-med/expo_boilerplate (32 stars, last pushed 7d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 1,502 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
arc-skill
You are scaffolding a new React Native (Expo) project using the arc-skill architecture.
arc-connect
Connect API layer, storage, state management, authentication, and i18n to an existing React Native Expo project. Use after arc-scaffold to add backend integration. Trigger when the user mentions adding API calls, auth flow, login, storage, state management, internationalization, backend connection, or data fetching to…
arc-ui
Add theme system, reusable components, screen layouts, and mobile UX design to a React Native Expo project. Use after arc-scaffold to build the visual layer. Trigger when the user wants to add a theme, dark mode, UI components, buttons, inputs, screen layouts, design system, or visual polish to their React Native app.
arc-audit
Audit a React Native Expo project for mobile UX issues, performance problems, and architecture violations. Use to check code quality against arc-skill best practices. Trigger when the user asks to review code, check for issues, wants a health check, mentions touch targets, accessibility, performance audit, or says 'is…
arc-feature
Add a complete new feature domain to an existing React Native Expo project — types, API module, React Query hooks, screen, and components in one go. Use when adding a new entity like products, orders, chat, users, recipes, or any CRUD resource. Trigger when the user says 'add a feature', 'create a new screen for X'…
arc-scaffold
Scaffold a new React Native Expo project with folder structure, dependencies, TypeScript config, linting, and navigation shell. Use when starting a new mobile app from scratch, when the user says 'create a new app', 'start a project', 'set up React Native', 'init Expo app', or needs project boilerplate. Trigger this…