architecture-constraints

A set of rules for keeping a GolemBot codebase within its intended architecture. GolemBot is a framework built around assistant directories and skills, with separate areas for the core library and command-line interface.

In plain words
What is it for?
Check it before changing files under src/ to verify interface changes, engine-owned process launching, skill placement, configuration boundaries, and command-line responsibilities.
Why use it?
It prevents code changes from adding unsupported concepts, putting business logic in the command-line layer, or bypassing the project's process and configuration rules.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/0xranx/golembot/architecture-constraints
Clone the repo
git clone --depth 1 https://github.com/0xranx/golembot

Made for: Cursor.

Per session 0 Nothing until a file matches its globs; then the whole rule loads.
When invoked 576 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.00576
Opus 5 $0.00000 $0.00288
Sonnet 5 $0.00000 $0.00115
Haiku 4.5 $0.00000 $0.00058

Measured yesterday against content hash b6084848f018, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

architecture-constraints scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Runs shell commandslowCapability

Expected in a hook, worth knowing in a rule or an instructions file.

5. **Process invocation is engine-owned** — All engines use `child_process.spawn`. Do not assume invocation style outside the engine.
.cursor/rules/architecture-constraints.mdc · 41 lines

How it starts

The opening of the file, as written. The whole thing — 41 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Architecture Hard Constraints

When modifying code under src/, the following constraints must not be violated. To relax them, first update docs/architecture.md.

Things You Must Never Do

  1. Don't do what the Agent should do — GolemBot does not manage context window, dispatch tools, reason, or set session TTL. All "intelligent" behavior is delegated to the underlying Coding Agent.
  2. Don't add new core concepts — The framework has only two concepts: assistant directory + Skill. Do not introduce Tool, Blueprint, Registry, Pipeline, or other abstractions.
  3. Don't put CLI logic in the core librarycli.ts is a thin shell; it only parses arguments and formats output. All business logic must live in index.ts / workspace.ts / engine.ts / session.ts / server.ts.
  4. Don't declare Skills in config — The skills/ directory is the single source of truth. golem.yaml only configures engine and name.
  5. Process invocation is engine-owned — All engines use child_process.spawn. Do not assume invocation style outside the engine.

Interface Change Rules

  • Any signature change to the Assistant interface (index.ts) must be reflected in docs/architecture.md Chapter 5 (API definition)
  • Any change to the AgentEngine interface (engine.ts) must be reflected in docs/architecture.md Chapter 7
  • StreamEvent type changes must verify compatibility with server.ts SSE output and cli.ts event handling

File Responsibility Boundaries

File Responsibility Should Not Contain
index.ts Public API, concurrency locks, orchestration of workspace/engine/session Engine implementation details, HTTP logic
engine.ts Engine interface, Cursor / Claude Code implementations, stream-json parsing, Skill injection Session management, config loading
workspace.ts golem.yaml read/write, skills scanning, AGENTS.md generation Engine invocation, session management
session.ts Session persistence (indexed by sessionKey) Any other logic
server.ts HTTP service, SSE, auth Engine implementation details
cli.ts Argument parsing → call core API → format output Business logic

Read the full file on GitHub · 41 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 41 lines · 0 tokens per session scan A b6084848f018

Subscribe to this mod's changes

architecture-constraints is a cursor rule published in the GitHub repository 0xranx/golembot (318 stars, last pushed 13d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 576 tokens. A static security scan graded it A with 1 finding (runs shell commands). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.