Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/abderrahimghazali/cursor-rules/github-actions-standardsgit clone --depth 1 https://github.com/abderrahimghazali/cursor-rulesWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00577 |
| Opus 5 | $0.00000 | $0.00289 |
| Sonnet 5 | $0.00000 | $0.00115 |
| Haiku 4.5 | $0.00000 | $0.00058 |
Grade A, and why
github-actions-standards scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
GitHub Actions Standards
Ensures GitHub Actions workflows follow best practices and use the latest action versions.
actions:
-
type: enforce conditions:
-
pattern: "uses:\s*actions/upload-artifact@v[123]" message: "Use actions/upload-artifact@v4 instead of older versions. Version 3 is deprecated: https://github.blog/changelog/2024-04-16-deprecation-notice-v3-of-the-artifact-actions/"
-
pattern: "uses:\s*actions/download-artifact@v[123]" message: "Use actions/download-artifact@v4 instead of older versions."
-
pattern: "uses:\s*actions/checkout@v[12]" message: "Consider using actions/checkout@v4 for the latest features and security updates."
-
-
type: suggest message: | GitHub Actions Best Practices:
- Latest Action Versions: Always use the latest stable versions of GitHub Actions.
actions/checkout@v4actions/upload-artifact@v4actions/download-artifact@v4actions/setup-node@v4actions/setup-python@v5
- Workflow Structure: Organize workflows with clear job names and step descriptions.
- Caching: Implement caching for dependencies to speed up workflows.
- Security: Use
GITHUB_TOKENwith minimum required permissions. - Artifacts: Use descriptive names for artifacts and set appropriate retention periods.
- Matrix Strategy: Use matrix builds for testing across multiple environments.
- Timeouts: Set appropriate timeouts for jobs to prevent hanging workflows.
- Latest Action Versions: Always use the latest stable versions of GitHub Actions.
-
type: validate conditions:
-
pattern: "uses:\s*actions/upload-artifact@v4" message: "Good job using the latest version of actions/upload-artifact!"
-
pattern: "uses:\s*actions/download-artifact@v4" message: "Good job using the latest version of actions/download-artifact!"
-
pattern: "uses:\s*actions/checkout@v[34]" message: "Good job using a recent version of actions/checkout!"
-
metadata: priority: high version: 1.0 tags: - ci/cd - github - automation
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 65 lines · 0 tokens per session scan A 1d37aa467dee
github-actions-standards is a cursor rule published in the GitHub repository abderrahimghazali/cursor-rules (2 stars, last pushed 1y ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 577 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
cursor
You are working on the checkout service. Preserve transaction integrity and auditability.
creating-cursor-rules
Meta-rule for creating effective Cursor IDE rules with best practices, patterns, and examples.
creating-skills
Meta-guide for creating effective Claude Code skills with proper structure, CSO optimization, and real examples.
test-case-to-katalon-studio
Convert Katalon True Platform/TestOps manual test cases into Katalon Studio automation inside a local Studio Test Project checkout. Use when you need to author or extend a .tc test case file and its paired Groovy script under Scripts/, keep test case variable GUIDs consistent with the .ts test suite bindings that read…
stripe-payments
Stripe payment integration patterns — server-only, webhook handling.
git-branch-agent
This rule enforces standards and best practices for branch management operations including checkout, creation, and deletion. This rule should be followed when: 1. creating new branches, 2. switching between branches, 3. deleting branches, or 4. when the git aliases 'gco', 'gcb', or similar branch-related commands are…