Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/ai-supervisor-foundry/foundry/alwaysgit clone --depth 1 https://github.com/ai-supervisor-foundry/foundryWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00167 | $0.00167 |
| Opus 5 | $0.00084 | $0.00084 |
| Sonnet 5 | $0.00033 | $0.00033 |
| Haiku 4.5 | $0.00017 | $0.00017 |
Grade B, and why
always scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Unrestricted tool accessmediumExcessive agency
A wildcard tool grant or "run any command" leaves no least-privilege boundary at all.
4. After root cause found or fix identified or suspected, NEVER run any commands, verify if I approve of solutions. What it actually says
- Be concise with your ending responses unless asked for elaboration.
- Propose means suggest without edits.
- Don't make more than 6 line changes at a time, if there are more suggest the next 6 lines you would change. After each 6 lines that you have changed, announce, tell me, let me review and acknowledge and then proceed with the next.
- After root cause found or fix identified or suspected, NEVER run any commands, verify if I approve of solutions.
- Always check if you have MCP available before asking me.
- Everytime I ask a question - answer alone and dont take any other mutating actions / make changes.
- Even if you realize you made a mistake. Alert, inform me and halt, dont make changes.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today First seen · 10 lines · 167 tokens per session scan B aadfe798b111
always is a cursor rule published in the GitHub repository ai-supervisor-foundry/foundry (11 stars, last pushed 1mo ago), licensed MIT. It adds 167 tokens to every session, about $0.0008 per session on Opus 5. A static security scan graded it B with 1 finding (unrestricted tool access). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-02.
Other cursor rules, from other repositories
agent-mesh
Use Agent Mesh to ask and answer cross-project questions.
cursor-rules-meta-guide
Guidelines for creating and maintaining Cursor rules to ensure consistency and effectiveness.
skill-writer
Cursor rule "skill-writer" from theneoai/skill-writer, covering skill summary, §0 quick start — 5 common workflows, workflow a — "i want to create a new skill", workflow c — "my skill scored below 700 (fail)" and workflow d — "i want to deploy my skill".
skills_prompt
Cursor rule "skills_prompt" from nemori-ai/agent_skills, covering what are skills?, when to use skills?, when to create skills?, usage process and tool permissions and file access.
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.