lessons-learnt

A record of practical lessons and known pitfalls for cursor-doctor, the tool that audits project documentation and creates remediation plans.

In plain words
What is it for?
It is for maintaining the scanner and prescription generator, adding documentation or rules, interpreting audit results, and rechecking tracked project artifacts.
Why use it?
It warns developers about text matching, artifact ordering, health-score calculation, ignored folders, YAML errors, and required synchronization steps.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/ajgreyling/cursor-doctor/lessons-learnt
Clone the repo
git clone --depth 1 https://github.com/ajgreyling/cursor-doctor

Made for: Cursor.

Per session 280 This file is loaded in full into every session.
When invoked 280 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00280 $0.00280
Opus 5 $0.00140 $0.00140
Sonnet 5 $0.00056 $0.00056
Haiku 4.5 $0.00028 $0.00028

Measured yesterday against content hash 279aa578ec54, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

lessons-learnt scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/lessons-learnt.mdc · 33 lines

What it actually says

Lessons Learnt

Matching and completeness

  • Completeness checks are text-signal based; wording changes can flip a concept to incomplete unexpectedly.
  • Pattern matching assigns one artifact per concept in first-match order; broad patterns can hide better matches.

Prescription generation

  • artifact-sync is intentionally always appended as the final todo; do not remove that behavior from src/prescription.ts.
  • Health score is weighted (found=1, incomplete=0.5); keep docs aligned with this model.

Scanner behavior

  • Scanner intentionally ignores node_modules, dist, build, and .git to avoid noisy matches.
  • Frontmatter parsing is best-effort; invalid YAML should degrade gracefully, not fail the entire scan.

Operational discipline

  • After adding docs/rules/skills, re-run generate to validate detection behavior.
  • Keep tracked doctor artifacts in sync: README.md, .cursor/rules/cursor-doctor.mdc, .cursor/rules/required-cursor-doctor-skill.mdc, and .cursor/skills/cursor-doctor/SKILL.md.

Completeness checklist

  • sectioned by area
  • actionable do/don't
  • alwaysApply or referenced in workflow
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 33 lines · 280 tokens per session scan A 279aa578ec54

Subscribe to this mod's changes

lessons-learnt is a cursor rule published in the GitHub repository ajgreyling/cursor-doctor (0 stars, last pushed 28d ago), licensed MIT. It adds 280 tokens to every session, about $0.0014 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.