Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/andvolodko/html5-game-editor/editor-uigit clone --depth 1 https://github.com/andvolodko/html5-game-editorWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00669 |
| Opus 5 | $0.00000 | $0.00334 |
| Sonnet 5 | $0.00000 | $0.00134 |
| Haiku 4.5 | $0.00000 | $0.00067 |
Grade A, and why
editor-ui scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 36 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Editor UI / editor-core
Canonical scene and editor state lives in Editor (DocumentManager, SelectionManager, CommandManager, AssetManager, EditorViewportController). React is a view layer.
Separation
- React must not own scene trees, transforms, or asset catalogues as source of truth. Read via
useEditor/useEditorState; mutate viaEditor/ commands / workflows (importDroppedFiles,dropAssetOntoScene). - Do not call
document/scenemutators from components except througheditor.execute,editor.createSprite*,editor.setTransform2D,editor.saveScene/loadScene, or exported workflows. - Do not mutate
PIXI.DisplayObject/THREE.Object3Dfrom React. Viewport tools (e.g.bindPixiTransformTool) map renderer pointer callbacks →editor.selectNodes/editor.setTransform2D. Preview-only motion may update the renderer; commit one command on gesture end. - Keep application policy in
packages/editor-core(commands, asset workflows, browser folder helpers). Keep panels thin:HierarchyPanel,InspectorPanel,AssetsPanel,ScenePanel,Toolbar.
Selection, layout, assets
- Node selection is stable node IDs in
SelectionManager— never store PIXI/THREE objects in selection. - Asset Browser selection (
selectedAssetId, search,currentFolder) may stay UI-local; do not confuse it with scene selection. Import destination should follow the browser folder model (ASSETS_ROOT_FOLDER,listAssetsInFolder, …). - Docking (
DockLayout/ dockview) is layout-only; it must not become domain state.
React performance and lifecycle
- Prefer
useEditorState(selector)so panels re-render fromEditorrevision/selection, not copied scene graphs in React state. - Do not push per-frame drag positions through React state. Drag preview stays in
PixiSceneRenderer.previewNodePosition; undoable update is oneSetTransform2DCommandon pointer-up. - Every
editor.subscribe/selection.subscribe/assets.subscribe/setPointerHandlers/attachRenderermust be disposed in the same scope (effect cleanup). PixiSceneRenderer: construct inScenePaneleffect; on teardown callunbindTool,editor.detachRenderer, andrenderer.destroy(). PassAssetResolver(editor.assets), not ad-hoc FS paths.- Inspector drafts (string inputs) are UI-only until blur/Enter commits a command. Display size on sprites is a scene override, not live asset metadata.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 36 lines · 0 tokens per session scan A 1782a758c1e0
editor-ui is a cursor rule published in the GitHub repository andvolodko/html5-game-editor (5 stars, last pushed 8d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 669 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
cli-error-handling
CLI command error handling patterns.
prefer-direct-imports-over-module-mocks
Prefer extracting a testable core over vi.mock / vi.resetModules when unit tests need to reach production logic entangled with config, env, or singletons.
control-plane-descriptors
Control plane descriptor and instance implementation patterns.
family-instance-domain-actions
Family instance domain action implementation patterns.