Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/archcore-ai/plugin/archcore-filesgit clone --depth 1 https://github.com/archcore-ai/pluginWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00150 |
| Opus 5 | $0.00000 | $0.00075 |
| Sonnet 5 | $0.00000 | $0.00030 |
| Haiku 4.5 | $0.00000 | $0.00015 |
Grade A, and why
archcore-files scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
.archcore/ File Operations
You are working with files in the .archcore/ directory. These are managed documents in the Archcore knowledge base.
Do not use Write or Edit tools on .archcore/*.md files. Use the Archcore MCP tools instead:
- To create:
create_document(type, filename, ...) - To modify:
update_document(path, ...) - To delete:
remove_document(path) - To link:
add_relation(source, target, type)
Direct file writes bypass validation, templates, and the sync manifest.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 19 lines · 0 tokens per session scan A a94b2da34edb
archcore-files is a cursor rule published in the GitHub repository archcore-ai/plugin (53 stars, last pushed 15d ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 150 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
pn-aesthetics-baseline
Non-generic UI baseline for user-facing surfaces; aligns with .pncore-design.md and pn-core aesthetics reference when MCP is available.
pn-build-gate
For build/design/scaffold requests, load pn-build or pn-design; discovery and skeptic mandatory. For fix/tweak, use skills directly.
pn-godot
Godot 4.x coding conventions: GDScript typing, signal patterns, scene composition, shader style, naming, Resource patterns, multiplayer RPC safety, GDExtension registration. Use when editing .gd, .tscn, .tres, .gdshader, or project.godot files.
pn-mcp-proactive
When MCP is available, use pn-core tools proactively when tasks match pn skills or agents; use Octocode for code research when available.
pn-nextjs
Next.js best practices. Data loading, server/client boundaries, streaming, mutations, and performance. For Next app/ or pages/, pn-react also applies (core React patterns); content is complementary.
pn-react
Core React conventions: function components, hooks, semantic HTML, naming, styling, performance, and component architecture. Use when editing .tsx or .jsx files. For Next.js app/ or pages/, pn-nextjs also applies.