archgate-governance

A set of project rules that enforces architecture decision records, or ADRs: written decisions describing how a codebase should be designed. It requires checking relevant decisions before coding and validating compliance afterward.

In plain words
What is it for?
Use it to find applicable ADR guidance for changed files and run compliance checks before considering work complete. Violations must be fixed.
Why use it?
It prevents changes from quietly conflicting with decisions the project has already made about its architecture.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/archgate/cli/archgate-governance
Clone the repo
git clone --depth 1 https://github.com/archgate/cli

Made for: Cursor.

Per session 195 This file is loaded in full into every session.
When invoked 195 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00195 $0.00195
Opus 5 $0.00097 $0.00097
Sonnet 5 $0.00039 $0.00039
Haiku 4.5 $0.00019 $0.00019

Measured yesterday against content hash d7304eddf493, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

archgate-governance scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/archgate-governance.mdc · 30 lines

What it actually says

Archgate Governance

This project uses Archgate to enforce Architecture Decision Records (ADRs).

Before writing code

  • Use the review_context MCP tool to get applicable ADR briefings for changed files
  • Review the Decision and Do's/Don'ts sections of each applicable ADR

After writing code

  • Run the check MCP tool to validate compliance with all ADR rules
  • Fix any violations before considering work complete

ADR commands

  • list_adrs — List all active ADRs with metadata
  • check — Run automated compliance checks (use staged: true for pre-commit)
  • review_context — Get changed files grouped by domain with ADR briefings

Key principle

Architectural decisions are enforced, not suggested. If check reports violations, they must be fixed.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 30 lines · 195 tokens per session scan A d7304eddf493

Subscribe to this mod's changes

archgate-governance is a cursor rule published in the GitHub repository archgate/cli (64 stars, last pushed yesterday), licensed Apache-2.0. It adds 195 tokens to every session, about $0.0010 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other cursor rules, from other repositories

code-convention

Code convention analysis and enforcement — ESLint integration, naming conventions, type safety checks, and quality scoring with remediation steps. Applied when analysing code style and conventions.

adonai-labs/agent-runway · 0 tokens

database-design

Database design guidelines — relational normalisation, indexing, constraints, NoSQL patterns, query optimisation, migrations, security, and backup strategies. Applied when working with database schemas and queries.

adonai-labs/agent-runway · 0 tokens

devops-practices

DevOps practices — CI/CD pipeline design, Docker containerisation, Kubernetes orchestration, Infrastructure as Code, monitoring, logging, and security. Applied when working with deployment and infrastructure files.

adonai-labs/agent-runway · 0 tokens

performance

Performance optimisation guidelines — bundle optimisation, memory management, rendering, network, Electron-specific, and monitoring strategies. Applied when working on performance-sensitive code.

adonai-labs/agent-runway · 0 tokens

security

Security guidelines — OWASP Top 10 mitigations, authentication, authorisation, encryption, input validation, and secure coding practices. Applied when writing or reviewing code that handles input, identity, secrets, or sensitive data.

adonai-labs/agent-runway · 0 tokens

testing

Testing strategies and quality assurance — testing pyramid, unit/integration/E2E testing, TDD/BDD, test automation, and quality metrics. Applied when writing or reviewing tests.

adonai-labs/agent-runway · 0 tokens