Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/benchflow-ai/agents/commitsgit clone --depth 1 https://github.com/benchflow-ai/agentsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00425 | $0.00425 |
| Opus 5 | $0.00212 | $0.00212 |
| Sonnet 5 | $0.00085 | $0.00085 |
| Haiku 4.5 | $0.00042 | $0.00042 |
Grade A, and why
commits scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Use the following format for commit messages:
ci: descriptionfor all testing related changes, and changes to github workflows etc.dev: descriptionfor development related changes, including updates to the cursor or claude rulesfix(component): descriptionfor bug fixesfeat(component): descriptionfor new featuresenh(component): descriptionfor enhancementsdocs: descriptionfor documentationref(component): descriptionfor refactoringchore: descriptionfor maintenance tasks (pre-commit hooks, imports, etc.)
Generally, the description should focus on the intent of the changes, not the implementation details.
Style notes
Do NOT add "Co-authored-by: Cursor" lines to the commit message or to the trailer.
Reviewing
While preparing the commit message, flag critical issues that should be addressed before committing. Do not flag style issues or minor changes.
Flag the following:
- Anything that might raise an unhandled exception in an unintentional manner
- Anything that looks logically wrong or inconsistent
- Breaking changes to protocols/interfaces without corresponding updates to implementations
Flag the following style issue as minor:
- Imports not at top of file
Components
Use these component names in parentheses for fix, feat, enh, and ref commits:
models- Changes to model interfaces (litellm, anthropic, openai, portkey, openrouter)agents- Changes to agent classes (default, interactive, multimodal)env- Changes to environments (docker, local, singularity, bubblewrap, swerex)config- Changes to configuration files or config handlingrun- Changes to run scripts (mini, hello_world)benchmarks- Changes to benchmark runners (swebench, inspector)cli- Changes to CLI argument handlingdeps- Dependency updates
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 48 lines · 425 tokens per session scan A 615831a4c2d1
commits is a cursor rule published in the GitHub repository benchflow-ai/agents (10 stars, last pushed 2d ago), licensed Apache-2.0. It adds 425 tokens to every session, about $0.0021 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
engine-internals
Coding Agent engine implementation details (Cursor + Claude Code) — reference when modifying engine.ts or debugging Agent behavior.
testing-conventions
Testing conventions — must reference when modifying src/ code or tests.
architecture-constraints
GolemBot architecture hard constraints — must check before modifying any src/ code.
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
typescript
Changes to these high-fan-out internals can affect every message, delta, element, or rerun. Keep work in them minimal, and benchmark changes with representative stress-test apps.