Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/bobbylkchao/ai-phone-agent/projectgit clone --depth 1 https://github.com/bobbylkchao/ai-phone-agentWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/bobbylkchao/ai-phone-agent/project)<a href="https://agentmods.dev/rules/bobbylkchao/ai-phone-agent/project"><img src="https://agentmods.dev/badge/rules/bobbylkchao/ai-phone-agent/project.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00451 | $0.00451 |
| Opus 5 | $0.00226 | $0.00226 |
| Sonnet 5 | $0.00090 | $0.00090 |
| Haiku 4.5 | $0.00045 | $0.00045 |
Grade A, and why
project scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Project context
- Stack: Node.js, TypeScript, Express; OpenAI Realtime for phone audio.
- Channels:
src/service/twilio-phone/(Twilio Media Streams) andsrc/service/amazon-connect-phone/openai-sip-webhook/(Connect + OpenAI SIP webhook). - Shared code:
src/foundation/(OpenAI helpers, MCP, Twilio WS, Amazon Connect SDK).
Conventions
- Linting:
eslint.config.mjsextends Airbnb base + @kesills/eslint-config-airbnb-typescript (TypeScript layer) + eslint-config-prettier. Runnpm run lint; new code should pass. - TypeScript style (arrow functions, callbacks):
.cursor/rules/typescript-style.mdcapplies when you editsrc/**/*.ts(x). - Prefer small, task-focused changes; match existing patterns and naming.
- Imports:
@/*maps tosrc/*. Afternpm run build,tsc-aliasrewrites paths indist/. - New tools (Connect Realtime): add Zod +
parametersJsonSchema, export tool, register inopenai-sip-webhook/tools/index.ts. - SIP voice prompts:
openai-sip-webhook/agents/(Connect; not the Twilio stack). - Twilio Realtime agent + tools:
service/twilio-phone/agents/(front-desk +general-agents).
Security
- Do not commit or hardcode secrets;
.envis gitignored. Use GSM or env vars in deployment. - Do not log tokens, API keys, or unnecessary PII.
When unsure
- Read
doc/amazon-connect-openai-webhook.mdordoc/twilio-integration.mdbefore changing call flow. - Developer-facing agent instructions: root
AGENTS.md/CLAUDE.md(keep in sync).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 31 lines · 451 tokens per session scan A dc37681797a3
project is a cursor rule published in the GitHub repository bobbylkchao/ai-phone-agent (110 stars, last pushed 4mo ago), licensed MIT. It adds 451 tokens to every session, about $0.0023 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
react-components
Rules for writing React components in this project.
state-management
Rules for Redux state management.
server-patterns
Rules for server-side Express code.
prefer-assertions-over-defensive-checks
Prefer assertions over defensive checks when data is guaranteed to be valid.
as-contract-cast-smell
// ❌ WRONG — bypasses the family ContractSerializer seam const contract = JSON.parse(raw) as Contract; const contract = JSON.parse(raw) as Contract .
no-barrel-files
Avoid barrel files and unnecessary re-exports.