Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/bybren-llc/safe-agentic-workflow/02-pattern-discoverygit clone --depth 1 https://github.com/bybren-llc/safe-agentic-workflowWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00685 | $0.00685 |
| Opus 5 | $0.00342 | $0.00342 |
| Sonnet 5 | $0.00137 | $0.00137 |
| Haiku 4.5 | $0.00068 | $0.00068 |
Grade A, and why
02-pattern-discovery scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 85 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Pattern Discovery Protocol (MANDATORY)
Before writing ANY code, you MUST complete pattern discovery. This is not optional.
Step 0: Search Specs Directory (FIRST)
# Find similar implementations in specs
ls specs/*-spec.md
# Review SAFe user stories for related work
grep -r "As a.*I want to" specs/
# Check patterns referenced by past specs
cat specs/{{TICKET_PREFIX}}-XXX-similar-spec.md
Step 1: Search Pattern Library
Check patterns_library/ for an existing pattern that fits your use case.
Available categories:
| Category | Path | Contents |
|---|---|---|
| API | patterns_library/api/ |
User context, admin, webhooks, Zod |
| UI | patterns_library/ui/ |
Authenticated pages, forms, tables |
| Database | patterns_library/database/ |
RLS migration, Prisma transactions |
| Testing | patterns_library/testing/ |
API integration, E2E user flows |
| Security | patterns_library/security/ |
Input sanitization, rate limiting |
| CI | patterns_library/ci/ |
GitHub Actions, deployment pipeline |
| Config | patterns_library/config/ |
Environment config, logging |
See patterns_library/README.md for the full index of 18+ patterns.
Step 2: Search Codebase
# Search for similar functionality
grep -r "feature_name" app/ lib/ components/
# Find existing helpers
ls lib/
grep -r "helper_pattern" lib/
# Check for existing components
grep -r "ComponentName" components/
Step 3: Consult Documentation
Required reading before implementation:
CONTRIBUTING.md-- Workflow and git processdocs/database/DATA_DICTIONARY.md-- Database schema (SINGLE SOURCE OF TRUTH)docs/database/RLS_IMPLEMENTATION_GUIDE.md-- Row Level Security (MANDATORY for DB ops)docs/security/SECURITY_FIRST_ARCHITECTURE.md-- Security patterns
Step 4: Architectural Validation
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 85 lines · 685 tokens per session scan A 67d6af6d457a
02-pattern-discovery is a cursor rule published in the GitHub repository bybren-llc/safe-agentic-workflow (404 stars, last pushed 1mo ago), licensed MIT. It adds 685 tokens to every session, about $0.0034 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
pulse
PULSE Framework - Call pulsestatus on EVERY message.
react-composition-patterns
React composition patterns for scalable component architecture including compound components, context providers, state management, boolean prop alternatives, render props vs children, and React 19 API changes. Use when refactoring components with many boolean props, building component libraries, designing flexible…
react-advanced-patterns
Advanced React patterns for refs, stable callbacks, useEffectEvent, and application initialization. Use when dealing with event handler refs, stable callback references, subscription management, effect dependencies, or one-time app initialization.
infra-devops
Infrastructure, Cloud, Terraform, Docker & CI/CD Agent.
change-budget
AI Change Budget Enforcer — scope guard for every task.
context-delegate
Context Gatherer & External LLM Prompt Generator.