Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/centrifuge/api-v3/cfg-api-v3-coregit clone --depth 1 https://github.com/centrifuge/api-v3Wrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/centrifuge/api-v3/cfg-api-v3-core)<a href="https://agentmods.dev/rules/centrifuge/api-v3/cfg-api-v3-core"><img src="https://agentmods.dev/badge/rules/centrifuge/api-v3/cfg-api-v3-core.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00536 | $0.00536 |
| Opus 5 | $0.00268 | $0.00268 |
| Sonnet 5 | $0.00107 | $0.00107 |
| Haiku 4.5 | $0.00054 | $0.00054 |
Grade A, and why
cfg-api-v3-core scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
cfg-api-v3 — core context
Before substantive work, read CLAUDE.md at the repo root. It is the source of truth for architecture and conventions.
Non-negotiables
- Never edit
generated/— regenerate viapnpm update-registry/pnpm codegenand upstream inputs. - Handlers live only in
src/handlers/. Nocontext.db.*, Drizzle, or raw SQL in handlers; usesrc/services/(exception: callsnapshotterfor snapshot tables, not ad-hoc inserts). - Services own persistence: extend abstract
Service<typeof Table>fromsrc/services/Service.tswithstatic readonly entityTable/entityName; useserviceLog/serviceErrorfromsrc/helpers/logger.tson meaningful methods. - Multi-version contracts: register contract events with
multiMapperfromsrc/helpers/multiMapper.tswhen the same logical event exists acrossHubV3,HubV3_1, etc. - Batch when possible:
insertMany/saveManyon services to reduce DB round-trips. - Raw SQL binds: Ponder's
context.db.sqlsends JS values as text params. InCOALESCE/col = $n, usebindPg*fromsrc/helpers/sqlSafety.ts(bindPgTimestamp,bindPgInteger,bindPgBigint,bindPgHex,bindPgHexBytes32) — never${date},${n}, or${hex}directly. Enforced bytest/unit/parity/raw-sql-bindings.test.ts.
Before finishing a task: run pnpm typecheck and pnpm lint from the repo root when you changed TypeScript. After ponder.schema.ts or Ponder config changes, run pnpm codegen.
Related rules: cfg-api-v3-handlers.mdc, cfg-api-v3-services.mdc, cfg-api-v3-ponder.mdc.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 22 lines · 536 tokens per session scan A b301f697df32
cfg-api-v3-core is a cursor rule published in the GitHub repository centrifuge/api-v3 (5 stars, last pushed 7d ago), licensed MIT. It adds 536 tokens to every session, about $0.0027 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
cli-error-handling
CLI command error handling patterns.
family-instance-domain-actions
Family instance domain action implementation patterns.
prefer-assertions-over-defensive-checks
Prefer assertions over defensive checks when data is guaranteed to be valid.
prefer-direct-imports-over-module-mocks
Prefer extracting a testable core over vi.mock / vi.resetModules when unit tests need to reach production logic entangled with config, env, or singletons.