cfg-api-v3-core

cfg-api-v3-core is a cursor rule for Cursor from centrifuge/api-v3. It costs 536 tokens per session, scanned A, original, MIT.

Project rules for the cfg-api-v3 codebase, including where handlers and services belong and how database access should be organized. They require reading the root CLAUDE.md file before substantial work.

In plain words
What is it for?
Use them before implementing or reviewing features in cfg-api-v3, especially changes involving handlers, persistence, multi-version events, batching, or SQL parameters.
Why use it?
They give coding agents the repository's required architecture and help prevent changes that bypass its service, logging, database, or versioning conventions.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/centrifuge/api-v3/cfg-api-v3-core
Clone the repo
git clone --depth 1 https://github.com/centrifuge/api-v3

Made for: Cursor.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for cfg-api-v3-core

README.md
[![agentmods](https://agentmods.dev/badge/rules/centrifuge/api-v3/cfg-api-v3-core.svg)](https://agentmods.dev/rules/centrifuge/api-v3/cfg-api-v3-core)
Your own site
<a href="https://agentmods.dev/rules/centrifuge/api-v3/cfg-api-v3-core"><img src="https://agentmods.dev/badge/rules/centrifuge/api-v3/cfg-api-v3-core.svg" alt="Measured on agentmods" height="20"></a>
Per session 536 This file is loaded in full into every session.
When invoked 536 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00536 $0.00536
Opus 5 $0.00268 $0.00268
Sonnet 5 $0.00107 $0.00107
Haiku 4.5 $0.00054 $0.00054

Measured 4d ago against content hash b301f697df32, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

cfg-api-v3-core scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/cfg-api-v3-core.mdc · 22 lines

What it actually says

cfg-api-v3 — core context

Before substantive work, read CLAUDE.md at the repo root. It is the source of truth for architecture and conventions.

Non-negotiables

  • Never edit generated/ — regenerate via pnpm update-registry / pnpm codegen and upstream inputs.
  • Handlers live only in src/handlers/. No context.db.*, Drizzle, or raw SQL in handlers; use src/services/ (exception: call snapshotter for snapshot tables, not ad-hoc inserts).
  • Services own persistence: extend abstract Service<typeof Table> from src/services/Service.ts with static readonly entityTable / entityName; use serviceLog / serviceError from src/helpers/logger.ts on meaningful methods.
  • Multi-version contracts: register contract events with multiMapper from src/helpers/multiMapper.ts when the same logical event exists across HubV3, HubV3_1, etc.
  • Batch when possible: insertMany / saveMany on services to reduce DB round-trips.
  • Raw SQL binds: Ponder's context.db.sql sends JS values as text params. In COALESCE / col = $n, use bindPg* from src/helpers/sqlSafety.ts (bindPgTimestamp, bindPgInteger, bindPgBigint, bindPgHex, bindPgHexBytes32) — never ${date}, ${n}, or ${hex} directly. Enforced by test/unit/parity/raw-sql-bindings.test.ts.

Before finishing a task: run pnpm typecheck and pnpm lint from the repo root when you changed TypeScript. After ponder.schema.ts or Ponder config changes, run pnpm codegen.

Related rules: cfg-api-v3-handlers.mdc, cfg-api-v3-services.mdc, cfg-api-v3-ponder.mdc.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 22 lines · 536 tokens per session scan A b301f697df32

Subscribe to this mod's changes

cfg-api-v3-core is a cursor rule published in the GitHub repository centrifuge/api-v3 (5 stars, last pushed 7d ago), licensed MIT. It adds 536 tokens to every session, about $0.0027 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.