Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/d-padmanabhan/agent-engineering-handbook/020-agent-auditgit clone --depth 1 https://github.com/d-padmanabhan/agent-engineering-handbookWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/d-padmanabhan/agent-engineering-handbook/020-agent-audit)<a href="https://agentmods.dev/rules/d-padmanabhan/agent-engineering-handbook/020-agent-audit"><img src="https://agentmods.dev/badge/rules/d-padmanabhan/agent-engineering-handbook/020-agent-audit.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.02491 | $0.02491 |
| Opus 5 | $0.01246 | $0.01246 |
| Sonnet 5 | $0.00498 | $0.00498 |
| Haiku 4.5 | $0.00249 | $0.00249 |
Grade A, and why
020-agent-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 270 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Agent Workflow & Audit Requirements
These rules apply to AI agents operating in this workspace. They are designed to make work reversible, verifiable, and auditable.
1) Remote Mutations: Explicit Authorization; Read-Only Operations Allowed
Read-only operations do not require checkpoints or extra approval. Examples include file reads/searches, API GET requests, listing/status/describe commands, plans/diffs, CLI --help, and read-only MCP/tool calls.
Remote mutations require user authorization. A user's direct request to perform a specific mutation counts as authorization; do not ask for redundant approval unless the operation is destructive, irreversible, security-sensitive, or materially broader than the request.
For high-risk remote mutations, record:
- the exact authorization (who/when/what),
- the exact commands executed,
- the results and exit codes, in the audit report.
This includes (non-exhaustive):
- Git remote:
git push, tag pushes, changing remotes, or any operation that writes toorigin/upstream. Plaingit fetchis read-only with respect to the remote. - GitHub remote: creating/merging PRs, pushing branches, forking repos, editing issues/PRs via write APIs.
- Cloud / infra / data planes:
terraform apply,kubectl apply,helm upgrade,aws cloudformation deploy, database migrations against non-local DBs, or any command that changes remote resources.
Commits are local-only and allowed only after explicit user authorization (see 130-git.mdc (${HANDBOOK_ROOT}/rules/130-git.mdc)).
When a push is authorized, fetch first and inspect branch divergence. Rebase or merge only when needed and permitted by repository policy; do not blindly run git pull --rebase against a dirty or shared branch. Use git push -u origin HEAD for a brand-new branch. See 130-git.mdc (${HANDBOOK_ROOT}/rules/130-git.mdc#branches-history-and-remote-writes). Never use --force or --force-with-lease unless the user explicitly authorizes that specific update.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 270 lines · 2,491 tokens per session scan A 63695767b8ec
020-agent-audit is a cursor rule published in the GitHub repository d-padmanabhan/agent-engineering-handbook (16 stars, last pushed 6d ago), licensed MIT. It adds 2,491 tokens to every session, about $0.0125 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
ponytail
Ponytail, lazy senior dev mode. Always pick the simplest solution that works.
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
cli-error-handling
CLI command error handling patterns.
control-plane-descriptors
Control plane descriptor and instance implementation patterns.
family-instance-domain-actions
Family instance domain action implementation patterns.