Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/datacovey/nornweave/maingit clone --depth 1 https://github.com/DataCovey/nornweaveWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.02102 | $0.02102 |
| Opus 5 | $0.01051 | $0.01051 |
| Sonnet 5 | $0.00420 | $0.00420 |
| Haiku 4.5 | $0.00210 | $0.00210 |
Grade A, and why
main scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 186 lines — stays where its author put it; the contents beside it link to each section on GitHub.
NornWeave - Cursor Rules
NornWeave is an open-source, self-hosted Inbox-as-a-Service API for AI Agents. It provides a stateful email layer (Inboxes, Threads, History) and an intelligent layer (Markdown parsing, Semantic Search) for LLMs via REST or MCP.
Repository Structure
nornweave/
├── src/nornweave/ # Main Python package
│ ├── adapters/ # Email provider adapters (Mailgun, SES, SendGrid, Resend, SMTP/IMAP, demo)
│ ├── core/ # Core utilities (config, exceptions, interfaces)
│ ├── models/ # Pydantic/SQLAlchemy models (Event, Inbox, Message, Thread)
│ ├── huginn/ # MCP Resources (read operations for AI agents)
│ ├── muninn/ # MCP Tools (write operations for AI agents)
│ ├── skuld/ # Outbound layer (rate limiting, scheduling, sending, webhooks)
│ ├── urdr/ # Storage layer (database adapters, migrations)
│ │ ├── adapters/ # PostgreSQL and SQLite adapters
│ │ └── migrations/ # Alembic migration scripts
│ ├── verdandi/ # Ingestion (webhook + IMAP, parsing, threading, attachments, LLM summarization)
│ └── yggdrasil/ # FastAPI gateway
│ ├── middleware/ # Auth and logging middleware
│ └── routes/ # API routes (v1/, webhooks/, v1/demo when in demo mode)
├── clients/ # SDK clients for NornWeave API
│ └── python/ # Python client library (nornweave-client)
├── packages/ # External platform integrations
│ └── n8n-nodes-nornweave/ # n8n community node for NornWeave
├── tests/ # Test suite (fixtures/, integration/, unit/, e2e/)
├── web/ # Hugo documentation website
│ └── content/docs/ # Documentation content
├── scripts/ # Utility scripts (DB init, migrations, dev setup)
├── skills/ # Distributable AI assistant skills for NornWeave
├── openspec/ # OpenSpec artifacts (specs, changes, context for implementations)
│ ├── specs/ # Feature specifications and design documents
│ └── changes/archive/ # Completed and archived changes
└── .github/ # CI/CD workflows
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 186 lines · 2,102 tokens per session scan A ad5ae8f05b6d
main is a cursor rule published in the GitHub repository DataCovey/nornweave (27 stars, last pushed 5d ago), licensed Apache-2.0. It adds 2,102 tokens to every session, about $0.0105 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
070-workflow-preferences
MAINTAIN development discipline WHEN implementing changes TO preserve codebase integrity.
cx-devassist-kics
Scan and remediate IaC (Infrastructure-as-Code) misconfigurations in Dockerfile, Terraform, Kubernetes YAML, and other IaC files using Checkmarx KICS and the Checkmarx MCP imageRemediation tool.
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
cli-error-handling
CLI command error handling patterns.
prefer-direct-imports-over-module-mocks
Prefer extracting a testable core over vi.mock / vi.resetModules when unit tests need to reach production logic entangled with config, env, or singletons.