Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/desko77/cursor-1c-skills/code-review-checklistgit clone --depth 1 https://github.com/Desko77/cursor-1c-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/desko77/cursor-1c-skills/code-review-checklist)<a href="https://agentmods.dev/rules/desko77/cursor-1c-skills/code-review-checklist"><img src="https://agentmods.dev/badge/rules/desko77/cursor-1c-skills/code-review-checklist.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.01000 |
| Opus 5 | $0.00000 | $0.00500 |
| Sonnet 5 | $0.00000 | $0.00200 |
| Haiku 4.5 | $0.00000 | $0.00100 |
Grade A, and why
code-review-checklist scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 112 lines — stays where its author put it; the contents beside it link to each section on GitHub.
1C Code Review Checklist
Применяется: при ревью кода 1С (*.bsl, *.os).
Классификация находок
Critical - блокировать коммит
- Синтаксические ошибки
- SQL injection (конкатенация строк в запросе вместо параметров)
- Риск порчи данных
- Пробои безопасности (hardcoded пароли, обход RLS)
- Операции >10с без оптимизации
- Нарушения БСП с breaking changes
High - исправить до merge
- Логические ошибки
- Отсутствие обработки ошибок (пустой Исключение)
- N+1 запросы (запрос в цикле)
- Отсутствие индексов на фильтруемых полях
- Недостаточный контроль доступа (нет проверки прав)
- Дублирование кода >50 строк
- Цикломатическая сложность >15 (количество независимых путей выполнения в функции)
Medium - исправить в спринте
- Нарушение конвенций именования
- Отсутствие документации экспортных функций
- Субоптимальные алгоритмы
- Code smells (God-модуль, длинные функции >200 строк)
- Незначительные отклонения от БСП
- Проблемы с тестируемостью
Low - технический долг
- Форматирование
- Стиль комментариев
- Именование переменных
- Мелкие оптимизации
- Возможности для рефакторинга
Шкала уверенности
| Баллы | Уровень | Описание |
|---|---|---|
| 0-25 | Низкая | Возможно false positive |
| 26-50 | Средняя | Стоит обсудить |
| 51-75 | Высокая | Вероятная реальная проблема |
| 76-100 | Очень высокая | Подтвержденная проблема с доказательствами |
Репортить: при ревью кода - только >=75, при ревью архитектуры - >=50.
Фильтр уверенности - цель: отсечь ложные срабатывания:
- Уверенность подтверждается конкретикой: сценарий сбоя (какие данные/действия ломают код) и подтверждение кодом (файл:строка). Без них оценка не выше средней
- Находки ниже порога - отбросить или вынести отдельным блоком "Гипотезы (не подтверждены)", не смешивая с основными
- В отчете находки группировать по severity (Critical -> Low)
Security-паттерны 1С
Уязвимости - искать
- SQL injection: конкатенация строк в
Запрос.Текствместо&Параметр - XSS: неэкранированный вывод в формах
- Обход RLS: отсутствие проверок
ПравоДоступа()/РольДоступна() - Hardcoded секреты: пароли, токены, ключи в коде
- Небезопасная обработка данных: внешние данные без валидации
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 112 lines · 0 tokens per session scan A a783d2173e08
code-review-checklist is a cursor rule published in the GitHub repository Desko77/cursor-1c-skills (55 stars, last pushed 2d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 1,000 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
cli-error-handling
CLI command error handling patterns.
prefer-direct-imports-over-module-mocks
Prefer extracting a testable core over vi.mock / vi.resetModules when unit tests need to reach production logic entangled with config, env, or singletons.
control-plane-descriptors
Control plane descriptor and instance implementation patterns.
family-instance-domain-actions
Family instance domain action implementation patterns.