pull-request

PR, pull request, commit, push, git push, gh pr create, open PR, create PR, reviewer, Asana task, merge, GitHub.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/duckduckgo/apple-browsers/pull-request
Clone the repo
git clone --depth 1 https://github.com/duckduckgo/apple-browsers

Made for: Cursor.

Per session 32 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 3,373 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin unknown No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00032 $0.03373
Opus 5 $0.00016 $0.01687
Sonnet 5 $0.00006 $0.00675
Haiku 4.5 $0.00003 $0.00337

Measured today against content hash 197fcad61024, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

pull-request scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/pull-request.mdc · 345 lines

How it starts

The opening of the file, as written. The whole thing — 345 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Pull Request Guidelines & Workflow

🚨 CRITICAL: Required Information and Approval Before Creating PR

MANDATORY: Before creating any PR, you MUST:

Step 1: Gather Required Information

1. Task/Issue URL

Ask: "What is the Asana task URL for this PR?"

  • NEVER proceed with placeholder text like [TASK_ID] or [INSERT_URL]
  • NEVER assume you can skip this step
  • ONLY proceed if user explicitly says to omit it or provides the URL

2. PR Reviewer Assignment (CRITICAL for Asana Integration)

Ask: "Who should review this PR?"

  • Ask if they want to:
    • Assign a specific reviewer (get their GitHub username for --reviewer flag)
    • Use auto-assignment (--reviewer Apple-dev team)
    • Handle it themselves after PR creation
  • NEVER proceed without understanding the reviewer assignment strategy
  • ONLY proceed if user explicitly provides the information or strategy

WHY THIS MATTERS:

  • GitHub Action only creates Asana subtask when reviewer is assigned via GitHub's reviewer mechanism
  • Using --reviewer flag triggers the review_requested event that runs the Asana integration
  • Without reviewer assignment, no Asana subtask is created automatically

3. Tech Design URL (For Significant Changes)

  • Default to "N/A" for minor changes and bug fixes
  • ASK for significant changes (new features, architectural changes)
  • Can be omitted if user doesn't explicitly provide one - use "N/A"
  • Unlike Task/Issue URL, this is optional and can default to "N/A"

4. Exception: User Explicitly Opts Out

The ONLY acceptable reason to skip asking for Task URL and Reviewer is if the user explicitly states:

  • "Skip Asana task" or "No Asana task"
  • "I'll assign reviewer myself" or "Use auto-assignment"

Failure to ask for Task URL and Reviewer = violation of PR workflow.


Step 2: Get User Approval Before Creating PR

MANDATORY: After gathering all information, you MUST:

  1. Present the complete PR body text to the user for review and approval
  2. Include the reviewer name that will be assigned
  3. Show the exact text that will be used in the PR body (not the command)
  4. Wait for explicit approval before proceeding
  5. ONLY after approval: Execute the gh pr create command

Read the full file on GitHub · 345 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. today First seen · 345 lines · 32 tokens per session scan A 197fcad61024

Subscribe to this mod's changes

pull-request is a cursor rule published in the GitHub repository duckduckgo/apple-browsers (252 stars, last pushed today), licensed Apache-2.0. It adds 32 tokens to every session and 3,373 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-01.