first-look-analysis

A set of rules for producing a first-look report on an unfamiliar software project. The report explains the project’s purpose, structure, architecture, components, logic, dependencies, and intended use.

In plain words
What is it for?
Use it when first examining a repository to document how the code is organized, how its parts interact, and which libraries and algorithms it uses.
Why use it?
It gives an agent a thorough baseline understanding before making changes or answering project-specific questions.

Cursor rule

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/emissium/cursor-rules/first-look-analysis
Clone the repo
git clone --depth 1 https://github.com/emissium/cursor-rules
Per session 12 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 419 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00012 $0.00419
Opus 5 $0.00006 $0.00210
Sonnet 5 $0.00002 $0.00084
Haiku 4.5 $0.00001 $0.00042

Measured 2d ago against content hash 50f272820d56, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

first-look-analysis scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

behaviour/first-look-analysis.mdc · 49 lines

How it starts

The opening of the file, as written. The whole thing — 49 lines — stays where its author put it; the contents beside it link to each section on GitHub.

This is your first time seeing this repository. Perform a deep-drive into the codebase, the logic, the architecture, and the details of the project. Write a detailed report on your findings. Make sure to build up a robust context of the project, its purpose, and how it works.

First Look Report

Overview

Provide a brief summary of the project, its main features, and its intended use case.

Architecture

Describe the overall architecture of the project. Include details about the main components, how they interact, and any architectural patterns used (e.g., MVC, microservices).

Code Structure

Outline the structure of the codebase. Discuss the organization of files and directories, naming conventions, and any notable patterns in the code organization.

Key Components

Identify and describe the key components of the project. Discuss their roles, how they interact with each other, and any dependencies they have.

Logic and Algorithms

Discuss the main logic and algorithms used in the project. Highlight any complex algorithms, data structures, or design patterns that are employed.

Dependencies

List the main dependencies of the project. Include libraries, frameworks, and any external services that the project relies on. Discuss how these dependencies are managed (e.g., package managers, version control).

Testing

Describe the testing strategy used in the project. Include details about unit tests, integration tests, and any testing frameworks employed. Discuss the coverage of tests and how they contribute to the reliability of the codebase.

Documentation

Discuss the documentation provided with the project. Include details about inline comments, README files, and any external documentation resources. Evaluate the clarity and completeness of the documentation.

Areas for Improvement

Identify any areas where the project could be improved. This could include code quality, performance optimizations, better documentation, or additional features.

Read the full file on GitHub · 49 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 49 lines · 12 tokens per session scan A 50f272820d56

Subscribe to this mod's changes

first-look-analysis is a cursor rule published in the GitHub repository emissium/cursor-rules (7 stars, last pushed 9mo ago), licensed MIT. It adds 12 tokens to every session and 419 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.