researchforge-baseline

researchforge-baseline is a cursor rule for coding agents from forger-labs-hq/researchforge. It costs 0 tokens per session (536 once invoked), scanned A, original, Apache-2.0.

A contract-and-baseline rule for ResearchForge, a tool for controlled repository experiments. It defines how changes will be measured, which files may change, and which files are protected, then runs the original benchmark.

In plain words
What is it for?
Defining metrics and constraints, approving the experiment setup, measuring the baseline, and controlling editable and protected repository paths.
Why use it?
It establishes a fixed comparison point and prevents experiments from changing the rules used to judge them.

Cursor rule

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/forger-labs-hq/researchforge/researchforge-baseline
Clone the repo
git clone --depth 1 https://github.com/forger-labs-hq/researchforge

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for researchforge-baseline

README.md
[![agentmods](https://agentmods.dev/badge/rules/forger-labs-hq/researchforge/researchforge-baseline.svg)](https://agentmods.dev/rules/forger-labs-hq/researchforge/researchforge-baseline)
Your own site
<a href="https://agentmods.dev/rules/forger-labs-hq/researchforge/researchforge-baseline"><img src="https://agentmods.dev/badge/rules/forger-labs-hq/researchforge/researchforge-baseline.svg" alt="Measured on agentmods" height="20"></a>
Per session 0 Nothing until a file matches its globs; then the whole rule loads.
When invoked 536 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00000 $0.00536
Opus 5 $0.00000 $0.00268
Sonnet 5 $0.00000 $0.00107
Haiku 4.5 $0.00000 $0.00054

Measured 5d ago against content hash 720d4163d055, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-05, from the pricing page.

Security

Grade A, and why

researchforge-baseline scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

src/researchforge/cursor/rules/researchforge-baseline.mdc · 67 lines

How it starts

The opening of the file, as written. The whole thing — 67 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Contract and baseline

The contract (researchforge.yaml at the repository root) freezes the evaluation: primary metric + direction, hard constraints, editable vs protected paths, commands, resource limits, network mode, shipping flags. Approval hashes it; later edits are detected as drift and refused until re-approved. The contract is the boundary — experiments can only change editable_paths and are judged only by the contracted benchmark.

1. Draft the contract

researchforge contract generate --json

Then edit researchforge.yaml with the user — these are their choices, not yours: the benchmark command (execution.full_command) must print or write a machine-readable result (execution.result_file), the primary metric must match a key in that result, and permissions.editable_paths / protected_paths decide what experiments may touch. Benchmarks and evaluation code belong in protected_paths.

2. Validate and approve

researchforge contract validate --json

Fix any of the semantic errors it reports (they are field-level and actionable). Then show the user a summary of what they are approving — metric, constraints, commands, limits, paths — and ask them to run:

researchforge contract approve

The approval is a typed confirmation. Only run it with --yes yourself if the user has explicitly said in this conversation to approve this contract.

3. Run the baseline

researchforge baseline run --json
researchforge baseline show --json

The baseline runs in an isolated detached worktree; the user's checkout is never touched. Report the recorded baseline metrics from the JSON. All future experiments are compared against this frozen measurement.

Next: the researchforge-plan rule designs experiments against a hypothesis.

Rules

  • The Python engine is the boundary: never work around a validation error, a protected path, or an approval gate — fix the artifact or ask the user.
  • Approvals belong to the user: never pass --yes or type a confirmation unless the user explicitly approved that step in this conversation.
  • Ground every summary in stored data: quote only numbers returned by --json output or files under .researchforge/ — never invent metrics.

Read the full file on GitHub · 67 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 67 lines · 0 tokens per session scan A 720d4163d055

Subscribe to this mod's changes

researchforge-baseline is a cursor rule published in the GitHub repository forger-labs-hq/researchforge (7 stars, last pushed 3d ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 536 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.