Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/forgesworn/402-mcp/cursorrulesgit clone --depth 1 https://github.com/forgesworn/402-mcpWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00554 | $0.00554 |
| Opus 5 | $0.00277 | $0.00277 |
| Sonnet 5 | $0.00111 | $0.00111 |
| Haiku 4.5 | $0.00055 | $0.00055 |
Grade A, and why
cursorrules scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 37 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Cursor Rules — 402-mcp
L402 + x402 client MCP server. AI agents discover, pay for, and consume any payment-gated API autonomously.
Commands
npm run build— compile TypeScript to build/npm test— run all tests (vitest)npm run typecheck— type-check without emitting
Conventions
- British English — colour, initialise, behaviour, licence
- ESM-only —
"type": "module", target ES2022, module Node16 - Tool pattern — each tool file exports a
handle*function (testable with injected deps) and aregister*Toolfunction (MCP wiring) - Tests live in
tests/, not co-located with source. Each handler'shandle*function is tested directly with mock deps usingvi.fn() - Commit messages —
type: descriptionformat (feat:, fix:, docs:, chore:, refactor:). No Co-Authored-By lines.
Key Patterns
- Atomic spend tracking — always use
spendTracker.tryRecord(sats, limit), never splitwouldExceed()+record()(TOCTOU race) - Preimage validation — validate hex format before storing. Preimages are sent raw in
Authorization: L402 {macaroon}:{preimage}headers - SSRF guard — all outbound HTTP goes through the SSRF guard. Money-mutating POSTs pass
{ retries: 0 }to disable retry - cashu-ts v2 —
getDecodedToken()returns{ mint, proofs, unit }at top level. There is NO.tokenarray - nostr-tools NIP-44 — use
getConversationKey(privkey, pubkey)thenencrypt(plaintext, conversationKey). Do NOT use NIP-04
Structure
src/index.ts— entry point: config, wiring, transport setupsrc/config.ts— environment variable parsing with validationsrc/tools/— one file per MCP tool (handler + registration)src/wallet/— payment implementations (NWC, Cashu, human-in-the-loop)src/store/— persistent JSON stores (credentials, Cashu tokens)src/l402/— L402 protocol utilities (parse, detect, cache, bolt11)src/fetch/— resilient fetch: SSRF guard, timeout, retry, transport selectiontests/— mirrors src/ structure
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 37 lines · 554 tokens per session scan A dbb2b97136d3
cursorrules is a cursor rule published in the GitHub repository forgesworn/402-mcp (0 stars, last pushed 10d ago), licensed MIT. It adds 554 tokens to every session, about $0.0028 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
e2e-script
BCH E2E Script Development Rules.
agent-files
This rule applies when editing .claude/, .cursor/, .codex/, or .github/copilot-instructions.md.
bun
Rules for projects using Bun runtime instead of Node.js.
3rd-library
XRP Third-Party Library Rules.
pkg-or-internal
BTC Package Placement Rules.
documentation-language
All documentation files (.md, .mdc) in this project must be written in English.