Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/freshworks-developers/fw-dev-tools/confusiongit clone --depth 1 https://github.com/freshworks-developers/fw-dev-toolsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.01345 |
| Opus 5 | $0.00000 | $0.00673 |
| Sonnet 5 | $0.00000 | $0.00269 |
| Haiku 4.5 | $0.00000 | $0.00135 |
Grade A, and why
confusion scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 173 lines — stays where its author put it; the contents beside it link to each section on GitHub.
App Development Disambiguation Guide
When to use: Prompt is vague, incomplete, or could be interpreted multiple ways.
Top 5 Common Ambiguities
1. OAuth vs API Token?
Ambiguous patterns:
- "integrate with [service]"
- "connect to [API]"
- No mention of authentication
Decision:
Does service support OAuth?
├─ YES → Is it user-facing (users have accounts)?
│ ├─ YES → Use OAuth (GitHub, Jira, Salesforce, Google)
│ └─ NO → Use API Token (simpler for admin services)
└─ NO → Use API Token (Zapier webhooks, custom APIs)
Implementation:
- OAuth:
config/oauth_config.jsonwithintegrationswrapper - API Token:
config/iparams.jsonwith"secure": true
2. Automatic vs Manual Trigger?
Ambiguous patterns:
- "logs data to [service]"
- "sends information to [platform]"
- "creates [item] from ticket"
Decision:
What's the purpose?
├─ LOGGING/ARCHIVING → Automatic (serverless events)
│ Examples: "logs tickets", "archives data"
│ Why: Must happen without user action
│
├─ NOTIFICATION/ALERT → Automatic (serverless events)
│ Examples: "sends alerts", "notifies team"
│ Why: Must be timely
│
├─ ACTION/CREATION → Manual (button in UI)
│ Examples: "creates issue", "generates card"
│ Why: User decides when to create
│
└─ UNCLEAR → Ask user or default to Manual (safer)
Implementation:
- Automatic: Serverless with
onTicketCreate,onTicketUpdateevents - Manual: Hybrid with button in sidebar + SMI function
3. Frontend vs Serverless?
Ambiguous patterns:
- "app that syncs data"
- "app that sends webhooks"
- No mention of UI
Decision:
Does user need to SEE or INTERACT with the app?
├─ YES → Frontend or Hybrid
│ Examples: View status, trigger actions, configure settings
│
└─ NO → Serverless only
Examples: Pure automation, background sync, webhook forwarding
Default rule: When in doubt, include frontend (Hybrid). Users almost always want to see what's happening.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 173 lines · 0 tokens per session scan A e3233bf1d3a8
confusion is a cursor rule published in the GitHub repository freshworks-developers/fw-dev-tools (5 stars, last pushed 8d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 1,345 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
battle-tested-engineer
Battle-tested engineering judgment for code, refactors, tests, and frontend UI. Ultra-terse caveman style during code work.
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
cli-error-handling
CLI command error handling patterns.
prefer-direct-imports-over-module-mocks
Prefer extracting a testable core over vi.mock / vi.resetModules when unit tests need to reach production logic entangled with config, env, or singletons.
control-plane-descriptors
Control plane descriptor and instance implementation patterns.