Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/freshworks-developers/fw-dev-tools/fdk-enforcementgit clone --depth 1 https://github.com/freshworks-developers/fw-dev-toolsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00734 | $0.00734 |
| Opus 5 | $0.00367 | $0.00367 |
| Sonnet 5 | $0.00147 | $0.00147 |
| Haiku 4.5 | $0.00073 | $0.00073 |
Grade A, and why
fdk-enforcement scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 59 lines — stays where its author put it; the contents beside it link to each section on GitHub.
FDK Setup Skill - Enforcement Rules
Scope
This skill handles FDK installation and management only. It does NOT create apps.
How This Skill Works
User must explicitly invoke commands (Confluence-style primary names):
/fw-setup-install(optional--version X.Y.Zfor FDK 10.x.y CDN pin)/fw-setup-status(optional--verbose; inline only)/fw-setup-upgrade(optional--to X.Y.Zfor pinned semver)- FDK 9 + Node 18 → FDK 10 + Node 24.11: use
/fw-setup-install//fw-setup-upgradeon an active Node 24 shell (seeSKILL.md); there is no separate/fw-setup-migratecommand file in this skill. /fw-setup-downgrade(optional pinned 9.x.y; else latest 9 line)/fw-setup-uninstall(FDK only — no--all/ no nvm removal)/fw-setup-troubleshoot(inline diagnose;--fix= shell Task)/fw-setup-use(workspacenvm use/.nvmrcfor FDK 10 vs 9 stack; optional--write-nvmrc; inline only)
Legacy aliases (same flows): /fdk-install, /fdk-status, /fdk-upgrade, /fdk-downgrade, /fdk-uninstall
What happens:
- User types slash command
- Command file under
commands/fw-setup-*.mddefines the Task (or inline status) - Subagent spawned with full context for mutating operations
- Operation executes autonomously
- Reports back results
Important Limitation
This skill does NOT automatically check for FDK when users request app creation.
If user says "create a freshdesk app" without first running /fw-setup-install (or legacy /fdk-install), the agent may create files manually without proper FDK setup.
Recommended Workflow for App Creation
Before creating any Freshworks app, users should:
-
First, install FDK:
/fw-setup-install(or legacy/fdk-install) -
Then, optionally install fw-app-dev skill for templates, Crayons, and app-specific slash commands (those live in fw-app-dev, not fw-setup).
-
Then proceed with app creation using
fdk createwhere possible.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 59 lines · 734 tokens per session scan A 7f17a6af4ba3
fdk-enforcement is a cursor rule published in the GitHub repository freshworks-developers/fw-dev-tools (5 stars, last pushed 8d ago), licensed MIT. It adds 734 tokens to every session, about $0.0037 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
battle-tested-engineer
Battle-tested engineering judgment for code, refactors, tests, and frontend UI. Ultra-terse caveman style during code work.
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
cli-error-handling
CLI command error handling patterns.
prefer-direct-imports-over-module-mocks
Prefer extracting a testable core over vi.mock / vi.resetModules when unit tests need to reach production logic entangled with config, env, or singletons.
control-plane-descriptors
Control plane descriptor and instance implementation patterns.