Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/golid-ai/golid/openapigit clone --depth 1 https://github.com/golid-ai/golidWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00840 |
| Opus 5 | $0.00000 | $0.00420 |
| Sonnet 5 | $0.00000 | $0.00168 |
| Haiku 4.5 | $0.00000 | $0.00084 |
Grade A, and why
openapi scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 98 lines — stays where its author put it; the contents beside it link to each section on GitHub.
OpenAPI Spec Patterns
Thesis: The OpenAPI spec is hand-maintained and drives frontend type generation. Update it whenever endpoints change, then regenerate types.
The API is documented in backend/openapi.yaml (OpenAPI 3.1, hand-maintained).
When to Update
Update the spec whenever you:
- Add a new endpoint (handler + route in
internal/wire/routes.go) - Change request/response schemas
- Add or modify query parameters
- Change authentication requirements
Adding a New Endpoint
Follow the existing pattern. Each endpoint needs:
/your-resource:
get:
summary: Short description
tags: [YourTag]
security: [{ bearerAuth: [] }] # omit for public endpoints
parameters: [] # query params if any
responses:
"200":
description: Success description
content:
application/json:
schema: { $ref: "#/components/schemas/YourSchema" }
"401": { $ref: "#/components/responses/Unauthorized" }
Adding a New Schema
Add to components/schemas. Match the Go Detail struct field names exactly:
YourResource:
type: object
properties:
id: { type: string, format: uuid }
title: { type: string }
created_at: { type: string, format: date-time }
Scaffold Integration
make new-module name=items generates backend code but does NOT auto-update the spec. After scaffolding, manually add the CRUD endpoints following the pattern above.
Conventions
- Endpoint paths must match routes registered in
internal/wire/routes.go - Use
$reffor shared schemas and responses (DRY) - Tag names match handler file groupings (Auth, Users, Features, SSE)
- Reuse
MessageResponsefor simple{"message": "..."}responses - Reuse
AppErrorfor all error responses
TypeScript Type Generation
The frontend generates TypeScript types from this spec via openapi-typescript:
cd frontend && npm run generate:types
This reads backend/openapi.yaml and outputs gitignored frontend/src/lib/api.generated.ts. CI runs this command in the frontend job so invalid specs fail the build.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 98 lines · 0 tokens per session scan A 5eb3de8ee349
openapi is a cursor rule published in the GitHub repository golid-ai/golid (40 stars, last pushed 2mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 840 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
cursorrules
AGENTS.md.
adapter-features
Database-specific features must be implemented in the specialized adapter only. Base adapters (postgres, mysql, etc.) must remain database-agnostic.
git-commits
Git commit safety — commits are human-only; AI suggests, never executes.
unit-tests-tdd
TDD required for behavior changes; ≥80% package coverage on touched packages; unit-test conventions.
token-optimization
Agent-mode tool-call efficiency. Cuts the largest hidden cost in modern AI IDEs — wasted tool calls and oversized context windows.
config-resilience
Config warn-and-continue for non-sensitive keys; Auth/ACL/JWT/secrets/DB credentials fail closed.