Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/goranerhartic/cursor-development-rules/resiliencegit clone --depth 1 https://github.com/GoranErhartic/cursor-development-rulesWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00017 | $0.00741 |
| Opus 5 | $0.00009 | $0.00370 |
| Sonnet 5 | $0.00003 | $0.00148 |
| Haiku 4.5 | $0.00002 | $0.00074 |
Grade A, and why
resilience scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 109 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Polly Resilience Patterns
HttpClient with Polly (.NET 10)
builder.Services.AddHttpClient<IPaymentGateway, PaymentGateway>(client =>
{
client.BaseAddress = new Uri(builder.Configuration["PaymentGateway:BaseUrl"]!);
client.Timeout = TimeSpan.FromSeconds(30);
})
.AddStandardResilienceHandler();
// Or with custom configuration
builder.Services.AddHttpClient<IExternalApi, ExternalApiClient>()
.AddResilienceHandler("custom", builder =>
{
builder
.AddRetry(new HttpRetryStrategyOptions
{
MaxRetryAttempts = 3,
Delay = TimeSpan.FromMilliseconds(500),
BackoffType = DelayBackoffType.Exponential,
ShouldHandle = new PredicateBuilder<HttpResponseMessage>()
.Handle<HttpRequestException>()
.HandleResult(r => r.StatusCode >= HttpStatusCode.InternalServerError)
})
.AddCircuitBreaker(new HttpCircuitBreakerStrategyOptions
{
FailureRatio = 0.5,
SamplingDuration = TimeSpan.FromSeconds(10),
MinimumThroughput = 5,
BreakDuration = TimeSpan.FromSeconds(30)
})
.AddTimeout(TimeSpan.FromSeconds(10));
});
Resilience Strategies
Retry
.AddRetry(new RetryStrategyOptions<HttpResponseMessage>
{
MaxRetryAttempts = 3,
Delay = TimeSpan.FromMilliseconds(200),
BackoffType = DelayBackoffType.Exponential,
UseJitter = true, // Prevents thundering herd
OnRetry = args =>
{
_logger.LogWarning("Retry {Attempt} after {Delay}ms",
args.AttemptNumber, args.RetryDelay.TotalMilliseconds);
return ValueTask.CompletedTask;
}
})
Circuit Breaker
.AddCircuitBreaker(new CircuitBreakerStrategyOptions<HttpResponseMessage>
{
FailureRatio = 0.5, // 50% failure rate triggers break
SamplingDuration = TimeSpan.FromSeconds(10),
MinimumThroughput = 10, // Minimum requests before evaluating
BreakDuration = TimeSpan.FromSeconds(30),
OnOpened = args =>
{
_logger.LogError("Circuit breaker opened for {Duration}", args.BreakDuration);
return ValueTask.CompletedTask;
}
})
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 109 lines · 17 tokens per session scan A 997d951bc4cd
resilience is a cursor rule published in the GitHub repository GoranErhartic/cursor-development-rules (19 stars, last pushed 6mo ago), licensed MIT. It adds 17 tokens to every session and 741 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
aspnet-abp-cursorrules-prompt-file
Cursor rules for Aspnet Abp.
kraken-net
Conventions for using Kraken.Net when working with Kraken Spot and Futures cryptocurrency exchange APIs in C#/.NET. Apply when generating code that interacts with Kraken API.
bybit-net
Conventions for using the Bybit.Net library when working with the Bybit cryptocurrency exchange in C#/.NET. Apply when generating code that interacts with the Bybit API.
hyperliquid-net
Conventions for using HyperLiquid.Net when working with the HyperLiquid DEX in C#/.NET, including spot, futures, account, HIP-3 DEX, and HIP-4 outcome APIs. Apply when generating code that interacts with the HyperLiquid API.
dotnet-clean-code
C#/.NET-specific clean code standards and idioms. Covers naming conventions, C# language patterns, async/await correctness, DI, and .NET tooling hygiene. Complements engineering-principles.mdc.
coding-style
his file provides guidelines for writing clean, maintainable, and idiomatic C# code with a focus on functional patterns and proper abstraction.