Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/gosha70/code-copilot-team/integration-testinggit clone --depth 1 https://github.com/gosha70/code-copilot-teamWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00020 | $0.00926 |
| Opus 5 | $0.00010 | $0.00463 |
| Sonnet 5 | $0.00004 | $0.00185 |
| Haiku 4.5 | $0.00002 | $0.00093 |
Grade A, and why
integration-testing scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl -s -o /dev/null -w "%{http_code}" http://localhost:3000/login How it starts
The opening of the file, as written. The whole thing — 107 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Integration Testing Protocol
Rules for verifying that cross-cutting features work before building on top of them.
Auth Must Be Verified Before Feature Development
Authentication is the most common source of cascading failures in multi-agent builds. Auth issues that go undetected compound as more features depend on protected routes.
After implementing auth (any strategy):
-
Verify the auth flow end-to-end:
- Login succeeds with valid credentials
- Login fails with invalid credentials
- Protected routes redirect unauthenticated users
- Session persists across page navigation
- Logout clears the session
-
Verify admin access (if applicable):
- Admin routes are accessible only to admin users
- Non-admin users are redirected or shown a 403
- The admin check works with the actual session token, not a mock
-
Do not build features on top of auth until the flow is verified. Building protected pages before confirming auth works leads to multi-session debugging cycles.
API Contract Verification
After implementing backend services or API routes:
- Test each endpoint with a real request (not just type-checking).
- Verify that request/response shapes match the contracts defined in the plan.
- Verify error responses (404, 400, 401, 500) return the expected format.
- If using an ORM, verify that database queries return the expected data shape.
Frontend-Backend Integration
After connecting frontend to backend:
- Verify that UI components call the correct API endpoints.
- Verify that loading states, error states, and empty states all render.
- Verify that mutations (create, update, delete) reflect in the UI without a page refresh.
- Check the browser console for errors — especially hydration mismatches in SSR frameworks.
Cross-Agent Integration
When multiple agents have worked in parallel:
- Check shared types — do both sides agree on the shape of shared data?
- Check imports — are agents importing from the correct paths?
- Check database state — if one agent created schema and another wrote queries, do they match?
- Run the full app — not just individual modules.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 107 lines · 20 tokens per session scan A d2fe66e6167e
integration-testing is a cursor rule published in the GitHub repository gosha70/code-copilot-team (6 stars, last pushed 2d ago), licensed MIT. It adds 20 tokens to every session and 926 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
typescript
Changes to these high-fan-out internals can affect every message, delta, element, or rerun. Keep work in them minimal, and benchmark changes with representative stress-test apps.
coolify-ai-docs
Master reference to all Coolify AI documentation in .ai/ directory.
python_lib
Tips and guidelines specific to the development of the Streamlit Python library, not applicable to scripts and e2e tests.
specs
This directory contains product and tech specs for Streamlit features.