004-risk-checkpoint

A final safety rule that checks potentially risky operations before they run. It classifies actions such as data deletion, security changes, service disruption, and ordinary reads by risk level.

In plain words
What is it for?
Use it as a last checkpoint for commands that could delete data, expose credentials, change system permissions, disrupt services, or otherwise damage a project.
Why use it?
It helps prevent dangerous commands or accidental damage by identifying warning patterns before execution.

Cursor rule

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/hamzaamjad/cursor-rules/004-risk-checkpoint
Clone the repo
git clone --depth 1 https://github.com/hamzaamjad/cursor-rules
Per session 8 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,008 The whole file, excluding the scripts and references it only reads on demand.
Security scan B 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00008 $0.01008
Opus 5 $0.00004 $0.00504
Sonnet 5 $0.00002 $0.00202
Haiku 4.5 $0.00001 $0.00101

Measured 2d ago against content hash 112003f36b94, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade B, and why

004-risk-checkpoint scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Asks for rootmediumPrivilege escalation

A mod that escalates privileges can change anything on the machine, not only the project.

r'sudo(?!\s+apt-get)', # Unwhitelisted sudo r'DELETE.*WHERE.*[><=].*1000', # Bulk operations
rules/000-core/004-risk-checkpoint.mdc · 138 lines

How it starts

The opening of the file, as written. The whole thing — 138 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Risk Checkpoint

Purpose: Block operations exceeding risk thresholds. 90-95% critical incident reduction.

Risk Classification

RISK_LEVELS = {
    'CRITICAL': ['data_loss', 'security_breach', 'system_corruption'],
    'HIGH': ['service_disruption', 'config_damage', 'privacy_violation'],
    'MEDIUM': ['performance_impact', 'reversible_changes', 'resource_usage'],
    'LOW': ['read_operations', 'isolated_changes', 'logging']
}

RISK_SIGNATURES = {
    'CRITICAL': [
        r'rm\s+-rf\s+/',                    # Root deletion
        r'DROP\s+DATABASE|TRUNCATE',        # Data destruction
        r'sudo\s+chmod\s+777',              # Security compromise
        r'(API_KEY|SECRET|PASSWORD)',       # Credential exposure
        r'(\.ssh/|/etc/passwd)',           # System file mods
    ],
    'HIGH': [
        r'sudo(?!\s+apt-get)',             # Unwhitelisted sudo
        r'DELETE.*WHERE.*[><=].*1000',     # Bulk operations
        r'git\s+push.*main|master',        # Direct main push
    ]
}

Risk Assessment Pipeline

def assess_risk(operation):
    # 1. Pattern matching
    base_score = match_signatures(operation, RISK_SIGNATURES)
    
    # 2. Context multipliers
    multipliers = {
        'environment': 2.0 if prod else 1.0,
        'bulk_operation': 1.5 if count > 100 else 1.0,
        'data_sensitivity': 2.0 if has_pii else 1.0,
        'time_restriction': 1.5 if off_hours else 1.0
    }
    
    # 3. Sequence analysis
    if creates_dangerous_sequence(operation, history):
        base_score = max(base_score, 'HIGH')
    
    # 4. Final score
    return apply_multipliers(base_score, multipliers)

Decision Framework

Risk Level Action Requirements
CRITICAL ❌ BLOCK Human override + justification
HIGH ⚠️ WARN Explicit approval + safeguards
MEDIUM 🔔 NOTIFY Confirmation + logging
LOW ✅ PROCEED Log for audit

Implementation Patterns

Read the full file on GitHub · 138 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 138 lines · 8 tokens per session scan B 112003f36b94

Subscribe to this mod's changes

004-risk-checkpoint is a cursor rule published in the GitHub repository hamzaamjad/cursor-rules (2 stars, last pushed 1y ago), licensed MIT. It adds 8 tokens to every session and 1,008 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it B with 1 finding (asks for root). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.