Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/hashgraph-online/hol-cursorrules/cursorrulesgit clone --depth 1 https://github.com/hashgraph-online/hol-cursorrulesWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.01787 | $0.01787 |
| Opus 5 | $0.00894 | $0.00894 |
| Sonnet 5 | $0.00357 | $0.00357 |
| Haiku 4.5 | $0.00179 | $0.00179 |
Grade A, and why
cursorrules scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 258 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Hashgraph Online (HOL) Development Rules
You are an expert TypeScript developer building applications with Hashgraph Online (HOL) - the open-source SDK for AI agents and decentralized applications on Hedera.
Technology Stack
Core:
- Language: TypeScript (strict mode)
- Runtime: Node.js 20+
- Package Manager: pnpm
- Testing: Jest with @swc/jest
HOL SDK:
- @hashgraphonline/standards-sdk - Core SDK for HCS standards and Registry Broker
- @hol-org/hashnet-mcp - MCP server for AI agent integration
Frontend (when applicable):
- Framework: Next.js 14+ (App Router)
- UI: shadcn/ui + Tailwind CSS
- Icons: react-icons (Lucide preferred)
Coding Standards
TypeScript Requirements
- NEVER use
any- define proper interfaces - NEVER use
as anycasting - use type guards - ALWAYS define explicit return types
- ALWAYS use generics for flexible code
- Validate external data with type guards or zod
File Naming
- Use kebab-case:
registry-client.ts,topic-manager.ts - Test files:
__tests__/registry-client.test.ts - Components:
registry-browser.tsx
Code Style
- Max 500 lines per file - split larger files
- No nested ternaries
- No inline comments - use JSDoc only
- No console.log - use Logger from standards-sdk
- Prettier formatting required
React Patterns (when applicable)
- NO render functions like
renderContent() - NO inline callbacks in JSX
- NO hooks in loops/conditionals
- ALWAYS use separate child components
- ALWAYS define Props interfaces
HOL SDK Usage
RegistryBrokerClient - Initialization
import { RegistryBrokerClient } from '@hashgraphonline/standards-sdk';
const client = new RegistryBrokerClient({
baseUrl: 'https://api.hol.org',
apiKey: process.env.HOL_API_KEY,
});
RegistryBrokerClient - Search Agents
import { RegistryBrokerClient, SearchParams, Logger } from '@hashgraphonline/standards-sdk';
const logger = new Logger({ module: 'AgentSearch', level: 'info' });
const client = new RegistryBrokerClient();
const searchParams: SearchParams = {
q: 'weather',
registry: 'hcs-10',
limit: 10,
page: 1,
};
const results = await client.search(searchParams);
logger.info('Search completed', { total: results.total });
results.hits.forEach(agent => {
logger.debug('Agent found', { name: agent.name, description: agent.description });
});
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 258 lines · 1,787 tokens per session scan A 837ce3ffbcae
cursorrules is a cursor rule published in the GitHub repository hashgraph-online/hol-cursorrules (1 stars, last pushed 7mo ago), licensed MIT. It adds 1,787 tokens to every session, about $0.0089 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
create-rule-agent
This rule is responsible for creating and updating Cursor rules. Cursor rules govern the structure, hierarchy, style and organization of code in a project. This rule should be invoked in Agent mode when: 1. a user wants to create a new cursor rule, 2. a user wants to update or change an existing rule, 3. user wants…
security-scan-agent
This rule provides comprehensive security scanning for dependencies, complementing the dependency analysis rule with deep security insights including CVE analysis, license compliance, and supply chain risk assessment.
cloudflare-workers-auto
Cloudflare Workers development standards and best practices.
cloudflare-workers-hono-auto
Cloudflare Workers with Hono framework development standards and best practices.
changelog-generator-manual
This rule generates a comprehensive changelog.md file by analyzing all git tags and commits, creating a chronological record of all project changes with proper semantic versioning structure. The changelog.md file is stored at the root of the project.
vue3-typescript-auto
Vue 3 with TypeScript Standards.