Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/hatefsystems/search-engine-core/frontendgit clone --depth 1 https://github.com/hatefsystems/search-engine-coreWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00366 |
| Opus 5 | $0.00000 | $0.00183 |
| Sonnet 5 | $0.00000 | $0.00073 |
| Haiku 4.5 | $0.00000 | $0.00037 |
Grade A, and why
frontend scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Frontend Integration
Paths
- Static:
/public/(StaticFileController, 1-year cache for JS/CSS) - Templates:
/templates/(Inja) - Locales:
/locales/— use language subfolders (en/,fa/), not files in root. Keeplanguages.jsonin root.
Localization Loading
// Load from language-specific folder
std::string localesPath = "locales/" + lang + "/crawling-notification.json";
std::string localeContent = loadFile(localesPath);
if (localeContent.empty()) {
localesPath = "locales/en/crawling-notification.json";
localeContent = loadFile(localesPath);
}
Locales checklist: locales/en/, locales/fa/; descriptive filenames (common.json, sponsor.json); fallback to English.
Links
Use {{ base_url }} for all internal links. Never hardcode localhost or port.
<a href="{{ base_url }}/crawl-request">Crawl Request</a>
CSS
Reuse existing classes; define shared values in :root; use BEM and utility classes.
JavaScript (CSP)
No inline handlers (onclick, etc.). Use data-* attributes and addEventListener().
<button data-copy-text="text" class="copy-btn">Copy</button>
Use addEventListener() and event delegation for dynamic elements. No onclick, onload, onsubmit, etc. in HTML.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 50 lines · 0 tokens per session scan A 55fcee57b513
frontend is a cursor rule published in the GitHub repository hatefsystems/search-engine-core (5 stars, last pushed 28d ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 366 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
wings
Authoring apps with the WINGS framework (Go compiled to WASM web components).
internationalization
Cursor rule "internationalization" from dtyq/magic, covering internationalization (i18n) rules, 国际化基本规范, 1. 文件结构, 2. 命名空间规范 and 3. 组件中使用国际化.
webkit-browser
Cursor rule "webkit-browser" from duckduckgo/apple-browsers, covering webkit & browser development guidelines, webview configuration, basic webview setup, user scripts management and tab management.
project-structure
Project folder layout for Vite and Next.js variants.
cypress-e2e-testing-cursorrules-prompt-file
Cursor rules for Cypress development with E2E testing.
vasu-playwright-utils
../../templates/cursor-rules/vasu-playwright-utils.mdc.