Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/hlalljie/agent-workflow-presets/shell-environmentgit clone --depth 1 https://github.com/hlalljie/agent-workflow-presetsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00375 | $0.00375 |
| Opus 5 | $0.00187 | $0.00187 |
| Sonnet 5 | $0.00075 | $0.00075 |
| Haiku 4.5 | $0.00038 | $0.00038 |
Grade A, and why
shell-environment scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Shell Environment
Target Shell by Platform
- macOS / Linux: write shell snippets assuming zsh (or a compatible POSIX shell).
- Windows: write shell snippets assuming PowerShell.
The goal is that a developer on each platform can copy/paste commands into their default shell without translation.
macOS / Linux (zsh / POSIX shell)
- Use
&&for chaining commands where failures should stop the chain. - Use standard Unix tools (
head,tail,grep,ls -t,sed,awk) and heredocs for multi-line input. - Avoid Windows-only constructs or PowerShell cmdlets in examples intended for macOS/Linux.
✅ Example (macOS / Linux):
git add models/template.js models/template.html
git commit -m "Update height formulas"
Windows (PowerShell)
- Use PowerShell cmdlets where appropriate (
Get-ChildItem,Select-Object, etc.). - For multi-line git commit messages, prefer opening the editor (
git commit) or using a file you create in your editor, rather than ad-hoc Python helpers. - Avoid assuming bash-only features (e.g.,
[[ ... ]], process substitution) in Windows-specific instructions.
✅ Example (Windows):
git add models/template.js models/template.html
git commit -m "Update height formulas"
General Guidance
- When giving cross-platform instructions, call out both variants if they differ (zsh/Unix vs PowerShell).
- Do not use inline Python (
python - << 'EOF') just to drive git; use the platform shell or a small script checked into the repo instead.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 45 lines · 375 tokens per session scan A de4b3a644891
shell-environment is a cursor rule published in the GitHub repository hlalljie/agent-workflow-presets (2 stars, last pushed 1mo ago), licensed MIT. It adds 375 tokens to every session, about $0.0019 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
honey
Honey — write less code and say less about it. A reflexive minimal-code (YAGNI/stdlib-first) and terse-prose discipline that cuts token cost while keeping code, commands, and safety-critical paths exact.
module-shape
Prefer modules with a narrow public surface and a thick internal implementation. Inject external dependencies at the boundary. Mock only at system edges.
context-discipline
Manage AI context window efficiently - read before write, no re-reads, tool-call budgets, one-pass discipline.
quality-gates
Enforce quality checks before commits - lint, typecheck, and test affected code.
token-efficiency
Token efficiency rules - eliminate waste in AI output, enforce read-before-write, prevent iteration cycles.
pn-nextjs
Next.js best practices. Data loading, server/client boundaries, streaming, mutations, and performance. For Next app/ or pages/, pn-react also applies (core React patterns); content is complementary.