Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/intrafere/moto-autonomous-asi/api-key-controlsgit clone --depth 1 https://github.com/Intrafere/MOTO-Autonomous-ASIWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/intrafere/moto-autonomous-asi/api-key-controls)<a href="https://agentmods.dev/rules/intrafere/moto-autonomous-asi/api-key-controls"><img src="https://agentmods.dev/badge/rules/intrafere/moto-autonomous-asi/api-key-controls.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.10559 | $0.10559 |
| Opus 5 | $0.05280 | $0.05280 |
| Sonnet 5 | $0.02112 | $0.02112 |
| Haiku 4.5 | $0.01056 | $0.01056 |
Grade A, and why
api-key-controls scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 326 lines — stays where its author put it; the contents beside it link to each section on GitHub.
API Key Controls & Workflow Management System
Overview
Enables cloud provider access with LM Studio fallback in default mode (OpenRouter API keys plus desktop OAuth providers such as OpenAI Codex and xAI Grok/SuperGrok) and OpenRouter-only operation in generic mode, plus boost controls, research metrics, and the Assistant Memory Bank in the workflow panel.
Key Features:
- Per-Role Cloud Provider Selection: Each role independently uses LM Studio, OpenRouter, or a desktop-only OAuth/subscription provider where available (OpenAI Codex OAuth, xAI Grok OAuth, Sakana Fugu API key; default mode); generic mode remains OpenRouter-only.
- OpenRouter/OAuth: Header overlay manages OpenRouter API keys and desktop OAuth/provider logins (OpenAI Codex, xAI Grok/SuperGrok OAuth, Sakana Fugu subscription API key). The post-disclaimer startup wizard requires OpenRouter or LM Studio first and presents OAuth/provider add-ons later. The provider UI is registry-driven (
openai_codex_oauth,xai_grok_oauth,sakana_fugu) so future providers can be added without changing saved profile shape. OAuth attribution identifiers must refer to MOTO Autonomous ASI, never the bare nicknamemoto; compact OAuth identifier fields usemoto-autonomous-asiunless a provider explicitly requires the full display name. - Credential State Refresh: Adding/removing OpenRouter keys or desktop OAuth/subscription credentials must immediately invalidate mounted settings panels so provider buttons and model lists refresh without tab navigation. Credential presence and model-list loading are distinct: a valid OpenRouter key stays enabled if
/modelstransiently fails; failed OAuth/subscription model loads clear stale model lists and show provider-specific errors. - SyntheticLib4 Access: SyntheticLib4 backend/search scaffolding remains in place, but the user-facing connectivity pill is currently a
Coming soonexplainer rather than a ready/configuration surface. The modal explains the reciprocal proof-contribution/access model until production corpus access is enabled. - Session History Memory: The connectivity toggle defaults enabled for new users and maps to local MOTO/manual/LeanOJ proof-history memory used by Assistant workflow-memory search during brainstorming, writing, proof work, and LeanOJ solving. It is not raw provider transcript or chain-of-thought storage. Disabling it persists as non-secret runtime state, removes local proof-history corpora from Assistant retrieval, and must not delete proof records or alter internal retry/rejection/prompt memory.
- Assistant Role: Aggregator, Compiler, Autonomous Research, and LeanOJ expose one shared non-blocking Assistant LLM role per workflow surface for verified Lean proof-history support. Autonomous papers-only runs suppress Assistant proof-memory scheduling and injection for the parent and its child Aggregator/Compiler roles without changing the user's persisted Session History setting. Otherwise supports are optional: Assistant cannot redirect or mathematically reinterpret an unrelated parent goal, and no useful proof support is a valid result. Assistant selects up to 7 prior verified proof supports, never replaces validators or submitters, never blocks parent workflows, and is disabled when Session History Memory is disabled. Useful Assistant packs may be reused by two eligible receiver reads before the next refresh. True no-history targets are skipped because Assistant only performs proof-memory retrieval for now. Durable cooldown groups transient task IDs/roles by workflow run while preserving real source/session separation: repeated zero-useful retrieval backs off and may shut down for the run; repeated stagnant same-pack retrieval backs off without shutdown. Top-level Stop clears live/latest pack state, while schema-validated SQLite ranking/goal/pack history can remain rebuildable; explicit Clear/reset or Session History Memory disable also clears durable run-scoped Assistant state. User live activity should show normal Assistant retrieval result logs and explicit Assistant model-output failures, not skip/backoff/shutdown turns. The WorkflowPanel Assistant Memory Bank may show the latest metadata-only up-to-7 pack as novelty-colored proof-history tiles; it must not expose Lean code through pack events.
- Progressive Solution Path: Before five cumulative accepted brainstorm events in a top-level run it is absent from prompts and UI. After activation, only existing semantic validators may optionally propose material updates through separately parsed normal-response JSON; this never changes or blocks the primary decision. Updates apply only after transactional serial review by a dedicated role configured exactly from Main Submitter 1. Hard provider/config/context failures enter visible user-repair state rather than retrying forever; after settings repair, the user explicitly retries the generation-fenced proposal through
POST /api/workflow/solution-path/resume. Stop/crash preserves state, while Clear/new-run is the only count reset and is serialized against reacquisition. - Startup provider requirement: OAuth providers are supplementary role providers, not a standalone startup path, because RAG embeddings route through LM Studio, OpenRouter, or generic-mode FastEmbed. First-run startup and workflow start preflights must require OpenRouter, generic FastEmbed, or LM Studio with an embedding model available before OAuth-only role selection is allowed.
- OpenRouter Auto-Fill: OpenRouter selectors fetch provider endpoint metadata and compute host-aware context/output settings from a capable endpoint set. Auto mode ignores known weak hosts (currently Venice) and low/missing-cap outliers before computing context/max-output; manual host selection uses that exact host and its largest exposed endpoint output cap.
- OAuth Auto-Fill: OAuth model selectors auto-fill only from provider model metadata, documented provider-specific limits, or curated provider-backed public aliases. Do not invent generic fallback context windows for unknown OAuth models; preserve current settings when metadata is unknown. GPT-5.5 Codex uses the Codex 400K product window, not the 1M regular API window; Codex Spark high is exposed as a curated alias for Codex Spark with high reasoning and its documented 128K window. Grok/SuperGrok OAuth uses xAI model metadata when available and may expose known Grok subscription limits only for known model IDs; model listings must filter xAI catalog entries that are not accepted by the OAuth chat-completions route, such as multi-agent-only models.
- OpenRouter Reasoning Effort: Every OpenRouter role exposes a visible reasoning-effort selector. Default
autosends maximum OpenRouter reasoning effort (xhigh) through the normalizedreasoning.effortrequest object; users may lower it or setnone. - LM Studio Fallback (default mode only): Optional fallback per role on credit exhaustion
- Free Model Cooldown Handling: SERIAL BOTTLENECK pause, free model looping, and auto-selector backup (see below)
- Boost Mode: Selective task acceleration via next-count, category, always-prefer, and per-task routing controls, using either an explicit boost override key or the active global OpenRouter key:
- Boost Next X Calls: Counter-based, next X API calls regardless of task ID
- Category Boost: Role-based, boosts all calls for exposed Aggregator, Compiler, autonomous parent-role, and selected LeanOJ category presets. Autonomous proof task IDs and non-exposed LeanOJ helper prefixes are boostable through Boost Next X, Always Prefer, or exact task IDs, but are not separate category presets unless added to
/api/boost/categories. - Always Prefer Boost: Attempts boost for every API call, falling back to the primary route on boost failure
- Per-Task Toggle: Legacy task-ID boost controls for individual workflow tasks
- Supercharge: Per-role setting that wraps one role answer as 4 parallel diversified full answer attempts plus a 5th same-model deterministic synthesis answer. If Boost applies, all 5 calls use the Boost route/model/provider/settings.
- Creativity Emphasis Boost: Developer-gated brainstorm prompt mode for Aggregator, Autonomous Aggregator-backed brainstorm/title/topic exploration, and LeanOJ topic/brainstorm submitters. It is prompt pressure only, not routing or concurrency, and marks accepted/rejected activity with
creativity_emphasized. - System works without LM Studio: Defaults to OpenRouter when LM Studio unavailable; generic-mode inference and embeddings never route through LM Studio, though shared legacy diagnostics may still exist and should not be used by hosted UI
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday Changed · +86 tokens per session 640b90ad26ce
- 6d ago First seen · 326 lines · 10,473 tokens per session scan A 53af4fa9c69b
api-key-controls is a cursor rule published in the GitHub repository Intrafere/MOTO-Autonomous-ASI (82 stars, last pushed yesterday), licensed MIT. It adds 10,559 tokens to every session, about $0.0528 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
ponytail
Ponytail, lazy senior dev mode. Always pick the simplest solution that works.
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
cli-error-handling
CLI command error handling patterns.
prefer-direct-imports-over-module-mocks
Prefer extracting a testable core over vi.mock / vi.resetModules when unit tests need to reach production logic entangled with config, env, or singletons.
control-plane-descriptors
Control plane descriptor and instance implementation patterns.