Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/jimmypocock/cursor-rules/aws-samgit clone --depth 1 https://github.com/jimmypocock/cursor-rulesWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00010 | $0.00752 |
| Opus 5 | $0.00005 | $0.00376 |
| Sonnet 5 | $0.00002 | $0.00150 |
| Haiku 4.5 | $0.00001 | $0.00075 |
Grade A, and why
aws-sam scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 112 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Description: AWS Serverless Application Model (SAM) Development Standards Globs: **/.yaml, **/.yml, **/template.yaml, **/sam.yaml
AWS SAM Development Standards
@base.mdc
SAM Template Structure
- Organize templates with logical resource groupings
- Use clear, descriptive resource names
- Add comments for complex resource configurations
- Structure templates consistently across projects
- Implement parameters for configurable values
- Use outputs for important resource information
- Create mappings for environment-specific variables
- Split complex applications into nested stacks
SAM Resource Definitions
- Define Lambda functions with appropriate properties
- Configure API Gateway resources properly
- Set up DynamoDB tables with correct key structures
- Implement proper S3 bucket configurations
- Create appropriate event source mappings
- Configure Step Functions state machines properly
- Set up SNS topics and SQS queues with correct attributes
- Define appropriate CloudWatch alarm resources
Function Configuration
- Set appropriate memory and timeout values
- Configure environment variables properly
- Implement function layers for shared code
- Set up appropriate IAM roles with least privilege
- Configure function URL settings when applicable
- Implement proper VPC configurations when needed
- Set up provisioned concurrency for critical functions
- Configure proper retry behavior for event sources
API Gateway Configuration
- Implement proper API Gateway endpoint types
- Configure appropriate authorization methods
- Set up request/response mappings properly
- Implement proper CORS settings
- Configure throttling and quota limits
- Set up appropriate caching strategies
- Implement proper stage variables
- Configure request validation when applicable
Event Configuration
- Define appropriate event sources for Lambda functions
- Configure event filters to reduce unnecessary invocations
- Set proper batch sizes for stream-based event sources
- Implement proper failure handling for event processing
- Configure event retention and replay strategies
- Set up dead-letter queues for failed events
- Configure event source mappings with proper concurrency settings
- Implement event bridging patterns when appropriate
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 112 lines · 10 tokens per session scan A 83745a469edf
aws-sam is a cursor rule published in the GitHub repository jimmypocock/cursor-rules (8 stars, last pushed 1y ago), licensed MIT. It adds 10 tokens to every session and 752 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
90-devops-deployment
Docker, CI/CD, AWS, Vercel, and VPS deployment rules.
00-global-architect
Global default behavior for the entire repository.
35-api-contracts
API versioning, contracts, and schema evolution rules.
45-environment-config
Environment configuration and secrets management rules.
50-rag-system
Retrieval-augmented generation rules.
55-data-model-versioning
Dataset versioning, model checkpoint management, and training reproducibility rules.