Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/jketreno/clare/skill-autonomy-bootstrapgit clone --depth 1 https://github.com/jketreno/clareWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00007 | $0.01395 |
| Opus 5 | $0.00003 | $0.00698 |
| Sonnet 5 | $0.00001 | $0.00279 |
| Haiku 4.5 | $0.00001 | $0.00139 |
Grade A, and why
skill-autonomy-bootstrap scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 209 lines — stays where its author put it; the contents beside it link to each section on GitHub.
name: autonomy-bootstrap description: "Draft or refine clare/autonomy.yml boundaries and sources_of_truth via guided interview" mode: agent
Bootstrap CLARE Autonomy Configuration
What this skill does: Guides the user through creating or refining clare/autonomy.yml so AI boundaries and sources of truth match the real project architecture. When to use: Use when adopting CLARE in a new repository, reworking module boundaries, or tightening AI safety zones. Output: A proposed or updated clare/autonomy.yml plus a short checklist of follow-up setup actions.
Context
CLARE's Limited principle requires explicit autonomy boundaries per path. CLARE's Reality-Aligned principle requires sources_of_truth for important domain concepts.
The canonical source for both in a CLARE project is clare/autonomy.yml.
Instructions
When invoked, run this process.
Step 1: Gather project structure and risk profile
- Read the repository tree and identify major modules.
- Ask the user which areas are high-risk or compliance-sensitive.
- Ask which areas are safe for AI iteration and regeneration.
Classify candidate paths into:
- full-autonomy: low-risk utilities, generated code, repetitive glue code
- supervised: most application code requiring review
- humans-only: auth/payment/compliance/safety-critical logic
Decision matrix:
| Path characteristics | Suggested level | Why |
|---|---|---|
| Authentication, payments, legal/compliance workflows, production access controls | humans-only | High impact mistakes require intentional manual authorship |
| Core business logic, API handlers, shared domain models | supervised | AI can draft quickly, but behavior needs human review |
| Generated code, boilerplate wiring, test fixtures, low-risk utilities | full-autonomy | Fast regeneration and iteration are low risk |
Step 2: Draft module boundaries
Draft a modules section with specific path patterns and reasons.
Requirements:
- Use specific paths first, then end with a wildcard default.
- Include a human-readable reason for every entry.
- Keep ambiguous paths out of humans-only until confirmed.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 209 lines · 7 tokens per session scan A ae3a62dc65af
skill-autonomy-bootstrap is a cursor rule published in the GitHub repository jketreno/clare (5 stars, last pushed 1mo ago), licensed MIT. It adds 7 tokens to every session and 1,395 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
cli-error-handling
CLI command error handling patterns.
prefer-direct-imports-over-module-mocks
Prefer extracting a testable core over vi.mock / vi.resetModules when unit tests need to reach production logic entangled with config, env, or singletons.
control-plane-descriptors
Control plane descriptor and instance implementation patterns.
family-instance-domain-actions
Family instance domain action implementation patterns.