Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/jlevy/speculate/tbdgit clone --depth 1 https://github.com/jlevy/speculateWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.01116 | $0.01116 |
| Opus 5 | $0.00558 | $0.00558 |
| Sonnet 5 | $0.00223 | $0.00223 |
| Haiku 4.5 | $0.00112 | $0.00112 |
Grade A, and why
tbd scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 124 lines — stays where its author put it; the contents beside it link to each section on GitHub.
tbd Workflow
tbd provides lightweight, git-native task and issue tracking using beads, which are
just lightweight issues managed from the CLI.
Context Recovery: Run
tbd primeafter compaction, clear, or new session. Hooks auto-call this in Claude Code when .tbd/ detected.
SESSION CLOSING PROTOCOL
CRITICAL: Before saying “done” or “complete”, you MUST run this checklist:
[ ] 1. Stage and commit: git add + git commit
[ ] 2. Push to remote: git push
[ ] 3. Start CI watch (BLOCKS until done): gh pr checks <PR> --watch 2>&1
[ ] 4. While CI runs: tbd close/update <id> for issues worked on
[ ] 5. While CI runs: tbd sync
[ ] 6. Return to step 3 and CONFIRM CI passed
[ ] 7. If CI failed: fix, re-push, restart from step 3
NON-NEGOTIABLE Requirements
CI: Wait for --watch to finish
The --watch flag blocks until ALL checks complete.
Do NOT see “passing” in early output and move on—wait for the final summary showing
all checks passed.
tbd: Update issues and sync
Every session must end with tbd in a clean state:
- Close/update every issue you worked on
- Run
tbd syncand confirm it completed
Work is not done until pushed, CI passes, and tbd is synced.
Core Rules
- Track all task work not being done immediately as beads using
tbd(discovered work, future work, TODOs for the session, multi-session work) - When in doubt, prefer tbd for tracking tasks, bugs, and issues
- Use
tbd createfor creating beads - Git workflow: update or close issues and run
tbd syncat session end - If not given specific directions, check
tbd readyfor available work
Essential Commands
Finding Work
tbd ready- Show issues ready to work (no blockers)tbd list --status open- All open issuestbd list --status in_progress- Your active worktbd show <id>- Detailed issue view with dependencies
Creating & Updating
tbd create "title" --type task|bug|feature --priority P2- New issue- Priority: P0-P4 (P0=critical, P2=medium, P4=backlog). Do NOT use "high"/"medium"/"low"
tbd update <id> --status in_progress- Claim worktbd update <id> --assignee username- Assign to someonetbd close <id>- Mark completetbd close <id> --reason "explanation"- Close with reason- Tip: When creating multiple issues, use parallel subagents for efficiency
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 124 lines · 1,116 tokens per session scan A e48bc8ac34fe
tbd is a cursor rule published in the GitHub repository jlevy/speculate (34 stars, last pushed 6mo ago), licensed MIT. It adds 1,116 tokens to every session, about $0.0056 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
typescript
Changes to these high-fan-out internals can affect every message, delta, element, or rerun. Keep work in them minimal, and benchmark changes with representative stress-test apps.
coolify-ai-docs
Master reference to all Coolify AI documentation in .ai/ directory.
python_lib
Tips and guidelines specific to the development of the Streamlit Python library, not applicable to scripts and e2e tests.
specs
This directory contains product and tech specs for Streamlit features.