Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/kareemessam09/openship-app/cursorrulesgit clone --depth 1 https://github.com/kareemessam09/Openship-AppWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00682 | $0.00682 |
| Opus 5 | $0.00341 | $0.00341 |
| Sonnet 5 | $0.00136 | $0.00136 |
| Haiku 4.5 | $0.00068 | $0.00068 |
Grade A, and why
cursorrules scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 51 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Openship-App — Cursor AI Rules
Project
Unofficial Android client for Openship (self-hostable deployment platform). KMP + Compose Multiplatform. MCP as primary API layer, SSE for real-time streams.
Tech Stack
- Kotlin 2.4.10, Compose Multiplatform 1.11.1, AGP 9.0.1
- compileSdk 36, minSdk 24, JDK 21
- Planned: Ktor 3.5.2, Kotlin MCP SDK 0.15.0, Koin 4.x, kotlinx.serialization 1.11.0
- Package:
com.kareemessam.openship(app),com.kareemessam.openship.shared(shared)
Architecture
shared/(KMP): commonMain = networking (MCP + SSE), models, repository. androidMain = Keystore, OkHttp engine.androidApp/(Android): Compose UI, ViewModels, Koin DI, navigation.- One shared Ktor HttpClient for both MCP transport and SSE streams.
- MCP for discrete ops (health, list projects). SSE for real-time (build logs, monitoring).
Key Rules
- All networking code in
shared/commonMain/— no Android imports in commonMain. - Platform-specific code in
shared/androidMain/platform/. - Use
@Serializabledata classes withJson { ignoreUnknownKeys = true }(API has no versioning). - SSE
logeventdatafield is base64-encoded — decode before display. - Track
eventId/seqfor deploy log resume (?since=<seq>on reconnect). - Don't hold MCP Client or SSE streams across backgrounding — reconnect on foreground.
- Monitoring SSE 404s in CLOUD_MODE — hide monitor tab for cloud instances.
- Use Ktor SSE plugin (NOT EventSource — can't set Authorization headers).
- Add dependencies to
gradle/libs.versions.tomlfirst, then reference in build.gradle.kts.
API Endpoints (Base: {instanceUrl})
GET /api/health/env— discovery, public, returns authModeGET /api/projects/home— list projects, PAT auth, tagproject:listGET /api/deployments/:id/stream— SSE build logs, PAT auth,?since=<seq>for replayGET /api/system/monitor/stream?serverId=<id>— SSE server metrics, PAT auth, 3s interval
Auth
- PAT:
Authorization: Bearer opsh_pat_<43-char base64url> - Modes: none (loopback), local (better-auth), cloud (PKCE OAuth)
- Store in EncryptedSharedPreferences (Android Keystore)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 51 lines · 682 tokens per session scan A 57edb2f7cd77
cursorrules is a cursor rule published in the GitHub repository kareemessam09/Openship-App (11 stars, last pushed 7d ago), licensed Apache-2.0. It adds 682 tokens to every session, about $0.0034 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
app_rules
This document outlines the essential rules and guidelines for developing with the MobileLauncher LT boilerplate. Follow these rules to maintain consistency, scalability, and code quality across the project.
android-viewmodel
Android ViewModel conventions — StateFlow, repository abstraction, coroutines, no LiveData.
android_clean_architecture
Enforce clean architecture principles in Android projects.
android-networking-retrofit-okhttp
Build Android networking stacks with Retrofit, OkHttp, interceptors, API contracts, and resilient error handling.
swift-development
Swift development: SwiftUI, Combine, async/await, iOS patterns, and Apple platform conventions.
flutter_architecture_overview
High-level overview of the Flutter project architecture, directory structure, file naming conventions, and decision checklists. Use this to understand where code belongs.