Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/kleosr/kleosrules/agentgit clone --depth 1 https://github.com/kleosr/kleosrulesWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00651 | $0.00651 |
| Opus 5 | $0.00326 | $0.00326 |
| Sonnet 5 | $0.00130 | $0.00130 |
| Haiku 4.5 | $0.00065 | $0.00065 |
Grade A, and why
agent scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 50 lines — stays where its author put it; the contents beside it link to each section on GitHub.
AGENT CAPSULE
Bash hooks + local NOW.md. One model per conversation.
Read NOW.md for multi-session work. Prefer NO CODE. Smallest Diff. Zero prose comments.
Start: read NOW.md. Stop with tools: update NOW.md.
Git only when asked. Secrets never in code or chat. Security: SECURITY.md.
Done = docs/TOOLCHAIN.md green with evidence.
Never fight a deny. Never reintroduce Rust kleos-gate or pack Python.
Harness (four registered events)
| Event | Script | Job |
|---|---|---|
| sessionStart | session_start.sh |
additional_context: NOW.md active sections. Quiet in plan mode. |
| beforeSubmitPrompt | before_submit_prompt.sh |
Secret/token in prompt → continue: false. Else continue: true. |
| beforeShellExecution | before_shell.sh |
Destructive / source-write deny. Secret path in command deny. Complexity-lint disable deny. Infra/DB ask. |
| beforeReadFile | before_read_file.sh |
Secret paths deny (failClosed: true). |
Cursor documents 21 hook events. This pack registers the four above. There is no stop, postToolUse, preToolUse, beforeMCPExecution, or LOC gate in hooks.json or on disk. Writes are not blocked by file size. Closing a turn does not follow up.
Brain = NOW.md. Local install only (~/.cursor). Skills on demand (Read SKILL.md or /name). Hooks never inject .mdc. This pack does not register preToolUse, so it never emits updated_input (Cursor only consumes that field there). Review specialists: hunter, cut, prove.
Before you write
Read this codebase first. Do not invent paths. Then, in one or two normal sentences, say what will be true when you stop, which files you will change, and how you will prove it. Never declare that via Shell, Write, or a code fence.
File map
Change only files you actually opened. Finish them this turn. No drip, no orphan files.
Before you claim done: cite green bash tests/run.sh / scripts/doctor.sh / package test.
State
NOW.md is durable. /state/ is ephemeral (mode from sessionStart). Law: docs/ARCHITECTURE.md + docs/CURATOR.md + SECURITY.md.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 50 lines · 651 tokens per session scan A 2b020b3e9865
agent is a cursor rule published in the GitHub repository kleosr/kleosrules (2 stars, last pushed 2d ago), licensed MIT. It adds 651 tokens to every session, about $0.0033 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
nextjs
Rules for Next.js projects (App Router and Pages Router).
java-kotlin
Rules applied when working in Java or Kotlin files (incl. Android).
php
Rules applied when working in PHP files (incl. Laravel, Symfony, WordPress).
vue
Rules for Vue (2 and 3) single-file components.
cursorrules
40 lines, or explicitly requested.
shell
Rules for shell scripts (bash, zsh, sh, PowerShell).