agent

A compact set of rules for an autonomous coding agent, including session notes, safety checks, file mapping, and a small-change policy.

In plain words
What is it for?
Use it to guide coding sessions that rely on shell hooks, a NOW.md work file, security rules, and documented toolchain checks.
Why use it?
It tells the agent when to read or write files, how to handle secrets and risky commands, and what evidence counts as finished work.

Cursor rule

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/kleosr/kleosrules/agent
Clone the repo
git clone --depth 1 https://github.com/kleosr/kleosrules
Per session 651 This file is loaded in full into every session.
When invoked 651 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00651 $0.00651
Opus 5 $0.00326 $0.00326
Sonnet 5 $0.00130 $0.00130
Haiku 4.5 $0.00065 $0.00065

Measured yesterday against content hash 2b020b3e9865, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

agent scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

shared/rules/agent.mdc · 50 lines

How it starts

The opening of the file, as written. The whole thing — 50 lines — stays where its author put it; the contents beside it link to each section on GitHub.

AGENT CAPSULE

Bash hooks + local NOW.md. One model per conversation. Read NOW.md for multi-session work. Prefer NO CODE. Smallest Diff. Zero prose comments. Start: read NOW.md. Stop with tools: update NOW.md. Git only when asked. Secrets never in code or chat. Security: SECURITY.md. Done = docs/TOOLCHAIN.md green with evidence. Never fight a deny. Never reintroduce Rust kleos-gate or pack Python.

Harness (four registered events)

Event Script Job
sessionStart session_start.sh additional_context: NOW.md active sections. Quiet in plan mode.
beforeSubmitPrompt before_submit_prompt.sh Secret/token in prompt → continue: false. Else continue: true.
beforeShellExecution before_shell.sh Destructive / source-write deny. Secret path in command deny. Complexity-lint disable deny. Infra/DB ask.
beforeReadFile before_read_file.sh Secret paths deny (failClosed: true).

Cursor documents 21 hook events. This pack registers the four above. There is no stop, postToolUse, preToolUse, beforeMCPExecution, or LOC gate in hooks.json or on disk. Writes are not blocked by file size. Closing a turn does not follow up.

Brain = NOW.md. Local install only (~/.cursor). Skills on demand (Read SKILL.md or /name). Hooks never inject .mdc. This pack does not register preToolUse, so it never emits updated_input (Cursor only consumes that field there). Review specialists: hunter, cut, prove.

Before you write

Read this codebase first. Do not invent paths. Then, in one or two normal sentences, say what will be true when you stop, which files you will change, and how you will prove it. Never declare that via Shell, Write, or a code fence.

File map

Change only files you actually opened. Finish them this turn. No drip, no orphan files. Before you claim done: cite green bash tests/run.sh / scripts/doctor.sh / package test.

State

NOW.md is durable. /state/ is ephemeral (mode from sessionStart). Law: docs/ARCHITECTURE.md + docs/CURATOR.md + SECURITY.md.

Read the full file on GitHub · 50 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 50 lines · 651 tokens per session scan A 2b020b3e9865

Subscribe to this mod's changes

agent is a cursor rule published in the GitHub repository kleosr/kleosrules (2 stars, last pushed 2d ago), licensed MIT. It adds 651 tokens to every session, about $0.0033 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.