Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/kok-o/koko-contextos-agents/engineering-workflowgit clone --depth 1 https://github.com/kok-o/koko-contextos-agentsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.02728 | $0.02728 |
| Opus 5 | $0.01364 | $0.01364 |
| Sonnet 5 | $0.00546 | $0.00546 |
| Haiku 4.5 | $0.00273 | $0.00273 |
Grade A, and why
engineering-workflow scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 339 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Skill: engineering-workflow
engineering-workflow
Overview
Systematic 6-phase engineering pipeline (DEFINE → PLAN → BUILD → VERIFY → REVIEW → SHIP) enforcing role declarations, atomic task execution, quality gates, and regression prevention.
When to Use
Activate on all project tasks to orchestrate structured development, spec definition, architectural planning, and verification gates.
Rules & Patterns
Inspired by addyosmani/agent-skills by Addy Osmani (Google Chrome).
Core Principle
A junior writes code immediately. A senior writes a spec first.
You are a senior. You never write code until the spec and plan are approved.
The 6-Phase Development Pipeline
DEFINE PLAN BUILD VERIFY REVIEW SHIP
┌──────┐ ┌──────┐ ┌──────┐ ┌──────┐ ┌──────┐ ┌──────┐
│ Idea │ ───▶ │ Spec │ ───▶ │ Code │ ───▶ │ Test │ ───▶ │ QA │ ───▶ │ Go │
│Refine│ │ PRD │ │ Impl │ │Debug │ │ Gate │ │ Live │
└──────┘ └──────┘ └──────┘ └──────┘ └──────┘ └──────┘
/spec /plan /build /test /review /ship
[ROLE: Product Manager] [ROLE: Architect] [ROLE: Senior Dev] [ROLE: QA Lead] [ROLE: Staff Eng] [ROLE: Release Eng]
IRON RULE: In interactive development, no phase can be skipped and no code is written before /plan is approved.
Direct Build Exception: When the prompt/caller explicitly requests a standalone implementation, or declares [PHASE: Build], execute the BUILD phase directly and deliver the complete, self-contained production code without conversational pauses.
Phase 1: DEFINE — /spec
Auto-activates → [ROLE: Product Manager]
Turn vague intent into a precise, executable specification.
Spec Template
## Feature Spec: [Feature Name]
### Why (Problem)
[What pain does this solve? Who has it? How often?]
### Scope (What's In / Out)
###
- [Specific thing 1]
- [Specific thing 2]
###
- [Thing we're NOT doing and why]
### Technical Approach
[Read the relevant code. Understand what changes where.]
Files affected:
- `src/X.js` — [what changes]
- `src/Y.js` — [what changes]
### Acceptance Criteria
- [ ] Given [context], when [action], then [result]
- [ ] Given [context], when [action], then [result]
### Open Questions
- [Unresolved decision 1]
- [Unresolved decision 2]
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 339 lines · 2,728 tokens per session scan A 51902f94c964
engineering-workflow is a cursor rule published in the GitHub repository kok-o/koko-contextos-agents (2 stars, last pushed 3d ago), licensed MIT. It adds 2,728 tokens to every session, about $0.0136 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
clean-code
Apply language-agnostic clean-code discipline to all code writing, editing, reviewing, testing, and refactoring, including file placement, single responsibility, and verified completion.
unity-performance
Cursor rule "unity-performance" from Common-ka/ai-agent-unity-rules, covering unity performance rules, update/fixedupdate/lateupdate, usage rules, object pooling (unityengine.pool) and addressables (not resources).
react-composition-patterns
React composition patterns for scalable component architecture including compound components, context providers, state management, boolean prop alternatives, render props vs children, and React 19 API changes. Use when refactoring components with many boolean props, building component libraries, designing flexible…
react-advanced-patterns
Advanced React patterns for refs, stable callbacks, useEffectEvent, and application initialization. Use when dealing with event handler refs, stable callback references, subscription management, effect dependencies, or one-time app initialization.
general-typescript-rule
Applies general TypeScript best practices and style guidelines to all TypeScript files in the project.
readme-best-practices
README Best Practices - enforces high-quality README patterns when creating or editing README files.