engineering-workflow

A six-stage engineering workflow for moving from an idea to shipped software through definition, planning, implementation, testing, review, and release.

In plain words
What is it for?
Use it to structure project work across specification, planning, building, verification, review, and shipping, with explicit roles and quality gates at each stage.
Why use it?
It provides checkpoints before and after coding so requirements, design, tests, quality checks, and release readiness are handled systematically.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/kok-o/koko-contextos-agents/engineering-workflow
Clone the repo
git clone --depth 1 https://github.com/kok-o/koko-contextos-agents

Made for: Cursor.

Per session 2,728 This file is loaded in full into every session.
When invoked 2,728 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.02728 $0.02728
Opus 5 $0.01364 $0.01364
Sonnet 5 $0.00546 $0.00546
Haiku 4.5 $0.00273 $0.00273

Measured 2d ago against content hash 51902f94c964, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

engineering-workflow scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/engineering-workflow.mdc · 339 lines

How it starts

The opening of the file, as written. The whole thing — 339 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Skill: engineering-workflow

engineering-workflow

Overview

Systematic 6-phase engineering pipeline (DEFINE → PLAN → BUILD → VERIFY → REVIEW → SHIP) enforcing role declarations, atomic task execution, quality gates, and regression prevention.

When to Use

Activate on all project tasks to orchestrate structured development, spec definition, architectural planning, and verification gates.

Rules & Patterns

Inspired by addyosmani/agent-skills by Addy Osmani (Google Chrome).

Core Principle

A junior writes code immediately. A senior writes a spec first.
You are a senior. You never write code until the spec and plan are approved.


The 6-Phase Development Pipeline

  DEFINE          PLAN           BUILD          VERIFY         REVIEW          SHIP
 ┌──────┐      ┌──────┐      ┌──────┐      ┌──────┐      ┌──────┐      ┌──────┐
 │ Idea │ ───▶ │ Spec │ ───▶ │ Code │ ───▶ │ Test │ ───▶ │  QA  │ ───▶ │  Go  │
 │Refine│      │  PRD │      │ Impl │      │Debug │      │ Gate │      │ Live │
 └──────┘      └──────┘      └──────┘      └──────┘      └──────┘      └──────┘
   /spec          /plan          /build        /test         /review       /ship

[ROLE: Product Manager]  [ROLE: Architect]  [ROLE: Senior Dev]  [ROLE: QA Lead]  [ROLE: Staff Eng]  [ROLE: Release Eng]

IRON RULE: In interactive development, no phase can be skipped and no code is written before /plan is approved. Direct Build Exception: When the prompt/caller explicitly requests a standalone implementation, or declares [PHASE: Build], execute the BUILD phase directly and deliver the complete, self-contained production code without conversational pauses.


Phase 1: DEFINE — /spec

Auto-activates → [ROLE: Product Manager]

Turn vague intent into a precise, executable specification.

Spec Template

## Feature Spec: [Feature Name]

### Why (Problem)
[What pain does this solve? Who has it? How often?]

### Scope (What's In / Out)
### 
- [Specific thing 1]
- [Specific thing 2]

### 
- [Thing we're NOT doing and why]

### Technical Approach
[Read the relevant code. Understand what changes where.]
Files affected:
- `src/X.js` — [what changes]
- `src/Y.js` — [what changes]

### Acceptance Criteria
- [ ] Given [context], when [action], then [result]
- [ ] Given [context], when [action], then [result]

### Open Questions
- [Unresolved decision 1]
- [Unresolved decision 2]

Read the full file on GitHub · 339 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 339 lines · 2,728 tokens per session scan A 51902f94c964

Subscribe to this mod's changes

engineering-workflow is a cursor rule published in the GitHub repository kok-o/koko-contextos-agents (2 stars, last pushed 3d ago), licensed MIT. It adds 2,728 tokens to every session, about $0.0136 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other cursor rules, from other repositories

clean-code

Apply language-agnostic clean-code discipline to all code writing, editing, reviewing, testing, and refactoring, including file placement, single responsibility, and verified completion.

btseee/clean-code-skills · 1,307 tokens

unity-performance

Cursor rule "unity-performance" from Common-ka/ai-agent-unity-rules, covering unity performance rules, update/fixedupdate/lateupdate, usage rules, object pooling (unityengine.pool) and addressables (not resources).

Common-ka/ai-agent-unity-rules · 2 tokens

react-composition-patterns

React composition patterns for scalable component architecture including compound components, context providers, state management, boolean prop alternatives, render props vs children, and React 19 API changes. Use when refactoring components with many boolean props, building component libraries, designing flexible…

alonsarias/agent-rules · 0 tokens

react-advanced-patterns

Advanced React patterns for refs, stable callbacks, useEffectEvent, and application initialization. Use when dealing with event handler refs, stable callback references, subscription management, effect dependencies, or one-time app initialization.

alonsarias/agent-rules · 0 tokens

general-typescript-rule

Applies general TypeScript best practices and style guidelines to all TypeScript files in the project.

yujiosaka/knowhub · 0 tokens

readme-best-practices

README Best Practices - enforces high-quality README patterns when creating or editing README files.

ofershap/readme-best-practices · 276 tokens