Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/kyungseo/ai-workflow-harness/java-springgit clone --depth 1 https://github.com/kyungseo/ai-workflow-harnessWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00411 |
| Opus 5 | $0.00000 | $0.00205 |
| Sonnet 5 | $0.00000 | $0.00082 |
| Haiku 4.5 | $0.00000 | $0.00041 |
Grade A, and why
java-spring scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Optional Spring Boot Example Rules
These rules are not part of the generic AI Workflow Harness core. They are kept as an optional example/profile surface for projects that adopt the harness with Spring Boot backend code.
MUST:
- Follow the Java and Spring conventions already present in the adopted project.
- Keep package names aligned with the adopted project's namespace.
- Use the adopted project's declared build tool and verification commands.
- Use MyBatis
#{}parameters. Use${}only with whitelist validation and an explanatory comment. - Use Lombok intentionally: prefer
@Getter,@Builder,@RequiredArgsConstructor, and@Slf4j; do not use@Data. - Keep annotation processor order consistent with the adopted project.
- Keep shared exception and response handling in the adopted project's established shared module.
NEVER:
- Add service-specific domain logic to
common-core. - Add default secret values for
JWT_SECRET,DB_PASSWORD, or similar sensitive settings. - Log full tokens, passwords, or
Authorizationheader values.
Comments
MUST:
- Add class-level Javadoc only for: architecture boundaries, security-sensitive logic, complex state. Skip for DTOs, mappers, and standard CRUD controllers.
- Use
// Korean reason — English technical termfor inline comments. Explain WHY, not WHAT. - Let
@Operation,@Schema, and@DisplayNameserve as documentation in their contexts.
NEVER:
- Add comments that repeat what the code already expresses.
- Add file headers (no-header policy; LICENSE file covers the project).
Full reference: docs/HARNESS-MAINTAINER-GUIDE.md
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 44 lines · 0 tokens per session scan A 4013ff651b4c
java-spring is a cursor rule published in the GitHub repository kyungseo/ai-workflow-harness (13 stars, last pushed 1mo ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 411 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
language-agnostic-patterns
Language-agnostic programming patterns: SOLID, design patterns, clean code, and architecture. Load when refactoring, designing abstractions, or reviewing structure — not for everyday syntax.
cursor-tools-mastery
Cursor 3.7 runtime guide: choose the right tool, canvases, Design Mode, /worktree, /best-of-n, Await, and parallel execution where safe.
fable5-coding-craft
Fable 5 coding craft: locate-before-write, root-cause method, simplicity taste, error-handling philosophy, test integrity, refactoring discipline, and counters to common LLM coding failure modes. Load when writing, refactoring, debugging, or reviewing non-trivial code in any language.
cursor-agent-orchestration
Cursor 3.7 orchestration guide: when to plan, when to delegate, nested subagents, multi-environment handoffs, /best-of-n, and Await for long-running branches.
fable5-reasoning
Fable 5 reasoning protocols: task interpretation, risk-first decomposition, approach selection, interleaved thinking, hypothesis ledgers, premortems, calibration, and the stuck-strategy ladder. Load for complex, ambiguous, or long-horizon tasks, for debugging strategy, or whenever progress stalls.
cursor-mcp-optimization
Cursor 3.7 MCP optimization: browser Design Mode, canvases, Figma, Cloudflare tools, MCP Apps structured content, and direct action patterns.