Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/lukinov/ai-form-builder/formenginegit clone --depth 1 https://github.com/lukinov/ai-form-builderWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.01701 |
| Opus 5 | $0.00000 | $0.00851 |
| Sonnet 5 | $0.00000 | $0.00340 |
| Haiku 4.5 | $0.00000 | $0.00170 |
Grade A, and why
formengine scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 162 lines — stays where its author put it; the contents beside it link to each section on GitHub.
FormEngine — AI Form Builder
You generate FormEngine JSON schemas plus runnable React code. Default
target is FormEngine Core (MIT, free) via
@react-form-builder/core + @react-form-builder/components-rsuite.
What you produce — every time
form.json— a normalized FormEngine schema, validated against the real list of component types from the target UI library.App.tsx— a runnable React file that imports the schema and renders it throughFormViewer.- A short validation report (Screen root, unique keys, layout-only
css, no smuggled HTML markup, valid validation rule keys). - Install command + a link to the Online FormBuilder so the user can tweak visually.
Hard rules — never violate
Schema invariants
- Root is
type: "Screen"(NOT"Form"). - Every component node has
key(unique within the tree),type(must exist in the chosen library), and usuallyprops. - Every prop value is wrapped:
"label": { "value": "Email" }— never"label": "Email". - Validations live under
schema.validationson the field component that owns the data — never on the Screen root. - Use the correct tooltip/error types:
- RSuite:
RsTooltip/RsErrorMessage - MUI:
MuiTooltip/MuiErrorWrapper - Mantine:
MtTooltip/MtErrorWrapper
- RSuite:
Layout vs. styling
cssandwrapperCssare layout-only — flex, grid, box-model, margin, padding, gap, width/height, alignment. Never color, font, background, border, shadow, radius, opacity, transform.- Visual styling belongs in the UI library's theme provider in
App.tsx(<CustomProvider>/<ThemeProvider>/<MantineProvider>). - The legacy
stylefield is forbidden — usecss/wrapperCss. - The shape is
{ "any": { "object": { "<layout-key>": "<value>" } } }, never a plain CSS string. - No companion
.cssfile alongsideApp.tsx. No rootclassName. No<style>blocks. Nostyled-components.
Plain-text strings only
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 162 lines · 0 tokens per session scan A f591e79df8df
formengine is a cursor rule published in the GitHub repository lukinov/ai-form-builder (2 stars, last pushed 4mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 1,701 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
shopify-theme-builder
Build production-grade Online Store 2.0 Shopify themes (interview-first, 100% theme-editor controllable, token-driven, theme-check clean, bilingual/RTL). Apply when building, generating, scaffolding, or designing a Shopify theme, sections, JSON templates, or Liquid.
main
GhostSwap Partners API integration conventions (auth, idempotency, polling, error handling). Apply when working on swap, exchange, quote, or crypto-conversion code.
qapla-api
Integrate with or answer questions about the Qapla' shipping & tracking REST API (public v1.3). Use this when working with Qapla' to push shipments or raw orders, generate and confirm carrier labels, track parcels, get real-time multi-carrier quotes, look up pickup points (PUDO), verify addresses, list couriers and…
00-kit-authoring
Kit-authoring rules for the @commerce-atoms/agents repo. Distinguishes root (npm package) from kit/ (shipped product). Always-on.
30-architecture-boundaries
Module boundaries, shared folder policies, route/view split. See rules/core/architecture.md.
00-agents-md
Universal AGENTS.md is the canonical source. Read it first.