cursorrules

Project rules for Python and JavaScript work that tell the coding agent to use envoic, a tool for finding and managing development environments and build files.

In plain words
What is it for?
Keeping virtual environments, JavaScript dependencies, and generated files organised while protecting lock files and project manifests.
Why use it?
They provide a consistent cleanup process and safety checks, such as scanning before deletion and previewing changes first.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/mahimailabs/envoic/cursorrules
Clone the repo
git clone --depth 1 https://github.com/mahimailabs/envoic

Made for: Cursor.

Per session 311 This file is loaded in full into every session.
When invoked 311 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00311 $0.00311
Opus 5 $0.00156 $0.00156
Sonnet 5 $0.00062 $0.00062
Haiku 4.5 $0.00031 $0.00031

Measured 2d ago against content hash 72c186185e52, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

cursorrules scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursorrules · 34 lines

What it actually says

Generated from skills/envoic/templates/cursor.cursorrules

Source of truth: skills/envoic/SKILL.md

envoic - Environment Scanner

When working on Python or JavaScript projects, use envoic to manage development environments and artifacts.

Quick Reference

uvx envoic scan .              # Python: discover .venv, conda, artifacts
uvx envoic scan . --deep       # include sizes
uvx envoic manage .            # interactive delete
uvx envoic info .venv          # health check single env
uvx envoic clean . --dry-run   # preview stale cleanup

npx envoic scan .              # JS: discover node_modules, artifacts
npx envoic manage .            # interactive delete
npx envoic info node_modules   # package manager, largest deps

Safety

  • Always run a scan before delete actions.
  • Prefer --dry-run before actual deletion.
  • Never delete lock files.
  • CAREFUL tier: .tox/, .nox/, *.egg-info - warn before deleting.
  • Use --json for programmatic parsing.

Canonical Skill Files

  • Full workflow: skills/envoic/SKILL.md
  • Command catalog: skills/envoic/references/commands.md
  • Safety guide: skills/envoic/references/safety.md
  • Troubleshooting: skills/envoic/references/troubleshooting.md
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 34 lines · 311 tokens per session scan A 72c186185e52

Subscribe to this mod's changes

cursorrules is a cursor rule published in the GitHub repository mahimailabs/envoic (5 stars, last pushed 1mo ago), licensed MIT. It adds 311 tokens to every session, about $0.0016 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.