Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/mbanderas/maestro/cursorrulesgit clone --depth 1 https://github.com/mbanderas/maestroWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.02195 | $0.02195 |
| Opus 5 | $0.01097 | $0.01097 |
| Sonnet 5 | $0.00439 | $0.00439 |
| Haiku 4.5 | $0.00219 | $0.00219 |
Grade A, and why
cursorrules scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 213 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Maestro -- Orchestration Kernel (Cursor)
Optional discipline layer for AI coding agents, independent of Maestro Frontier. Self-contained copy for Cursor, which does not support file imports; the full multi-agent protocol lives in docs/orchestration.md and is read on demand. Section numbers S0-S10 are stable identifiers.
Read these as calibrated defaults, not rigid laws: apply judgment and scale them to the task in front of you — every task differs. Lead with the work, not the process; the S1 orchestration decision is a quick checkpoint just before your first edit, never your opening move. A rule that plainly does not fit a task yields to doing the task well — say so and proceed. The few hard invariants are narrow: verification honesty (S7.3), surgical scope (S7.4), and compression integrity (S8).
0. Quality Standard [ALWAYS]
Do the whole thing, do it right, with tests and docs scaled to the change. Search before building; test before shipping. Bar: genuinely done. Applies within requested scope.
1. Decision Gate [ALWAYS]
Engage the task first — read the request, orient on the files it names. The gate is the checkpoint immediately before your first file edit, not your opening move: by then you know the real file count. Don't open a task with "split or not?" — that attention belongs on the work.
At that checkpoint, output one verdict line —
Maestro · frontier <on|off> — files=<n> concerns=<m> -> single-agent — <reason> or
Maestro · frontier <on|off> — files=<n> concerns=<m> -> multi-agent — <trigger met>.
files = every file the task will create or modify; concerns =
distinct areas touched (commands, core, config, docs, tests). For
obviously single-agent work the verdict is a one-line reflex — emit
it and proceed. No edits before the verdict. The frontier <on|off> badge states the
engine state — frontier on (<mode>/<preset-or-model>) when armed,
else frontier off; on Claude Code the gate-reminder hook injects
the current value.
Multi-agent triggers (ANY true — check FIRST): 5+ files across 2+ concerns, independent subtasks, >15 messages single-agent, adversarial review needed, multiple skill domains. files>=5 across 2+ concerns is multi-agent by count — independent subtasks ARE the parallel benefit. A met trigger downgrades ONLY on: >60% file overlap between subtasks, or <=3 files total in one dependency chain. Nothing else.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 213 lines · 2,195 tokens per session scan A 78c2741d8e47
cursorrules is a cursor rule published in the GitHub repository mbanderas/maestro (5 stars, last pushed 5d ago), licensed MIT. It adds 2,195 tokens to every session, about $0.0110 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
cursor
You are working on the checkout service. Preserve transaction integrity and auditability.
architecture-constraints
GolemBot architecture hard constraints — must check before modifying any src/ code.
beanstalk-deploy
Robust deployment patterns for Elastic Beanstalk with GitHub Actions, Pulumi, and edge case handling.
creating-kiro-agents
Kiro agent configuration patterns, JSON structure, tool permissions, and security best practices for creating specialized AI development assistants.
archcore-files
Enforce MCP-only operations when working with .archcore/ files.
test-plan
Plan Katalon True Platform/TestOps testing for a release, sprint, or feature. Use when you need to translate quality goals into scope, prioritize testing by requirement coverage and risk, decide what to test first, or build the executable plan structure (folders, suites, and sprint/release association) that stands in…