Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/modiqo/cliare/cliare-artifact-reviewgit clone --depth 1 https://github.com/modiqo/cliareWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00016 | $0.00634 |
| Opus 5 | $0.00008 | $0.00317 |
| Sonnet 5 | $0.00003 | $0.00127 |
| Haiku 4.5 | $0.00002 | $0.00063 |
Grade A, and why
cliare-artifact-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
CLIARE Artifact Review
Use this rule when reviewing a CLIARE artifact directory containing scorecard.json, issues.json, shape.json, and evidence.jsonl. If artifact-map.json is present, read it first. If it is missing and CLIARE is available, generate it with cliare describe <artifact-dir> --write.
Start with persona tables, not raw JSON dumps. For persona-level review, read persona-<persona>.md first, then use persona-<persona>.json and issues.json only for drill-down.
Prefer jq with explicit file paths. Do not use Python, cd, shell redirection, heredocs, or compound shell commands for routine artifact inspection.
Use this order:
- Read
artifact-map.jsonfor folder kind, health, missing required artifacts, and navigation order. - Read posture from
scorecard.json. - Generate missing persona artifacts with
cliare report <persona> --out <artifact-dir> --write. - Show a concise table of priority issues: priority, severity, category, confidence, affected count, issue id/title, and persona action.
- Ask which row to drill into unless the user already named an issue.
- For drill-down, show what the issue means, where it appears, evidence ids, how to address it, and how to verify the fix.
Large issue lists:
- Count affected commands by runtime state first.
- If the user asks for all commands, list compactly from
issues.json. - Do not infer false positives, root causes, or design intent from command names.
- Use artifact states only:
runtime_confirmed,precondition_blocked,unconfirmed, andnot_in_shape_catalog.
Useful queries:
jq '{kind:.artifact_kind,health:.health,navigation:.navigation,missing_required:.missing_required,summaries:.summaries}' <artifact-dir>/artifact-map.json
jq '{score:.score.total,status:.score.status,coverage:{commands_discovered:.coverage.commands_discovered,commands_runtime_confirmed:.coverage.commands_runtime_confirmed,traversal_complete:.coverage.traversal_complete,budget_exhausted:.coverage.budget_exhausted,observed_max_depth:.coverage.observed_max_depth,max_depth:.coverage.max_depth,probes_completed:.coverage.probes_completed,max_probes:.coverage.max_probes}}' <artifact-dir>/scorecard.json
jq '.summary, [.issues[] | {id,severity,category,confidence,title,affected:(.affected_commands|length)}]' <artifact-dir>/issues.json
jq --arg id "issue.help_unavailable" '[.issues[] | select(.id==$id) | .affected_commands[]] | group_by(.state) | map({state:.[0].state,count:length})' <artifact-dir>/issues.json
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 47 lines · 16 tokens per session scan A e36d23ed5a95
cliare-artifact-review is a cursor rule published in the GitHub repository modiqo/cliare (487 stars, last pushed 1mo ago), licensed Apache-2.0. It adds 16 tokens to every session and 634 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
cli-error-handling
CLI command error handling patterns.
prefer-direct-imports-over-module-mocks
Prefer extracting a testable core over vi.mock / vi.resetModules when unit tests need to reach production logic entangled with config, env, or singletons.
control-plane-descriptors
Control plane descriptor and instance implementation patterns.
family-instance-domain-actions
Family instance domain action implementation patterns.