ai-usage-policy

ai-usage-policy is a cursor rule for Cursor from mohitagw15856/pm-claude-skills. It costs 112 tokens per session (1,326 once invoked), scanned A, original, MIT.

A practical company policy for using AI tools at work. It covers which tools are allowed, what data may be shared, when AI use should be disclosed, and what people must review.

In plain words
What is it for?
Use it to write acceptable-use rules for tools such as ChatGPT, Claude, or Copilot, including data handling, approval, disclosure, and review requirements.
Why use it?
It replaces vague rules or blanket bans with guidance people can apply when deciding whether to put workplace information into an AI service.

Cursor rule for Cursor

Written for Cursor: a Cursor rule (.mdc).

Good fit Use it to write acceptable-use rules for tools such as ChatGPT, Claude, or Copilot, including data handling, approval, disclosure, and review requirements.

Compare 6 cursor rules from other repositories ↓
Install with agentmods
npx agentmods add rules/mohitagw15856/pm-claude-skills/ai-usage-policy
About the project

PM Skills is a collection of plain-Markdown instructions that teach AI assistants structured methods for handling professional, personal, and life-admin tasks. People use it with Claude, ChatGPT, Gemini, Cursor, Codex, and other supported agents for work such as writing product requirements, reviewing documents, or planning difficult situations.

mohitagw15856/pm-claude-skills · 1,357 stars · on GitHub · mohitagw15856.github.io

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Clone the repo
git clone --depth 1 https://github.com/mohitagw15856/pm-claude-skills

Made for: Cursor.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for ai-usage-policy

README.md
[![agentmods](https://agentmods.dev/badge/rules/mohitagw15856/pm-claude-skills/ai-usage-policy/github.svg)](https://agentmods.dev/rules/mohitagw15856/pm-claude-skills/ai-usage-policy)
Your own site
<a href="https://agentmods.dev/rules/mohitagw15856/pm-claude-skills/ai-usage-policy"><img src="https://agentmods.dev/badge/rules/mohitagw15856/pm-claude-skills/ai-usage-policy/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for ai-usage-policy

Your own site · 80×15
<a href="https://agentmods.dev/rules/mohitagw15856/pm-claude-skills/ai-usage-policy"><img src="https://agentmods.dev/badge/rules/mohitagw15856/pm-claude-skills/ai-usage-policy.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 112 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,326 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00112 $0.01326
Opus 5 $0.00056 $0.00663
Sonnet 5 $0.00022 $0.00265
Haiku 4.5 $0.00011 $0.00133

Measured 9d ago against content hash 4259f1e3c3f0, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

ai-usage-policy scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

exports/cursor/pm-aiwork/ai-usage-policy/ai-usage-policy.mdc · 75 lines

How it starts

The opening of the file, as written. The whole thing — 75 lines — stays where its author put it; the contents beside it link to each section on GitHub.

AI Usage Policy Skill

Most corporate AI policies fail in one of two ways: a fearful ban everyone quietly ignores (shadow AI, zero visibility), or legal fog nobody can apply to the question they actually have — "can I paste this customer email into Claude?" This skill writes the policy as a decision aid: one page, answerable in the moment of use, with the reasoning logged separately for counsel.

What This Skill Produces

  • A one-page policy: approved tools, the data traffic-light, disclosure duties, review obligations, and how to get a tool approved
  • A decision log: the reasoning behind each rule, for legal/leadership review
  • A rollout note: how the policy lands without becoming shelfware

Required Inputs

Ask for (if not already provided):

  • The org: size, industry, regulatory exposure (health, finance, gov contracts change the answers)
  • Current reality: which AI tools are already in use — officially and (honestly) unofficially
  • Data landscape: what sensitive classes exist (customer PII, PHI, source code, financials, client-confidential)
  • Enterprise agreements in place: which tools have zero-retention/no-training terms signed vs consumer accounts
  • Risk appetite: enable-with-guardrails or restrict-hard? (Get the sponsor's one-word answer.)

Policy Method

  1. Legalise reality first. Shadow AI is the largest risk created by strict policies. Start from what people already use; the policy's first job is making the sanctioned path easier than the unsanctioned one — approved tools with enterprise terms, clearly listed, with a fast approval lane for new ones (named owner, ≤2-week SLA).
  2. Rule on data, not tools. Tools churn monthly; data classes don't. The core artifact is a traffic-light table people can apply in three seconds:
    • 🟢 Fine in approved tools — public info, your own drafts, non-confidential work product
    • 🟡 Approved tools with enterprise terms only — internal business data, code, unreleased plans
    • 🔴 Never in any AI tool (until a named exception is granted) — regulated data (PHI, card data), client-confidential under NDA, credentials, anything under legal hold Each row names examples from this org's actual work, not abstract categories.
  3. Set the accountability rule once, clearly. The human who ships it owns it — AI-assisted or not. From that root, the review duties follow: outputs going to customers/public/regulators get human review by someone competent to catch the errors; internal drafts don't need ceremony. State both halves; policies that demand review-everything get review-nothing.
  4. Decide disclosure deliberately. Internal: generally not required (it's a tool). External: disclose where the audience would feel deceived otherwise (bylined content, legal filings, anything presented as human judgment — expert reports, references) or where law/regulator requires it. Write the specific disclosure lines for this org's cases, not a principle.
  5. Keep the enforcement honest. First violations of 🟡 rules are coaching moments; 🔴 violations follow the existing data-handling discipline process (don't invent a parallel one). The policy names its owner, its review cadence (quarterly — the landscape moves), and where questions go today.
  6. Log the reasoning separately. Every rule gets one line in the decision log: what we ruled, why, what we considered. Counsel reviews the log; humans read the page.

Read the full file on GitHub · 75 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 75 lines · 112 tokens per session scan A 4259f1e3c3f0

Subscribe to this mod's changes

ai-usage-policy is a cursor rule published in the GitHub repository mohitagw15856/pm-claude-skills (1,357 stars, last pushed yesterday), licensed MIT. It adds 112 tokens to every session and 1,326 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.