Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/nickcirv/engram/cursorrulesgit clone --depth 1 https://github.com/NickCirv/engramWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00946 | $0.00946 |
| Opus 5 | $0.00473 | $0.00473 |
| Sonnet 5 | $0.00189 | $0.00189 |
| Haiku 4.5 | $0.00095 | $0.00095 |
Grade A, and why
cursorrules scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- cursorrules — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 56 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Codebase Structure (auto-generated by engram)
Graph: 451 nodes, 1005 edges | 96% extracted, 4% inferred View: general
Core entities
extractDirectory()(function, 2 connections) — src/miners/ast-miner.tsextractFile()(function, 2 connections) — src/miners/ast-miner.tsgenerateSummary()(function, 2 connections) — src/autogen.tswriteToFile()(function, 2 connections) — src/autogen.tsparseReadLikeBashCommand()(function, 2 connections) — src/intercept/handlers/bash.tscreateAuthService()(function, 2 connections) — tests/intercept/handlers/bash.test.tshashPassword()(function, 2 connections) — tests/intercept/handlers/bash.test.tsSessionStore(class, 2 connections) — tests/intercept/handlers/bash.test.ts
Structure
./— tsup.config.tsbench/— runner.tssrc/— autogen.ts, cli.ts, core.ts, dashboard.ts, hooks.ts, serve.ts, watcher.tssrc/ccs/— exporter.ts, importer.tssrc/db/— migrate.tssrc/generators/— aider-context.ts, cursor-mdc.tssrc/graph/— path-utils.ts, query.ts, render-utils.ts, schema.ts, store.tssrc/intelligence/— hook-log.ts, token-tracker.tssrc/intercept/— component-status.ts, context.ts, cursor-adapter.ts, dispatch.ts, formatter.ts, installer.ts, memory-md.ts, safety.ts, stats.tssrc/intercept/handlers/— bash.ts, cwd-changed.ts, edit-write.ts, lsp-capture.ts, post-tool.ts, pre-compact.ts, read.ts, session-start.ts, user-prompt.tssrc/miners/— ast-miner.ts, git-miner.ts, session-miner.ts, skills-miner.tssrc/providers/— ast.ts, context7.ts, engram-git.ts, engram-mistakes.ts, engram-structure.ts, grammar-loader.ts, lsp-connection.ts, lsp.ts, mempalace.ts, obsidian.ts, resolver.ts, types.tssrc/server/— http.tssrc/tuner/— config.ts, index.tssrc/types/— sql.js.d.tstests/— ast-miner.test.ts, autogen.test.ts, core.test.ts, mistake-memory.test.ts, provider-cache.test.ts, render-utils.test.ts, skills-miner.test.ts, store.test.ts, stress.test.ts, watcher.test.tstests/ccs/— ccs.test.tstests/db/— migrate.test.tstests/fixtures/— sample.tstests/generators/— cursor-mdc.test.tstests/intercept/— cli-intercept.test.ts, context.test.ts, cursor-adapter.test.ts, dispatch-new-events.test.ts, dispatch.test.ts, formatter.test.ts, get-file-context.test.ts, hook-log.test.ts, installer.test.ts, memory-md.test.ts, mistakes-filter.test.ts, render-file-structure.test.ts, safety.test.ts, spike-regression.test.ts, stats.test.tstests/intercept/handlers/— bash.test.ts, cwd-changed.test.ts, edit-write.test.ts, post-tool.test.ts, pre-compact.test.ts, read.test.ts, session-start.test.ts, user-prompt.test.tstests/providers/— ast.test.ts, lsp.test.ts, resolver.test.tstests/server/— http.test.tstests/tuner/— tuner.test.ts
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 56 lines · 946 tokens per session scan A d8d170d0f4b2
cursorrules is a cursor rule published in the GitHub repository NickCirv/engram (141 stars, last pushed 2mo ago), licensed Apache-2.0. It adds 946 tokens to every session, about $0.0047 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
codebase
Forensic codebase brief for AI agents.
cursor
You are working on the checkout service. Preserve transaction integrity and auditability.
archcore-files
Enforce MCP-only operations when working with .archcore/ files.
dev_workflow
Guide for using Taskmaster to manage task-driven development workflows.
execution
Repository execution and verification commands.
fix-issue
Implement a fix following the human-thinking loop — understand the root cause, plan the minimal change, implement, verify the problem is actually gone.