cursorrules

An automatically generated map of a codebase's structure and connections. It lists important files, functions, classes, and how parts of the project relate to one another.

In plain words
What is it for?
Use it to navigate a repository, find entry points and related modules, understand dependencies, and generate or update project context files.
Why use it?
It gives an unfamiliar developer a quick overview of where code lives and which components may be affected by a change.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/nickcirv/engram/cursorrules
Clone the repo
git clone --depth 1 https://github.com/NickCirv/engram

Made for: Cursor.

Per session 946 This file is loaded in full into every session.
When invoked 946 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00946 $0.00946
Opus 5 $0.00473 $0.00473
Sonnet 5 $0.00189 $0.00189
Haiku 4.5 $0.00095 $0.00095

Measured yesterday against content hash d8d170d0f4b2, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

cursorrules scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

Copies of this mod

1 near-identical copy found in the catalogue:

.cursorrules · 56 lines

How it starts

The opening of the file, as written. The whole thing — 56 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Codebase Structure (auto-generated by engram)

Graph: 451 nodes, 1005 edges | 96% extracted, 4% inferred View: general

Core entities

  • extractDirectory() (function, 2 connections) — src/miners/ast-miner.ts
  • extractFile() (function, 2 connections) — src/miners/ast-miner.ts
  • generateSummary() (function, 2 connections) — src/autogen.ts
  • writeToFile() (function, 2 connections) — src/autogen.ts
  • parseReadLikeBashCommand() (function, 2 connections) — src/intercept/handlers/bash.ts
  • createAuthService() (function, 2 connections) — tests/intercept/handlers/bash.test.ts
  • hashPassword() (function, 2 connections) — tests/intercept/handlers/bash.test.ts
  • SessionStore (class, 2 connections) — tests/intercept/handlers/bash.test.ts

Structure

  • ./ — tsup.config.ts
  • bench/ — runner.ts
  • src/ — autogen.ts, cli.ts, core.ts, dashboard.ts, hooks.ts, serve.ts, watcher.ts
  • src/ccs/ — exporter.ts, importer.ts
  • src/db/ — migrate.ts
  • src/generators/ — aider-context.ts, cursor-mdc.ts
  • src/graph/ — path-utils.ts, query.ts, render-utils.ts, schema.ts, store.ts
  • src/intelligence/ — hook-log.ts, token-tracker.ts
  • src/intercept/ — component-status.ts, context.ts, cursor-adapter.ts, dispatch.ts, formatter.ts, installer.ts, memory-md.ts, safety.ts, stats.ts
  • src/intercept/handlers/ — bash.ts, cwd-changed.ts, edit-write.ts, lsp-capture.ts, post-tool.ts, pre-compact.ts, read.ts, session-start.ts, user-prompt.ts
  • src/miners/ — ast-miner.ts, git-miner.ts, session-miner.ts, skills-miner.ts
  • src/providers/ — ast.ts, context7.ts, engram-git.ts, engram-mistakes.ts, engram-structure.ts, grammar-loader.ts, lsp-connection.ts, lsp.ts, mempalace.ts, obsidian.ts, resolver.ts, types.ts
  • src/server/ — http.ts
  • src/tuner/ — config.ts, index.ts
  • src/types/ — sql.js.d.ts
  • tests/ — ast-miner.test.ts, autogen.test.ts, core.test.ts, mistake-memory.test.ts, provider-cache.test.ts, render-utils.test.ts, skills-miner.test.ts, store.test.ts, stress.test.ts, watcher.test.ts
  • tests/ccs/ — ccs.test.ts
  • tests/db/ — migrate.test.ts
  • tests/fixtures/ — sample.ts
  • tests/generators/ — cursor-mdc.test.ts
  • tests/intercept/ — cli-intercept.test.ts, context.test.ts, cursor-adapter.test.ts, dispatch-new-events.test.ts, dispatch.test.ts, formatter.test.ts, get-file-context.test.ts, hook-log.test.ts, installer.test.ts, memory-md.test.ts, mistakes-filter.test.ts, render-file-structure.test.ts, safety.test.ts, spike-regression.test.ts, stats.test.ts
  • tests/intercept/handlers/ — bash.test.ts, cwd-changed.test.ts, edit-write.test.ts, post-tool.test.ts, pre-compact.test.ts, read.test.ts, session-start.test.ts, user-prompt.test.ts
  • tests/providers/ — ast.test.ts, lsp.test.ts, resolver.test.ts
  • tests/server/ — http.test.ts
  • tests/tuner/ — tuner.test.ts

Read the full file on GitHub · 56 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 56 lines · 946 tokens per session scan A d8d170d0f4b2

Subscribe to this mod's changes

cursorrules is a cursor rule published in the GitHub repository NickCirv/engram (141 stars, last pushed 2mo ago), licensed Apache-2.0. It adds 946 tokens to every session, about $0.0047 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.