Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/ocean-industries-concept-lab/openbridge-webcomponents/ci-and-releasegit clone --depth 1 https://github.com/Ocean-Industries-Concept-Lab/openbridge-webcomponentsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/ocean-industries-concept-lab/openbridge-webcomponents/ci-and-release)<a href="https://agentmods.dev/rules/ocean-industries-concept-lab/openbridge-webcomponents/ci-and-release"><img src="https://agentmods.dev/badge/rules/ocean-industries-concept-lab/openbridge-webcomponents/ci-and-release.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.01732 |
| Opus 5 | $0.00000 | $0.00866 |
| Sonnet 5 | $0.00000 | $0.00346 |
| Haiku 4.5 | $0.00000 | $0.00173 |
Grade A, and why
ci-and-release scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 130 lines — stays where its author put it; the contents beside it link to each section on GitHub.
CI and Release
Your commit type decides whether anything ships
.releaserc.json drives semantic-release, and its releaseRules mean most
commit types produce no release at all:
| Commit type | Release |
|---|---|
feat!: / any BREAKING CHANGE: |
major |
feat: |
minor |
fix: · perf: · revert: |
patch |
docs: · style: · refactor: · test: · build: · ci: · chore: |
none |
Pick the type for the effect you want. A user-visible fix committed as
refactor: never reaches consumers; a docs-only change committed as fix:
ships a version nobody needs. When a change is genuinely non-shipping, the
no-release types are the correct choice, not a fallback.
The same convention is enforced on PR titles by
.github/workflows/pr-title-lint.yml — the squashed PR title is what
semantic-release reads, so the title matters more than the individual commits.
Release model
| Branch | npm dist-tag | Version shape |
|---|---|---|
stable |
latest |
2.0.0 |
develop |
next |
2.0.0-next.N (prerelease) |
release.yml runs on push to develop and on manual workflow_dispatch.
A release commits back as chore(release): <version> [skip ci], updating
packages/openbridge-webcomponents/CHANGELOG.md, the core package.json, and
package-lock.json.
CHANGELOG.md is generated by @semantic-release/changelog — never hand-edit
it. See generated-code.md.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 130 lines · 0 tokens per session scan A 0028df323063
ci-and-release is a cursor rule published in the GitHub repository Ocean-Industries-Concept-Lab/openbridge-webcomponents (92 stars, last pushed yesterday), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 1,732 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
dev-workflow
Monorepo developer workflow standards - mise tasks, git hooks, CI/CD, release automation.
release
Changesets release pipeline - version PR, shared vX.Y.Z tag, CI gate before tagging, no npm publish, GITHUBTOKEN tag trigger limitation.
ci-cd-workflows
This rule provides guidance on the CI/CD pipeline, GitHub Actions workflows (defined in .github/workflows/), custom actions (in .github/actions/), versioning strategies, and release processes. Use this rule if the query involves CI/CD, build/test issues, release procedures, versioning questions, or if it references…
cut-release
When the team is ready to ship a new version — version bumps, changelog finalization, dependency snapshots, and CI release trigger.
dev-workflow
Monorepo developer workflow standards - mise tasks, git hooks, CI/CD, release automation.
sciclaw-papercuts
Papercuts from Sol/ImageMagick/release cycles — release, brew, CI, and workspace hygiene for sciClaw agents.