Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/ocean-industries-concept-lab/openbridge-webcomponents/coding-standardsgit clone --depth 1 https://github.com/Ocean-Industries-Concept-Lab/openbridge-webcomponentsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.01577 |
| Opus 5 | $0.00000 | $0.00788 |
| Sonnet 5 | $0.00000 | $0.00315 |
| Haiku 4.5 | $0.00000 | $0.00158 |
Grade A, and why
coding-standards scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 118 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Coding Standards
AGENTS.md § 2 carries the summary; docs/agents/coding-standards.md is the
source of truth for comments, CSS comments, writing style, boolean naming and
Storybook titles.
npm run lint:comments reports what breaks the comment rules.
Comments
Write for a developer reading this file in a month, not for the reviewer of this PR. If they would get it from the code, don't write it.
- WHY, never WHAT. A comment that restates the code is deleted.
- Explanation belongs on the declaration. Document a class, property or method in its JSDoc. A comment inside a method body is allowed only for a why that has no declaration to live on (a guard that looks removable, a coupling to another file) — three lines at most.
- Three lines, at most. Longer explanations are not comments:
- behaviour → a
.spec.tstest that pins it - CSS / layout / visual behaviour → a Storybook story; the snapshot is the doc
- still needs prose → the story's
parameters.docs.description.story
- behaviour → a
- A title line, then a short paragraph — in JSDoc, docs and CSS blocks. Two words of heading usually replace four lines of prose.
- No history, no dates, no change narration — no "previously did X",
"since #994", "confirmed 2026-08-17", "added to fix Y". The why of a change
goes in the commit message and the PR body;
git logandgit blameare first-class sources — use them before writing a comment. - State, then cite. If a reference is used, the sentence stands alone and
(#1234)is a trailing pointer, never the explanation. One per comment. TODO(designer): …marks an open design question. Any other TODO carries an issue:TODO(#1234): ….- Keep existing comments when refactoring unless the change makes them obsolete.
- Comment pass before done: re-read the comments in your diff against
these rules; delete what does not earn its lines.
npm run lint:commentsreports the rest.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 118 lines · 0 tokens per session scan A 1c16fe9a8fd4
coding-standards is a cursor rule published in the GitHub repository Ocean-Industries-Concept-Lab/openbridge-webcomponents (91 stars, last pushed 4d ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 1,577 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
cursorrules
Read and follow AGENTS.md for all development conventions.
static-analysis
Run local static analysis and fix new issues before finishing a task.
development-experience
Dev seed data and local explorability for every feature.
issues-test-failure-diagnosis
Classify test failures and write reports under reports/.
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.