agent-workflow

A set of rules for organizing AI-agent work from a product requirements document to a work plan and individual tasks. A work plan is a simple list of planned work and its status.

In plain words
What is it for?
Use it to plan and sequence software changes, create task requirements, check dependencies, and keep the project’s work queue consistent.
Why use it?
It prevents agents from choosing unfinished dependent work, skipping required planning, or adding untracked tasks. It also requires key design decisions and fallback plans to be recorded.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/otis22/vetmanager-mcp/agent-workflow
Clone the repo
git clone --depth 1 https://github.com/otis22/vetmanager-mcp

Made for: Cursor.

Per session 3,724 This file is loaded in full into every session.
When invoked 3,724 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.03724 $0.03724
Opus 5 $0.01862 $0.01862
Sonnet 5 $0.00745 $0.00745
Haiku 4.5 $0.00372 $0.00372

Measured yesterday against content hash bc16c51801c4, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

agent-workflow scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/agent-workflow.mdc · 267 lines

How it starts

The opening of the file, as written. The whole thing — 267 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Agent Project Workflow Rules

1. Workplan

  • Workplan хранится в Roadmap.md
  • Формируется агентами на основе PRD
  • Содержит только:
    • название этапа / задачи
    • статус
  • Не содержит деталей реализации
  • Является единственным источником очереди работ

2. Выбор задачи

Агент выбирает задачу по правилам:

  • Только задачи со статусом todo
  • Без незавершённых зависимостей
  • Самая верхняя в списке
  • Запрещено:
    • брать несколько задач
    • перескакивать
    • создавать новые задачи вне Workplan

3. PRD задачи

Перед началом реализации агент обязан:

  • Создать PRD задачи в /PRD
  • Выполнить декомпозицию
  • Изучить связанные /artifacts после создания PRD и обновить PRD проверенными фактами
  • Добавить в новые PRD секцию Архитектурное решение:
    • проблема, которую решает выбранная архитектура;
    • контекст и ограничения: existing patterns, API/OpenAPI facts, security/privacy, backward compatibility, performance/load limits;
    • рассмотренные варианты с плюсами/минусами;
    • выбранное решение и почему оно лучше альтернатив;
    • инварианты, которые должны остаться истинными после реализации;
    • rollback/fallback, если решение окажется неверным или upstream поведение изменится.
  • Для задач, которые затрагивают auth, storage, public/API/MCP contract, production behavior, performance/load limits или cross-module ownership boundary, выполнить отдельный Architecture Critique gate через стороннюю сильную модель до обычного PRD-review.
  • Перед PRD-review выполнить Spark-review pass, устранить только адекватные и важные findings
  • Провести PRD-review, устранить адекватные findings и повторить review после правок
  • Перед PRD-review сторонней моделью выполнить Spark-review pass, устранить только адекватные и важные findings
  • Провести PRD-review сторонней моделью, устранить адекватные findings и повторить review после существенных правок в пределах бюджета
  • Провести оценку PRD на простоту; если PRD изменился после упрощения, повторить PRD-review

Ограничения:

Read the full file on GitHub · 267 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 267 lines · 3,724 tokens per session scan A bc16c51801c4

Subscribe to this mod's changes

agent-workflow is a cursor rule published in the GitHub repository otis22/vetmanager-mcp (1 stars, last pushed yesterday), licensed MIT. It adds 3,724 tokens to every session, about $0.0186 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.