beefreeSDK

A set of coding guidelines for Beefree SDK, a software development kit for building and managing email editor applications and templates.

In plain words
What is it for?
Use it when adding Beefree SDK to a JavaScript application, setting up its dependencies and environment variables, configuring authentication, or managing templates.
Why use it?
It helps developers install and configure the SDK while keeping authentication credentials on a proxy server instead of exposing them in the client.

Cursor rule

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/patrickjs/awesome-cursorrules/beefreesdk
Clone the repo
git clone --depth 1 https://github.com/PatrickJS/awesome-cursorrules
Per session 3,982 This file is loaded in full into every session.
When invoked 3,982 The same file — it is already loaded in full.
Security scan B 2 findings. Scan, not verified.
Origin 98% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.03982 $0.03982
Opus 5 $0.01991 $0.01991
Sonnet 5 $0.00796 $0.00796
Haiku 4.5 $0.00398 $0.00398

Measured 2d ago against content hash 36104de1c129, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade B, and why

beefreeSDK scanned grade B with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Sends data to an external URLmediumData exfiltration

A POST to an outside endpoint may be telemetry or may be exfiltration; either way the mod talks to somewhere, and you should know where.

const token = await fetch('http://localhost:3001/proxy/bee-auth', { method: 'POST',

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

const response = await axios.post(
Origin

This is a copy

98% identical to beefreeSDK-nocode-content-editor-cursorrules-prompt-file — 10 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

rules/beefreeSDK.mdc · 555 lines

How it starts

The opening of the file, as written. The whole thing — 555 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Beefree SDK Guidelines

Guidelines and best practices for building applications with Beefree SDK, including installation, authentication, configuration, customization, and template management.

Installation Guidelines

Package Installation

  • Install the Beefree SDK package using npm or yarn:
    npm install @beefree.io/sdk
    # or
    yarn add @beefree.io/sdk
    

Dependencies

  • Beefree SDK requires the following core dependencies:
    {
      "dependencies": {
        "@beefree.io/sdk": "^9.0.2-fix-optional-url-config.0",
        "axios": "^1.10.0",
        "express": "^5.1.0",
        "cors": "^2.8.5",
        "dotenv": "^17.2.0"
      }
    }
    

Environment Setup

  • Create a .env file in your project root with your Beefree credentials:
    BEE_CLIENT_ID=your_client_id_here
    BEE_CLIENT_SECRET=your_client_secret_here
    

Authentication Guidelines

Proxy Server Setup

  • ALWAYS use a proxy server for authentication to protect your credentials
  • Create a proxy server file (e.g., proxy-server.js) to handle authentication:
    import express from 'express';
    import cors from 'cors';
    import axios from 'axios';
    import dotenv from 'dotenv';
    
    dotenv.config();
    
    const app = express();
    const PORT = 3001;
    
    app.use(cors());
    app.use(express.json());
    
    const BEE_CLIENT_ID = process.env.BEE_CLIENT_ID;
    const BEE_CLIENT_SECRET = process.env.BEE_CLIENT_SECRET;
    
    // V2 Auth Endpoint
    app.post('/proxy/bee-auth', async (req, res) => {
      try {
        const { uid } = req.body;
        
        const response = await axios.post(
          'https://auth.getbee.io/loginV2',
          {
            client_id: BEE_CLIENT_ID,
            client_secret: BEE_CLIENT_SECRET,
            uid: uid || 'demo-user'
          },
          { headers: { 'Content-Type': 'application/json' } }
        );
        
        res.json(response.data);
      } catch (error) {
        console.error('Auth error:', error.message);
        res.status(500).json({ error: 'Failed to authenticate' });
      }
    });
    
    app.listen(PORT, () => {
      console.log(`Proxy server running on http://localhost:${PORT}`);
    });
    

Read the full file on GitHub · 555 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 555 lines · 0 tokens per session scan B 36104de1c129

Subscribe to this mod's changes

beefreeSDK is a cursor rule published in the GitHub repository PatrickJS/awesome-cursorrules (40,694 stars, last pushed 3mo ago), licensed CC0-1.0. It adds 3,982 tokens to every session, about $0.0199 per session on Opus 5. A static security scan graded it B with 2 findings (sends data to an external url, makes network calls). It is 98% identical to beefreeSDK-nocode-content-editor-cursorrules-prompt-file, differing in 10 lines, and is treated as a copy.