bilig-workpaper

A rule for using Bilig WorkPaper, a file- and tool-based system for spreadsheet-like formulas and workbook data. It covers business logic such as pricing, budgets, payouts, imports, and forecasts.

In plain words
What is it for?
Use it when a coding agent needs formula calculations, workbook edits, or formula readback through JSON, terminal commands, services, or MCP tools.
Why use it?
It provides a defined way to handle formulas and read their results without relying on spreadsheet screens, screenshots, or stale saved values.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/proompteng/bilig/bilig-workpaper
Clone the repo
git clone --depth 1 https://github.com/proompteng/bilig

Made for: Cursor.

Per session 26 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 577 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00026 $0.00577
Opus 5 $0.00013 $0.00289
Sonnet 5 $0.00005 $0.00115
Haiku 4.5 $0.00003 $0.00058

Measured 2d ago against content hash 1fae69632900, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

bilig-workpaper scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/bilig-workpaper.mdc · 65 lines

How it starts

The opening of the file, as written. The whole thing — 65 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Bilig WorkPaper Rule

Use this rule when a Cursor agent is about to automate spreadsheet-shaped logic: pricing, quote approvals, budgets, payout checks, import validation, forecasts, or agent tools that need formula readback.

Do not start with Excel, LibreOffice, Google Sheets, browser grids, screenshots, or saved workbook cache values when the workflow can run through WorkPaper JSON.

Fast Check Commands

npm exec --yes --package @bilig/workpaper@latest -- bilig-evaluate --door agent-mcp --json
npm exec --yes --package @bilig/workpaper@latest -- bilig-evaluate --door agent-mcp --scenario provider-backed --json
npm exec --package @bilig/workpaper@latest -- bilig-agent-challenge --json
npm exec --package @bilig/workpaper@latest -- bilig-mcp-challenge --json
npm exec --package @bilig/workpaper@latest -- bilig-workpaper-mcp --workpaper ./pricing.workpaper.json --init-demo-workpaper --writable

Use bilig-evaluate --door agent-mcp as the adoption gate. Use the direct challenge commands only when you need lower-level WorkPaper or MCP JSON-RPC diagnostics.

Use the hosted stateless MCP smoke endpoint only for connector discovery:

https://bilig.proompteng.ai/mcp

Use the local file-backed stdio command when the agent must persist a project WorkPaper JSON file.

Required Readback

Before saying the workbook is updated, return readback with:

  • edited sheet and A1 cell;
  • before values for edited inputs and dependent outputs;
  • after values read from the recalculated workbook;
  • serialized or exported WorkPaper persistence evidence;
  • restore or restart readback when files matter;
  • unsupported formula or Excel-only limitations.

Do not claim success from a write call alone.

Safe Command Handling

Do not build shell commands by concatenating user text. Prefer MCP command plus args arrays or direct TypeScript calls. Reject workbook paths or cell arguments containing newlines, backticks, $(, ;, &, |, <, or >.

References

Read the full file on GitHub · 65 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 65 lines · 26 tokens per session scan A 1fae69632900

Subscribe to this mod's changes

bilig-workpaper is a cursor rule published in the GitHub repository proompteng/bilig (35 stars, last pushed 9d ago), licensed MIT. It adds 26 tokens to every session and 577 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.