Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/rkawaishi/workato-dev-kit/workato-page-componentsgit clone --depth 1 https://github.com/rkawaishi/workato-dev-kitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/rkawaishi/workato-dev-kit/workato-page-components)<a href="https://agentmods.dev/rules/rkawaishi/workato-dev-kit/workato-page-components"><img src="https://agentmods.dev/badge/rules/rkawaishi/workato-dev-kit/workato-page-components.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.01779 |
| Opus 5 | $0.00000 | $0.00890 |
| Sonnet 5 | $0.00000 | $0.00356 |
| Haiku 4.5 | $0.00000 | $0.00178 |
Grade A, and why
workato-page-components scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 218 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Workato Page Component JSON Format
Top-level structure
{
"name": "Page name",
"path": "url-slug",
"content": {
"type": "common",
"maxWidth": "fixed",
"background": { "style": "pattern", "pattern": "light-2" },
"variables": [],
"handlers": { "pageLoad": null },
"layout": [ /* nested component tree */ ]
}
}
layout structure
layout is an array of rows. Each row consists of a row number (1-based) followed by [component, colSpan] pairs:
"layout": [
1, // row number
[{ /* component */ }, 0], // [component, colSpan (usually 0)]
[{ /* component */ }, 0]
]
A container may have its own nested layout.
Shared component properties
| Property | Description |
|---|---|
type |
Component kind |
id |
8-digit hex unique ID (e.g. "cb33ba2c") |
name |
Component name (for the builder) |
x |
Grid starting position (0–11; 12-column layout) |
width |
Grid width (1–12) |
visible |
true / false / conditional expression |
Additional properties for input components:
| Property | Description |
|---|---|
dataSource |
Save destination (see below). NOT the source of option values. |
editable |
true / false / conditional expression |
validations.required.condition |
true / false / conditional expression |
label |
User-facing label |
hint |
Input hint |
placeholder |
Placeholder text |
dataSource (important)
dataSource specifies the Data Table column the value is written to, not the source of option values.
"dataSource": {
"id": "Employee name", // Data Table field title (NOT its UUID)
"type": "short-text" // field type
}
dataSource: null → the value is not persisted on submit.
Component type mapping
| Purpose | type |
style |
Data Table field type |
|---|---|---|---|
| Short text | "input" |
"short-text" |
short-text |
| Long text | "input" |
"long-text" |
long-text |
| Number | "input" |
"number" |
number |
"input" |
"email" |
short-text |
|
| Phone | "input" |
"phone" |
short-text |
| URL | "input" |
"url" |
short-text |
| Date | "date" |
"date" |
date |
| Date-time | "date" |
"date-time" |
date-time |
| Dropdown (single) | "dropdown" |
not used | short-text |
| Dropdown (multi) | "dropdown" + multiValue: true |
not used | short-text |
| Checkbox | "checkbox" |
not used | boolean |
| File | "file" |
not used | file |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 218 lines · 0 tokens per session scan A 0e58fb06fac5
workato-page-components is a cursor rule published in the GitHub repository rkawaishi/workato-dev-kit (5 stars, last pushed 4d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 1,779 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
cli-error-handling
CLI command error handling patterns.
prefer-direct-imports-over-module-mocks
Prefer extracting a testable core over vi.mock / vi.resetModules when unit tests need to reach production logic entangled with config, env, or singletons.
control-plane-descriptors
Control plane descriptor and instance implementation patterns.
family-instance-domain-actions
Family instance domain action implementation patterns.