Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/rosendolu/cursor-rules-deploy/npm-publish-agentgit clone --depth 1 https://github.com/rosendolu/cursor-rules-deployWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/rosendolu/cursor-rules-deploy/npm-publish-agent)<a href="https://agentmods.dev/rules/rosendolu/cursor-rules-deploy/npm-publish-agent"><img src="https://agentmods.dev/badge/rules/rosendolu/cursor-rules-deploy/npm-publish-agent.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00005 | $0.01120 |
| Opus 5 | $0.00003 | $0.00560 |
| Sonnet 5 | $0.00001 | $0.00224 |
| Haiku 4.5 | $0.00001 | $0.00112 |
Grade A, and why
npm-publish-agent scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 172 lines — stays where its author put it; the contents beside it link to each section on GitHub.
NPM Package Publishing Guidelines
Critical Rules
- Always use GitHub Actions for automated package publishing
- Store authentication tokens as GitHub Secrets, never in code
- Use conventional commits format for automated versioning
- Validate packages by building and testing before publishing
- Tag releases with version numbers prefixed with 'v' (e.g., v1.0.0)
- Configure workflows to trigger on both tag pushes and manual events
- Generate and maintain changelogs for all releases
- Ensure package.json contains all required fields before publishing
- Scope packages appropriately (public/private, org-scoped)
- Verify package contents before publishing using npm pack
- Use a consolidated workflow for both npm and GitHub Packages publishing
GitHub Actions Setup Requirements
- Create
.github/workflows/package-publish.ymlfor a unified publishing workflow - Include registry selection in workflow_dispatch inputs
- Set proper permissions in workflow file (contents:write, packages:write)
- Configure Node.js environment using actions/setup-node@v4
- Set registry URL based on selected target registry
- Cache dependencies using the cache parameter
- Run tests before publishing
- Generate changelog using conventional-changelog-cli
Package Configuration Requirements
- Valid package.json with all required fields:
- name, version, description, main, files
- scripts (build, test)
- publishConfig (access, registry)
- repository information
- Package should be properly scoped for GitHub Packages (@username/package-name)
- Files array should include only distribution files, not source code
- Include README.md, LICENSE, and CHANGELOG.md
Security Guidelines
- NPM_TOKEN must be stored as a GitHub Secret
- Use GITHUB_TOKEN with minimal required permissions
- Generate fresh tokens periodically
- Do not expose tokens in logs or outputs
- Use permission boundaries in GitHub Actions workflows
Version Management
- Use semantic versioning (MAJOR.MINOR.PATCH)
- Automate version bumps based on conventional commits:
- fix: patch version update
- feat: minor version update
- BREAKING CHANGE: major version update
- Use npm version to update package.json and create tags
- Push tags to trigger automated releases
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 172 lines · 5 tokens per session scan A f58d38a1e321
npm-publish-agent is a cursor rule published in the GitHub repository rosendolu/cursor-rules-deploy (37 stars, last pushed 1y ago), licensed MIT. It adds 5 tokens to every session and 1,120 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
vue-typescript-patterns
Cursor rule "vue-typescript-patterns" from soaring-xiongkulu/easyaiot, covering vue3 + typescript 开发规范, vue 组件规范, vue sfc 组件规范, typescript 规范 and 状态管理.
nextjs-typescript-app-cursorrules-prompt-file
Cursor rules for Next.js development with TypeScript integration.
ts
Cursor rule "ts" from un-pany/v3-admin-vite, covering ts 开发规范, 类型, 命名, 代码组织 and 错误处理.
platform-pattern-2-filesystem-operations
Cursor rule "platform-pattern-2-filesystem-operations" from PaulJPhilp/EffectPatterns, covering platform pattern 2: filesystem operations and example.
handle-unexpected-errors-by-inspecting-the-cause
Cursor rule "handle-unexpected-errors-by-inspecting-the-cause" from PaulJPhilp/EffectPatterns, covering handle unexpected errors by inspecting the cause and example.
modeling-tagged-unions-with-datacase
Cursor rule "modeling-tagged-unions-with-datacase" from PaulJPhilp/EffectPatterns, covering modeling tagged unions with data.case and example.