Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/sruja-ai/sruja/cli-handlergit clone --depth 1 https://github.com/sruja-ai/srujaWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00427 | $0.00427 |
| Opus 5 | $0.00214 | $0.00214 |
| Sonnet 5 | $0.00085 | $0.00085 |
| Haiku 4.5 | $0.00043 | $0.00043 |
Grade A, and why
cli-handler scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
CLI Handler Patterns
Patterns for Sruja CLI command handlers. Keeps the CLI thin and consistent.
Scopes
crates/sruja-cli/src/commands/**/*.rs
Rules
- Handlers are thin: CLI handlers parse args, call library functions, format output. Business logic lives in engine/language/scan crates.
- Use clap derive: All commands use
#[derive(Parser)]from clap. Subcommands use#[derive(Subcommand)]. - Exit codes: Return
ExitCodefrom main. UseExitCode::SUCCESS/ExitCode::FAILURE. Neverstd::process::exit()directly. - Output formats: Support
--format json|text|github-actionswhere applicable. JSON output usesserde_json::to_string_pretty. - Error display: Use
anyhow::Resultfor error propagation in CLI. Display errors witheprintln!to stderr, never stdout. - Repo path: Accept
-r, --repo <PATH>with default.. UsePathBuffor the type. - Verbose flag: Use
-v, --verbose(counting) for log levels. Map-vto info,-vvto debug,-vvvto trace. - No global state: Each command handler receives its parsed args. No lazy_static or global singletons.
Patterns
use anyhow::Result;
use clap::Parser;
use std::path::PathBuf;
#[derive(Parser)]
pub struct MyCommand {
#[arg(short, long, default_value = ".")]
repo: PathBuf,
#[arg(short, long, default_value = "text")]
format: OutputFormat,
}
pub fn run(cmd: MyCommand) -> Result<()> {
// 1. Validate inputs
// 2. Call library function
// 3. Format and print output
Ok(())
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 41 lines · 427 tokens per session scan A 6d7b8502f18a
cli-handler is a cursor rule published in the GitHub repository sruja-ai/sruja (22 stars, last pushed 8d ago), licensed Apache-2.0. It adds 427 tokens to every session, about $0.0021 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
laminar
Use it when user asks about adding instrumentation with Laminar, creating an eval with Laminar or migrating from Langfuse to Laminar instrumentation.
testing
Testing strategies and quality assurance — testing pyramid, unit/integration/E2E testing, TDD/BDD, test automation, and quality metrics. Applied when writing or reviewing tests.
api-design
API design guidelines — REST principles, GraphQL patterns, versioning, pagination, error handling, documentation, security, caching, and testing. Applied when designing or reviewing API endpoints.
owasp-ai-security-privacy
OWASP AI Security & Privacy Guide – PR rules emphasizing data protection, governance, and safety.
cursorrules
Cursor rule "cursorrules" from me2resh/agent-decision-record, covering agent decision records (agdr) — cursor rules, purpose, see: https://github.com/me2resh/agent-decision-record, decision detection and adding a new dependency → stop, document decision first.
agdr
Agent Decision Records - enforces structured documentation of technical decisions before implementation.