Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/theimaginaryfoundation/what-iffWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/theimaginaryfoundation/what-iff/api)<a href="https://agentmods.dev/rules/theimaginaryfoundation/what-iff/api"><img src="https://agentmods.dev/badge/rules/theimaginaryfoundation/what-iff/api/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/rules/theimaginaryfoundation/what-iff/api"><img src="https://agentmods.dev/badge/rules/theimaginaryfoundation/what-iff/api.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.04286 |
| Opus 5 | $0.00000 | $0.02143 |
| Sonnet 5 | $0.00000 | $0.00857 |
| Haiku 4.5 | $0.00000 | $0.00429 |
Grade A, and why
api scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 659 lines — stays where its author put it; the contents beside it link to each section on GitHub.
API Server Design and Structure
Overview
The API server is a RESTful service built with Go, using the Gorilla Mux router for routing and Ent for database operations. The server follows a modular design with clear separation of concerns and dependency injection patterns.
Server Initialization
The API server is initialized in cmd/api-server/main.go. It follows these steps:
- Load environment variables
- Initialize logger
- Connect to database
- Create and configure server
- Start server and handle graceful shutdown
func main() {
// Load environment variables
if err := godotenv.Load(envFile); err != nil {
log.Printf("Warning: Error loading .env file: %v", err)
}
// Initialize logger
logger, err := zap.NewProduction()
if err != nil {
log.Fatalf("Failed to initialize logger: %v", err)
}
defer logger.Sync()
// Initialize database connection
client, err := database.NewClient(logger)
if err != nil {
logger.Fatal("Failed to connect to database", zap.Error(err))
}
defer client.Close()
// Create server config
config := server.NewConfig()
// Create and configure server
srv := server.NewServer(config, logger, client)
// Run server in a goroutine
go func() {
if err := srv.Start(); err != nil {
logger.Fatal("Server failed", zap.Error(err))
}
}()
// Handle graceful shutdown
c := make(chan os.Signal, 1)
signal.Notify(c, os.Interrupt, syscall.SIGTERM)
sig := <-c
ctx, cancel := context.WithTimeout(context.Background(), time.Second*15)
defer cancel()
if err := srv.Shutdown(ctx); err != nil {
logger.Fatal("Server forced to shutdown", zap.Error(err))
}
}
Server Configuration
Server configuration is managed through the Config struct in internal/server/config.go. It loads settings from environment variables with sensible defaults.
type Config struct {
Host string
Port string
ReadTimeout time.Duration
WriteTimeout time.Duration
IdleTimeout time.Duration
RunMigrations bool
}
func NewConfig() *Config {
port := os.Getenv("SERVER_PORT")
if port == "" {
port = "8080"
}
host := os.Getenv("SERVER_HOST")
if host == "" {
host = "localhost"
}
return &Config{
Host: host,
Port: port,
ReadTimeout: 15 * time.Second,
WriteTimeout: 15 * time.Second,
IdleTimeout: 60 * time.Second,
RunMigrations: false,
}
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 659 lines · 0 tokens per session scan A 544e3ba74c57
api is a cursor rule published in the GitHub repository theimaginaryfoundation/what-iff (15 stars, last pushed today), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 4,286 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-09.
Other cursor rules, from other repositories
trigger
Guidelines for writing PostgreSQL triggers, which are database actions that run automatically when data changes. They explain when a trigger is appropriate and how to keep its function safe and predictable.
rulesforconvex
description: Convex guidelines globs: alwaysApply: true.
ehs-ims-conventions
EHS IMS app — RBAC, data layer, tRPC, migrations, AI boundaries.
startup-migration-bounded-work
Production djangostartup migrate must be bounded; never run makemigrations in production.
schema
Scalable and secure schema design patterns for relational databases, NoSQL, and APIs. / TR: İlişkisel veri tabanları, NoSQL ve API'ler için ölçeklenebilir ve güvenli şema tasarım kalıpları.
redis_rate_limiting
Complete guide for implementing Redis-based rate limiting with authentication troubleshooting and FastAPI integration.