Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/ttpears/gitlab-mcp/cursorrulesgit clone --depth 1 https://github.com/ttpears/gitlab-mcpWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00572 | $0.00572 |
| Opus 5 | $0.00286 | $0.00286 |
| Sonnet 5 | $0.00114 | $0.00114 |
| Haiku 4.5 | $0.00057 | $0.00057 |
Grade A, and why
cursorrules scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Project rules and notes for gitlab-mcp
-
Authentication model
- Hybrid by default: shared read-only token for read tools; user PAT required for write tools.
- Env: GITLAB_SHARED_ACCESS_TOKEN, GITLAB_AUTH_MODE=hybrid, optional GITLAB_URL.
- Tools accept optional
userCredentialswithaccessTokenand optionalgitlabUrl.
-
Transports
- Server provides stdio (default) and Streamable HTTP transport at
/(and/mcpfor container compatibility). - LibreChat (HTTP) should use
type: streamable-httpandurl: http://HOST:PORT/. - Hosted environments may provide
PORT; server also respectsGITLAB_MCP_PORTandMCP_TRANSPORT=http.
- Server provides stdio (default) and Streamable HTTP transport at
-
Pagination
- All list/search tools support cursor-based pagination (
first,after) and auto-pagination (fetchAll). fetchAllloops server-side viafetchAllPages()up to maxItems (default 100), returning{ nodes, totalFetched, hasMore, pageInfo }.- Default page size: 20. Max per request:
config.maxPageSize(default 50, envGITLAB_MAX_PAGE_SIZE). - Sort defaults to
UPDATED_DESCfor recency bias on issues, MRs, and projects. search_gitlabpaginates projects and issues independently whenfetchAll=true.
- All list/search tools support cursor-based pagination (
-
GraphQL / Validation
- Avoid unsupported fields (e.g.,
Project.defaultBranch) across self-hosted instances; rely on introspection. - Search term inputs are trimmed and empty strings are rejected for tools that require them.
- Issue/MR state:
allmaps to undefined; others map to GQL enums via UPPERCASE.
- Avoid unsupported fields (e.g.,
-
New discovery tools
resolve_path: Distinguishesgroupvsprojectand lists group projects.get_group_projects: Lists projects within a group, supports search and pagination.get_type_fields: Lists fields for a given GraphQL type using introspection.update_issue: Schema-aware updates for issues; falls back to granular mutations when needed.update_merge_request: Schema-aware MR updates; supports assignees, reviewers, labels, title/description.
-
Error handling
- Read tools fall back to shared token; write tools throw if no user token is provided.
- Null guards ensure clearer errors when a group path is provided to project-only tools.
-
Maintenance
- Keep this file updated when adding tools, transports, or auth changes.
- Reviewers apply to merge requests, not issues (per GitLab GraphQL docs).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 39 lines · 572 tokens per session scan A f5ce35f9d635
cursorrules is a cursor rule published in the GitHub repository ttpears/gitlab-mcp (10 stars, last pushed 1mo ago), licensed MIT. It adds 572 tokens to every session, about $0.0029 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
swift-development
Swift development: SwiftUI, Combine, async/await, iOS patterns, and Apple platform conventions.
cursorrules
When the user asks about social media, use social-media-ai-mcp tools: schedulepost, generatehashtags, analyzeengagement, plancontentcalendar, getaudienceinsights.
cursorrules
This is an MCP (Model Context Protocol) server that provides Notion integration tools and AI agent workflows. Built with TypeScript, using the MCP SDK for server implementation.
lighter-safety
Safety contract for the Lighter MCP server. Apply whenever a lighter tool is invoked.
nix-security
Nix Security and Sandboxing.
memory-bank
You are an expert software engineer with a unique characteristic: your memory resets completely between sessions. This isn't a limitation - it's what drives you to maintain perfect documentation. At the beginning of each dialogue, you rely ENTIRELY on your Memory Bank to understand the project and continue work…