Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/v0id-user/setmac/release-policygit clone --depth 1 https://github.com/v0id-user/setmacWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00238 | $0.00238 |
| Opus 5 | $0.00119 | $0.00119 |
| Sonnet 5 | $0.00048 | $0.00048 |
| Haiku 4.5 | $0.00024 | $0.00024 |
Grade A, and why
release-policy scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Release Policy
- Use Conventional Commits and keep one logical change per commit.
- Let semantic-release own version bumps. Never hand-edit release versions in
pyproject.toml,cli/pyproject.toml,justfile,scripts/bundle.sh, or__init__.py. - Default to prereleases: push
canaryfor-canary.N, pushbetafor-beta.N. - Only publish stable when the user explicitly asks. Stable releases run through the manual
Release Stableworkflow frommain. - Keep release artifacts as
dist/Setmac.dmgandcli/dist/setmac-cli. - Release builds must run through
scripts/release-build.sh, which signs artifacts and only notarizes when Apple secrets are configured. - If Apple signing secrets are missing, treat builds as ad-hoc signed and include the Gatekeeper workaround in release/install notes:
xattr -cr /Applications/Setmac.app- or Control-click
Setmac.appand chooseOpen
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 17 lines · 238 tokens per session scan A febfec384505
release-policy is a cursor rule published in the GitHub repository v0id-user/setmac (14 stars, last pushed 5mo ago), licensed MIT. It adds 238 tokens to every session, about $0.0012 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
cursorrules
AGENTS.md.
macos-system-integration
Use proper service management for background agents.
performance-optimization
// Use weak/unowned references appropriately class ViewController: UIViewController { private var timer: Timer?
webkit-browser
Cursor rule "webkit-browser" from duckduckgo/apple-browsers, covering webkit & browser development guidelines, webview configuration, basic webview setup, user scripts management and tab management.
commit-and-push
Commit (conventional commit) files and push to the remote repository.
swiftui-advanced
Create reusable ViewModifiers for common styling.