Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/virtuslab-open-source/strapi-plugin-mcp/mcp-integrationgit clone --depth 1 https://github.com/VirtusLab-Open-Source/strapi-plugin-mcpWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00497 |
| Opus 5 | $0.00000 | $0.00249 |
| Sonnet 5 | $0.00000 | $0.00099 |
| Haiku 4.5 | $0.00000 | $0.00050 |
Grade A, and why
mcp-integration scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 73 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Model Context Protocol (MCP) Integration Guidelines
MCP Overview
This plugin integrates Model Context Protocol functionality into Strapi, enabling AI models to interact with Strapi content and system information.
Core MCP Dependencies
@modelcontextprotocol/sdk- Primary SDK for MCP functionalityzod- Schema validation for MCP data structures
MCP Service Architecture
Content Types Service (server/src/services/contentTypes.service.ts)
- Provides introspection of Strapi content types
- Exposes content type schemas and relationships
- Handles content type metadata for MCP clients
Strapi Info Service (server/src/services/strapiInfo.service.ts)
- Exposes Strapi system information
- Provides version and configuration details
- Offers plugin and system status information
Events Controller (server/src/controllers/events.controller.ts)
- Handles MCP event processing
- Manages communication between MCP clients and Strapi
- Processes MCP requests and responses
MCP Protocol Implementation
- Follow MCP specification for message formats
- Use proper error handling for MCP operations
- Implement appropriate authentication and authorization
- Ensure data validation using Zod schemas
Data Exposure Guidelines
- Only expose necessary Strapi information through MCP
- Implement proper access controls for sensitive data
- Validate all incoming MCP requests
- Sanitize data before sending to MCP clients
Error Handling for MCP
- Use MCP-compliant error formats
- Provide meaningful error messages
- Log MCP-related errors for debugging
- Handle network and protocol errors gracefully
Security Considerations
- Validate all MCP inputs
- Implement rate limiting for MCP endpoints
- Use proper authentication mechanisms
- Audit MCP operations for security compliance
Testing MCP Integration
- Test MCP protocol compliance
- Verify data integrity in MCP responses
- Test error scenarios and edge cases
- Validate performance under load
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 73 lines · 0 tokens per session scan A 6a09e73883ac
mcp-integration is a cursor rule published in the GitHub repository VirtusLab-Open-Source/strapi-plugin-mcp (3 stars, last pushed 6mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 497 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
long-running-agents
Best practices for long-running agents (initializer/coding pattern, incremental progress, clean state).
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
cli-error-handling
CLI command error handling patterns.
prefer-direct-imports-over-module-mocks
Prefer extracting a testable core over vi.mock / vi.resetModules when unit tests need to reach production logic entangled with config, env, or singletons.
control-plane-descriptors
Control plane descriptor and instance implementation patterns.