Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/virtuslab-open-source/strapi-plugin-mcp/testing-conventionsgit clone --depth 1 https://github.com/VirtusLab-Open-Source/strapi-plugin-mcpWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00009 | $0.01043 |
| Opus 5 | $0.00005 | $0.00522 |
| Sonnet 5 | $0.00002 | $0.00209 |
| Haiku 4.5 | $0.00001 | $0.00104 |
Grade A, and why
testing-conventions scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 107 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Testing Conventions & Techniques
Overview
- Test runner: Vitest (
pnpm test,pnpm test:run,pnpm coverage). - Test files:
**/*.spec.tsor**/*.test.tscolocated with code or underserver/test. - Style: Given/When/Then sections with comments. Behavior-oriented test names.
Structure and Patterns
- Unit tests: Target pure logic in services and tool callbacks. Avoid real Strapi.
- MCP tools: Build tool via its builder with a mock
strapi, callcallback(args, ctx). - Controllers: Keep minimal; test they delegate and shape responses correctly.
- Services: Assert inputs/outputs; use dependency injection for collaborators.
Strapi Mocking
- Prefer lightweight fakes over deep mocks. Use
server/test/strapi.mock.tsfor content types/components. - For specialized cases, create ad-hoc mocks with only required surface:
const strapi = {
config: { get: vi.fn(() => 'value') },
services: { 'api::blog.post': {}, 'plugin::mcp.services': {} },
} as unknown as Strapi;
MCP Tool Testing Recipe
- Build tool:
const tool = getXTool(strapi); - Validate metadata:
name,description,argsSchema(Zod parse with valid/invalid payloads). - Invoke:
const res = await tool.callback(args as any, {} as any); - Extract payload:
const text = (res.content?.[0] as any)?.text; const json = JSON.parse(text ?? '{}'); - Assert
jsonshape:success/isSuccess, data fields, and error messages for negative paths.
Example:
it('returns services list', async () => {
// Given
const strapi = { services: { 'api::blog.post': {}, 'plugin::mcp.services': {} } } as any;
const tool = getServicesTool(strapi);
// When
const res = await tool.callback({}, {} as any);
// Then
const payload = JSON.parse((res.content?.[0] as any).text ?? '{}');
expect(payload.success).toBe(true);
expect(payload.services).toEqual(
expect.arrayContaining([
expect.objectContaining({ fullQualifiedName: 'api::blog.post', type: 'internal', name: 'post' }),
expect.objectContaining({ fullQualifiedName: 'plugin::mcp.services', type: 'plugin', name: 'services', plugin: 'mcp' }),
])
);
});
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 107 lines · 9 tokens per session scan A 4e3c356b73f3
testing-conventions is a cursor rule published in the GitHub repository VirtusLab-Open-Source/strapi-plugin-mcp (3 stars, last pushed 6mo ago), licensed MIT. It adds 9 tokens to every session and 1,043 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
astro-strapi-starter
Astro x Strapi starter — layout, content collections, block renderer vs StrapiBlocks, types.
tailwind-shadcn
Tailwind CSS 4 + shadcn-style UI — global.css, components.json, cn(), Astro + React.
astro-strapi-blocks
Astro + Strapi Blocks — StrapiBlocks, data, theme (extend/overwrite), custom blocks.
astro-strapi-loader
Strapi 5 + @sensinum/astro-strapi-loader — content.config.ts, populate, qs, locales.
api-property-optionality-hygiene
Fix ApiProperty/ApiPropertyOptional optionality mismatches in DTO files; use for scheduled batch fixes or DTO edits.
java-springboot-jpa-cursorrules-prompt-file
description: "Cursor rules for Java development with Springboot and JPA integration." globs: / alwaysApply: false.