Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/williamisnotdefined/rubiks-cube-solver/wca-data-boundarygit clone --depth 1 https://github.com/williamisnotdefined/rubiks-cube-solverWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/williamisnotdefined/rubiks-cube-solver/wca-data-boundary)<a href="https://agentmods.dev/rules/williamisnotdefined/rubiks-cube-solver/wca-data-boundary"><img src="https://agentmods.dev/badge/rules/williamisnotdefined/rubiks-cube-solver/wca-data-boundary.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.02541 |
| Opus 5 | $0.00000 | $0.01270 |
| Sonnet 5 | $0.00000 | $0.00508 |
| Haiku 4.5 | $0.00000 | $0.00254 |
Grade A, and why
wca-data-boundary scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 169 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Generated from ai/registry.json. Do not edit manually.
Canonical skill: ../../ai/skills/wca-data-boundary.md.
Referenced context:
../../ai/rules/wca-data-rules.md../../ai/rules/frontend-rules.md../../ai/rules/testing-rules.md../../ai/architecture/wca-data.md
This file is compiled from canonical AI knowledge files. Edit canonical files under ai, then run npm run ai:sync.
Compiled AI Skill: wca-data-boundary
Canonical Skill: ai/skills/wca-data-boundary.md
WCA Data Boundary
Use for the WCA Data workspace, OpenAPI contract, import worker, PostgreSQL lifecycle, or web WCA client.
Read First
ai/rules/wca-data-rules.mdai/rules/frontend-rules.mdai/rules/testing-rules.mdai/architecture/wca-data.md
Workflow
- Identify whether the change owns public API, canonical data, import, persistence, worker, or web consumption.
- Preserve contract-first OpenAPI and dataset metadata; keep Axum/Nginx routing aligned around the non-localized 308 docs redirect.
- Use fixture/disposable verification unless a real target was explicitly approved.
- Run WCA build/tests and the relevant web client tests; run public smoke only against an intentional available target.
Referenced Context
Reference: ai/rules/wca-data-rules.md
WCA Data Rules
- Treat
apps/wca-data/openapi/wca-data-v1.yamland contract tests as the public API contract. - Keep import, canonical domain, public API, persistence, and worker concerns separately owned.
- Validate archive size and expected entries; extract only expected TSV files.
- Run local write checks with
npm run wca:sync-once -- --fixture. Real sync and persistent migrations require explicit target approval. - Never execute downloaded SQL or expose fixture data in production. A successful production import retains only the active dataset; retired and failed datasets are removed after atomic publication, so rollback requires a backup or fresh verified import.
- Verify workspace changes with
npm run wca:buildandnpm run wca:test; use the public smoke command only when the target is intentional and available.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 169 lines · 0 tokens per session scan A 5904a438c0eb
wca-data-boundary is a cursor rule published in the GitHub repository williamisnotdefined/rubiks-cube-solver (4 stars, last pushed 10d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 2,541 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
prefer-assertions-over-defensive-checks
Prefer assertions over defensive checks when data is guaranteed to be valid.
as-contract-cast-smell
// ❌ WRONG — bypasses the family ContractSerializer seam const contract = JSON.parse(raw) as Contract; const contract = JSON.parse(raw) as Contract .
no-backward-compatibility
Do not add backward-compatibility shims or migration scaffolding.
sqlmodel
Satisfying the type checker when working with SQLModel.
database
Database architecture, schema design, Prisma, Drizzle ORM, indexing strategies, migrations, and N+1 query resolution.
create-rls-policies
Guidelines for writing Postgres migrations.