Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/xi-kari/crossframe-skill/crossframegit clone --depth 1 https://github.com/xi-kari/crossframe-skillWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.01287 |
| Opus 5 | $0.00000 | $0.00643 |
| Sonnet 5 | $0.00000 | $0.00257 |
| Haiku 4.5 | $0.00000 | $0.00129 |
Grade A, and why
crossframe scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 42 lines — stays where its author put it; the contents beside it link to each section on GitHub.
When a task involves complex relationships, teams, organizations, institutions, public disputes, structural diagnosis, 推演, 开放断言, 反俘获审查, 低条件试探行动, 强判断, 高反身性, 亲密关系, 疗愈转移, 公共制度, 框架边界, 生命周期, 递进闭环, 势场解离, 治理连续性, 超大规模压力测试, long-term evolution, or concept explanation, read skills/crossframe/SKILL.md first, then skills/crossframe/references/read-routing-map.md.
If the task needs multiple CrossFrame skills in sequence, such as public commentary, organization repair writing, debate-to-essay, reading-note-to-essay, casebook plus review, or post-completion inquiry, read skills/crossframe-suite/SKILL.md first and follow skills/crossframe-suite/references/workflow-routing-map.md. Do not read every sibling skill at once.
For any CrossFrame content task where the user has not explicitly disabled articles, prefer crossframe-suite; it defaults to full-visible-v5-longform after the needed sibling skills: complete visible structural dossier plus complete long-form article.
If the task asks for 中文文章、长文、评论、思想文章、批判性洞察文章, or turning CrossFrame reasoning into readable prose, use skills/crossframe-essay/SKILL.md and .cursor/rules/crossframe-essay.mdc instead of stopping at this diagnostic rule.
If the task asks for review/audit, short reader reply, casebook, history research, post-completion inquiry, public issue, organization repair, concept teaching, debate analysis, or research notebook, read the matching skills/crossframe-*/SKILL.md first: crossframe-review, crossframe-dialogue, crossframe-casebook, crossframe-history, crossframe-inquiry, crossframe-public, crossframe-org, crossframe-teach, crossframe-debate, or crossframe-notebook.
If the task explicitly asks for crossframe-max, maximum CrossFrame mode, exhaustive structural projection, full-scale world-model interpretation, or no word-limit complete explanation, read skills/crossframe-max/SKILL.md. This is an independent mode; do not route it through the suite 2+1 selector or ordinary article-type selector.
CrossFrame ProMax is a v8-only, exact-name only independent skill. Read skills/crossframe-promax/SKILL.md only for crossframe-promax, CrossFrame ProMax, $crossframe-promax, or /crossframe-promax. If both Max and ProMax are named, ProMax wins; generic maximality remains Max; suite never auto-upgrades; ProMax uses its own audit with no review chain and never falls back to Max.
After a completed suite workflow has produced diagnosis, article, and review, any substantive follow-up without an explicit new-task/exit or pure acknowledgment/thanks signal should route to skills/crossframe-inquiry/SKILL.md by default. Pure acknowledgments or endings such as "谢谢", "好的", "明白了", or "先这样" should only close lightly. The inquiry layer may do targeted retrieval from 1-3 relevant sibling skills for question design, counterexamples, transfer conditions, and risk boundaries, but it must not turn that retrieval into a formal sibling judgment.
Use Chinese as the authoritative semantic layer. CrossFrame is only the传播名 / skill id.
Before the final answer, show a concise 推理提纲 with:
- 诊断对象
- 事实边界
- 尺度窗口
- 机制候选
- 判断档位
- 本次读取的概念
- 下一步
Do not use concept piles as conclusions. Translate terms such as 承接, 回流, 开放断言, 责任链, 观测反身性 into concrete behavior and evidence. Do not turn structural diagnosis into personality judgment, fate prediction, responsibility dilution, or compliance theater.
If any high-risk concept carries the judgment, read skills/crossframe/references/concept-cards/README.md and the corresponding concept card before answering. Use skills/crossframe/references/runtime-read-policy.md and skills/crossframe/references/continuity-closure-map.md to ensure the compressed output still preserves concept evidence requirements, failure mechanisms, repair actions, and continuous-reading constraints.
If the task involves high responsibility, public institutions, intimate relationships, long-term evolution, deep analysis, or essay/article output, read skills/crossframe/references/runtime-read-policy.md, skills/crossframe/references/read-routing-map.md, and skills/crossframe/references/continuity-closure-map.md first. When an expanded audit is needed, check skills/crossframe/references/continuity-bundles.md, skills/crossframe/references/v5-source-spine.md, skills/crossframe/references/v5-section-digest-index.md, and skills/crossframe/worksheets/source-continuity-check.md so the model does not read a single concept card and lose the v5.0 source continuity.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 42 lines · 0 tokens per session scan A 3254bba418ed
crossframe is a cursor rule published in the GitHub repository xi-kari/crossframe-skill (18 stars, last pushed 25d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 1,287 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
evaluation-protocol
Evaluation protocol for blind skill testing across model tiers.
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
typescript
Changes to these high-fan-out internals can affect every message, delta, element, or rerun. Keep work in them minimal, and benchmark changes with representative stress-test apps.
coolify-ai-docs
Master reference to all Coolify AI documentation in .ai/ directory.
python_lib
Tips and guidelines specific to the development of the Streamlit Python library, not applicable to scripts and e2e tests.