Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/zifeo/lade/message-boxgit clone --depth 1 https://github.com/zifeo/ladeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00012 | $0.00362 |
| Opus 5 | $0.00006 | $0.00181 |
| Sonnet 5 | $0.00002 | $0.00072 |
| Haiku 4.5 | $0.00001 | $0.00036 |
Grade A, and why
message-box scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
stderr output must always use MessageBox
Never use eprintln! for user-facing messages. Every message shown to the user — error, warning, or info — must go through message_box::MessageBox.
eprintln! silently bypasses the box, producing bare unformatted output regardless of context (Quiet mode, interactive mode, etc.).
The pattern that broke this
The is_interactive() / UiMode::Quiet flag controls interactive behaviour (countdowns, prompts, sleeps). It must never suppress the MessageBox itself — not for errors, not for warnings.
// ❌ BAD — Quiet mode skips the box entirely
if ctx.is_interactive() {
message_box::MessageBox::new().error()...print_stderr();
sleep_or_cancel(5).await;
} else {
eprintln!("lade: {e}"); // bare, no box
}
// ❌ BAD — same mistake for warnings
if ctx.is_interactive() && !warnings.is_empty() {
message_box::MessageBox::new().warning()...print_stderr();
sleep_or_cancel(5).await;
}
// ✅ GOOD — box always; only the interactive parts are gated
let mut mb = message_box::MessageBox::new()
.error() // or .warning()
.paragraph(e.to_string());
if ctx.is_interactive() {
mb = mb.line("Waiting 5 seconds before continuing... (2x Ctrl-C to cancel)");
}
mb.print_stderr();
if ctx.is_interactive() {
sleep_or_cancel(5).await;
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 43 lines · 12 tokens per session scan A c0645745ba25
message-box is a cursor rule published in the GitHub repository zifeo/lade (127 stars, last pushed 12d ago), licensed MPL-2.0. It adds 12 tokens to every session and 362 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
next
Next.js roof. Bundled docs for THIS next version. App vs Pages from the tree.
cloudflare-tunnel-routes
Persistent HTTPS URL for local Gradio/Streamlit/FastAPI/webhook services without deploying. Use when the user wants a stable permanent URL on a domain they own (not a throwaway URL, not managed hosting).
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
typescript
Changes to these high-fan-out internals can affect every message, delta, element, or rerun. Keep work in them minimal, and benchmark changes with representative stress-test apps.
coolify-ai-docs
Master reference to all Coolify AI documentation in .ai/ directory.