Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/zotoio/CRUX-CompressWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/zotoio/crux-compress/zip-contents-protection.crux)<a href="https://agentmods.dev/rules/zotoio/crux-compress/zip-contents-protection.crux"><img src="https://agentmods.dev/badge/rules/zotoio/crux-compress/zip-contents-protection.crux/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/rules/zotoio/crux-compress/zip-contents-protection.crux"><img src="https://agentmods.dev/badge/rules/zotoio/crux-compress/zip-contents-protection.crux.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00495 | $0.00495 |
| Opus 5 | $0.00247 | $0.00247 |
| Sonnet 5 | $0.00099 | $0.00099 |
| Haiku 4.5 | $0.00049 | $0.00049 |
Grade A, and why
zip-contents-protection.crux scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
[!IMPORTANT] Generated file - do not edit!
Zip Contents Protection Rule
⟦CRUX:zip-contents-protection.md
P.⊛{¬auto-Δ scripts/create-crux-zip.py w/o user req!}
Κ{script=scripts/create-crux-zip.py→dist;
manifest=.crux/dist-manifest.json}
P.never{auto-add: .cursor/rules/*.mdc|.cursor/skills/*/|
scripts/*.py|any files}
P.only{Δ zip: user says
"add to dist zip"|"include in release"|"modify zip contents"}
Λ.add{w/ perm→1.Δ script +path;
2.run script→manifest records path;
3.Δ CONTRIBUTORS.md; 4.warn: +→ver bump}
M.zip{CRUX.md;install.crux.md;AGENTS.crux.md←AGENTS.md;
.crux/[crux.json,crux-release-files.json];
.cursor/[hooks.json,
agents/crux/crux-cursor-[rule-manager,memory-manager,
meditation-guide].md,
commands/crux/crux-[compress,amnesia,dream,forget,
meditate,recall,remember].md,
hooks/crux-[detect-changes,detect-memory-changes,
session-start].py,
rules/crux/[_CRUX-RULE.mdc,
crux-memories-integration.crux.mdc],
skills/crux/[crux-utils/[SKILL.md,scripts/crux-utils.py],
crux-skill-memory-[crud,compress,extract,index,
rebalance,reference-tracker]/SKILL.md,
crux-skill-memory-index/scripts/[memory-index.py,
post-dream.py],
crux-skill-memory-meditation-[research,quick,ensemble,
review,report,coordination]/SKILL.md]]}
Ω{dist=minimal;+→[↑size,?conflicts,↑updates,↑maint]}
⟧
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 57 lines · 495 tokens per session scan A 683807b94768
zip-contents-protection.crux is a cursor rule published in the GitHub repository zotoio/CRUX-Compress (8 stars, last pushed 5d ago), licensed MIT. It adds 495 tokens to every session, about $0.0025 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
mcp-releasing
Steps and procedures for releasing MCP (Model Context Protocol) servers as NPM packages.
add-to-changelog
Update the project's CHANGELOG.md file with a new entry.
releasing
How to release AdLoop to PyPI — version bumping, tagging, and publishing.
release
Changesets release pipeline - version PR, shared vX.Y.Z tag, CI gate before tagging, no npm publish, GITHUBTOKEN tag trigger limitation.
cd
GitHub Actions CD - called by release.yml after the tag, no push-tags trigger, Cloudflare versions upload then 100% promote, scoped API token on the production environment, GitHub-owned deployment record.
changeset
Guidelines for using Changesets (npm run changeset) to manage versioning and changelogs.