Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/zunmax/fhevm-skill/fhevm-soliditygit clone --depth 1 https://github.com/zunmax/fhevm-skillWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.08874 |
| Opus 5 | $0.00000 | $0.04437 |
| Sonnet 5 | $0.00000 | $0.01775 |
| Haiku 4.5 | $0.00000 | $0.00887 |
Grade A, and why
fhevm-solidity scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 442 lines — stays where its author put it; the contents beside it link to each section on GitHub.
FHEVM Solidity Rules (v0.11)
This rule set targets @fhevm/[email protected] (Solidity Guides v0.11 on docs.zama.org). Generated code assumes v0.11. Pre-v0.11 patterns (TFHE.*, requestDecryption, SepoliaConfig as Solidity base, neq/lte/gte) are flagged for migration. v0.11-specific identifiers to know: IERC7984ERC20Wrapper interface ID 0x1f1c62b2, inferredTotalSupply() (replaces v0.10 totalSupply()), UnwrapRequested / UnwrapFinalized events carry bytes32 indexed unwrapRequestId.
Contracts operate on opaque bytes32 handles - a coprocessor does FHE computation off-chain.
You CANNOT branch on encrypted values: ebool is a bytes32 UDVT, so require(ebool) and if (ebool) are Solidity compile errors. The bug to flag is when a dev unwraps the handle to a primitive (ebool.unwrap(r) != bytes32(0)) - the non-zero handle always passes.
Setup
pragma solidity ^0.8.28;
import { FHE, euint64, externalEuint64, ebool } from "@fhevm/solidity/lib/FHE.sol";
import { ZamaEthereumConfig } from "@fhevm/solidity/config/ZamaConfig.sol";
contract MyContract is ZamaEthereumConfig { }
Pragma Policy
| Case | Pragma |
|---|---|
| Default for new contracts | ^0.8.28 (matches reference template, hardhat.config.ts uses version: "0.8.28") |
Importing @openzeppelin/confidential-contracts (ERC-7984) |
^0.8.27 minimum (ERC7984.sol declares ^0.8.27) |
| Absolute minimum for FHEVM | ^0.8.24 (only if a dependency pins lower) |
EVM target: "cancun". Do not target a lower EVM version.
ALWAYS / ASK FIRST / NEVER
ALWAYS:
- Read
.cursor/references/anti-patterns.mdbefore writing FHEVM code - Call
FHE.allowThis()after every stored encrypted computation - Call
FHE.allow(result, user)for values users need to decrypt - Use
ZamaEthereumConfig,FHE.fromExternal(),FHE.select() - Run 2-layer verification (references + installed source) on every technical value. Trust hierarchy: source >
.cursor/references/> Zama docs > training knowledge. If layers conflict, source wins. - Grep output for deprecated patterns before delivering
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 442 lines · 0 tokens per session scan A c40c4dc54180
fhevm-solidity is a cursor rule published in the GitHub repository zunmax/fhevm-skill (2 stars, last pushed 2mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 8,874 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
solana-integration-constraints
Constraints and requirements for Solana integration with MetaMask Connect — wallet adapter config, CAIP-2 IDs, network support per platform, RPC routing, and platform limitations.
cadence-nft-standards
Comprehensive standards and best practices for developing Non-Fungible Tokens (NFTs) using Cadence. Ensures proper implementation of NonFungibleToken interfaces, MetadataViews integration for marketplace compatibility, secure resource handling patterns, and advanced modular architectures for complex NFTs with traits…
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
cli-error-handling
CLI command error handling patterns.
prefer-direct-imports-over-module-mocks
Prefer extracting a testable core over vi.mock / vi.resetModules when unit tests need to reach production logic entangled with config, env, or singletons.