Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/zyx379/zoehis_workflow/zoehis-test-datagit clone --depth 1 https://github.com/zyx379/zoehis_workflowWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/zyx379/zoehis_workflow/zoehis-test-data)<a href="https://agentmods.dev/rules/zyx379/zoehis_workflow/zoehis-test-data"><img src="https://agentmods.dev/badge/rules/zyx379/zoehis_workflow/zoehis-test-data.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00323 | $0.00323 |
| Opus 5 | $0.00161 | $0.00161 |
| Sonnet 5 | $0.00065 | $0.00065 |
| Haiku 4.5 | $0.00032 | $0.00032 |
Grade A, and why
zoehis-test-data scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
ZOEHIS 测试库造数(MCP)
功能交付后(docs/workflow.md Step 11),使用 zoe-his-mcp 在 测试库 造数并验证。
约束
- 仅限测试库:
dataSourceId必须指向测试环境;禁止 对生产数据源 INSERT/UPDATE/DELETE - 测试库允许:对任意业务表
INSERT、UPDATE(团队测试库策略) - 验证:写操作后用 SELECT(
query_business_data)核对;符合池表/主细/预交金等业务规则 - 生产排查:仍仅 SELECT,与本规则测试造数分离
推荐步骤
get_table_schema查表结构- 测试库执行 INSERT/UPDATE(造数 SQL 须在回复中摘要)
query_business_dataSELECT 验证- 输出界面手工测试步骤
MCP 工具
get_table_schema— 表结构query_business_data— SELECT 验证(description注明测试验证目的)- 写操作 — 测试库写 SQL 接口(与 SELECT 同源 MCP、测试
dataSourceId)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 29 lines · 323 tokens per session scan A b93819e2e6af
zoehis-test-data is a cursor rule published in the GitHub repository zyx379/zoehis_workflow (2 stars, last pushed 1mo ago), licensed MIT. It adds 323 tokens to every session, about $0.0016 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
prefer-direct-imports-over-module-mocks
Prefer extracting a testable core over vi.mock / vi.resetModules when unit tests need to reach production logic entangled with config, env, or singletons.
test-database-limitations
Test databases created via withDevDatabase() from @repo/test-utils use pglite (an in-memory PostgreSQL implementation via @prisma/dev). Pglite does not support PostgreSQL extensions like pgvector, pgtrgm, etc.
no-bare-casts
No bare as casts in production TypeScript. Use blindCast (value) from @internal/utils/casts as the auditable escape hatch, castAs (value) for declarative-only assertions, or rewrite to eliminate the cast. as const is exempt. Test files are exempt.
no-contract-data-patching-in-tests
Never patch raw contract data in tests; use real emitted fixtures or a user-facing authoring surface.
typed-contract-in-tests
Use typed Contract from fixtures in integration tests.
use-contract-ir-factories
Use factory functions for creating ContractIR objects instead of manual object creation.