Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add kensaurus/cursor-kenji --skill enhance-arch-boundariesgit clone --depth 1 https://github.com/kensaurus/cursor-kenjiWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/kensaurus/cursor-kenji/enhance-arch-boundaries)<a href="https://agentmods.dev/skills/kensaurus/cursor-kenji/enhance-arch-boundaries"><img src="https://agentmods.dev/badge/skills/kensaurus/cursor-kenji/enhance-arch-boundaries/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/kensaurus/cursor-kenji/enhance-arch-boundaries"><img src="https://agentmods.dev/badge/skills/kensaurus/cursor-kenji/enhance-arch-boundaries.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00066 | $0.01645 |
| Opus 5 | $0.00033 | $0.00822 |
| Sonnet 5 | $0.00013 | $0.00329 |
| Haiku 4.5 | $0.00007 | $0.00164 |
Grade A, and why
enhance-arch-boundaries scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 155 lines — stays where its author put it; the contents beside it link to each section on GitHub.
enhance-arch-boundaries — Architecture as a fitness function
Degree of freedom: MIXED — T1 is the priority. Recovering the model
[HIGH freedom]; do-not-invent, shrink-only baseline, and deliberate-violation
probes [LOW freedom — run exactly].
Codify the repo's intended structure as rules that block merge. Import spaghetti is how agents degrade architecture: each import looks locally reasonable, no single diff is wrong, and after forty sessions the layering is gone. A rule in AGENTS.md is advisory. A dependency-cruiser rule in the aggregator gate is physics.
This skill vs neighbors
| Skill | Owns |
|---|---|
| enhance-arch-boundaries (this) | Mechanical boundary rules + shrink-only baseline |
audit-backend-architecture |
Advises which pattern to adopt — does not enforce |
housekeep-gates |
Wires this check into the aggregator |
docs-adr |
Records why the model was chosen |
enhance-agent-guardrails |
Broader guard install; this owns the import graph |
How to reason
- Observe — folder layout, existing conventions, any architecture audit
- Interpret — what layering does the repo already mean to have?
- Classify — recoverable model / no intended structure (stop) / inventing (forbidden)
- Severity — client → server-only / service-role is the worst edge
Worked example
Observe:
app/dashboard/page.tsximports@/lib/supabase/admin(service-role). No boundary rule. Interpret: the intended split exists in folder names but is not physics. Classify: forbidden edge — client → server-only. Fix: dependency-cruiser / eslint-boundaries rule; grandfather other violations into a shrink-only baseline; probe a new forbidden import fails CI.
Phase 0 — Recover the intended architecture (do not invent one) [LOW freedom — stop if none]
The rules must encode the architecture the repo means to have.
- Read folder structure and existing conventions (
features/*,app/,lib/,server/,components/, monorepo packages). - Read
audit-backend-architectureoutput if it exists — that is the drift to stop. - Confirm with the user in one pass: layers and allowed direction (e.g.
ui → application → domain → infrastructure, never reverse), feature units that must stay isolated, special zones (server-only, secrets, generated).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 155 lines · 66 tokens per session scan A fac0ad5ac9dc
enhance-arch-boundaries is a skill published in the GitHub repository kensaurus/cursor-kenji (9 stars, last pushed 11d ago), licensed MIT. It adds 66 tokens to every session and 1,645 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
refactor
Guides a refactor, cleanup, or restructure with the right decomposition. Use when the user asks to refactor, simplify, extract, or modernize code.
work-with-pr
Full PR lifecycle in a fresh task-owned git worktree: implement via the ulw-loop skill with mandatory evidence-bound manual QA → reviewer-readable English PR → verification loop (CI + Cubic, where Cubic is skipped only when its quota is exhausted) → merge by default → worktree cleanup. Decomposes one task into the…
remove-ai-slops
Removes AI-generated code smells from branch changes or an explicit file list behind regression tests. Use when the user asks to clean up, deslop, or remove AI-slop patterns from recent changes.
review-work
Post-implementation gate review: run manual QA on the real surface yourself, then launch ONE gate reviewer (never a panel) to audit goal, constraints, code quality, security, missed context, and QA evidence. Use before a PR handoff or when the user explicitly asks to review completed work.
tech-debt-audit
Thorough, file-cited technical debt audit across 9 dimensions using AST-grep (tree-sitter), grep, LSP, and language-native tooling. Produces TECHDEBTAUDIT.md with severity, effort estimates, and prioritized fixes. Use when asked for codebase health check, tech debt audit, architecture review, code quality assessment…
code-review
Use when asked to review a PR, MR, branch, or diff, audit changed files, or check code quality.