Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add pekral/cursor-rules --skill pr-staged-merge-plangit clone --depth 1 https://github.com/pekral/cursor-rulesWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/pekral/cursor-rules/pr-staged-merge-plan)<a href="https://agentmods.dev/skills/pekral/cursor-rules/pr-staged-merge-plan"><img src="https://agentmods.dev/badge/skills/pekral/cursor-rules/pr-staged-merge-plan/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/pekral/cursor-rules/pr-staged-merge-plan"><img src="https://agentmods.dev/badge/skills/pekral/cursor-rules/pr-staged-merge-plan.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00097 | $0.03059 |
| Opus 5 | $0.00048 | $0.01529 |
| Sonnet 5 | $0.00019 | $0.00612 |
| Haiku 4.5 | $0.00010 | $0.00306 |
Grade A, and why
pr-staged-merge-plan scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 113 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Constraints
- Apply
@rules/git/general.mdc— every proposed commit subject follows Commit Messages (English,type(scope): short description, lowercase, allowed types only, no trailing period) and every proposed unit follows One phase = one commit. - Read-only. Never run
git rebase,git commit --amend,git cherry-pick,git reset,git push,gh pr merge, orgh pr edit. This skill produces a plan; a human or a follow-up skill executes it. - Load PR context only through
skills/code-review-github/scripts/load-issue.sh <NUMBER|URL>. Never callgh pr view/gh api /repos/.../pulls/...directly; fall back to the GitHub MCP server only when the loader is unavailable (exit code 2/3). Localgit log/git diffreads against the loaded base and head refs are expected and allowed. - Merging a unit is owned by
@skills/merge-github-pr/SKILL.md; interactive-rebase, conflict, and force-with-lease mechanics are owned by@skills/git-workflow/SKILL.md. Reference them — do not restate them. - Commit-level reshaping inside one PR is owned by
@rules/git/general.mdcGit Rules, not by this skill. This skill is the on-demand deeper plan: it splits the work into several pull requests, each with its own review-and-merge gate — the answer for units that cannot ship inside one PR (destructive migration, consumer-contract change needing expand → migrate → contract across deploys). - Every unit is its own pull request and carries its own hard code-review gate (
@rules/git/general.mdcMerging): the plan never proposes merging a unit whose own diff has not been reviewed to 0 Critical + 0 Moderate. - No work may be dropped or re-scoped. The union of the proposed units must equal the current PR's diff exactly — same files, same net content. State this reconciliation explicitly in the output.
- Do not publish the plan anywhere unless the user asks for it. When asked, apply
@rules/reports/general.mdc(assignment language) and post it viaskills/code-review-github/scripts/upsert-comment.sh <NUMBER|URL> -— never a rawgh pr comment.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 113 lines · 97 tokens per session scan A 07035ac78bbf
pr-staged-merge-plan is a skill published in the GitHub repository pekral/cursor-rules (7 stars, last pushed 9d ago), licensed MIT. It adds 97 tokens to every session and 3,059 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
git-workflow-and-versioning
Structures git workflow practices. Use when making any code change. Use when committing, branching, resolving conflicts, splitting uncommitted work in a messy working tree into clean atomic commits, opening or reviewing a pull request (PR), pushing to a remote, or when you need to organize work across multiple…
finishing-a-development-branch
A process for finishing a completed development branch. A branch is a separate line of code changes that can later be merged or submitted as a pull request.
skillshare-changelog
Generate CHANGELOG.md entry from recent commits in conventional format. Also syncs the website changelog page. Use this skill whenever the user asks to: generate a changelog, document what changed between tags, or create a new CHANGELOG entry. If you see requests like "write the changelog for v0.17", "what changed…
skillshare-release
End-to-end release workflow for skillshare. Runs tests, generates changelog (via /changelog), optionally writes local RELEASENOTES, updates version numbers, commits, and drafts announcements. Use when the user says "release", "prepare release", "cut a release", "release v0.19", or any request to publish a new version.…
github-release-briefing-skill
Create a source-linked briefing for the latest published GitHub release of a public repository. Use for engineering teams tracking a dependency release; do not use it to publish releases or change repositories.
devops/changelog-generation
A method for creating a CHANGELOG, a document that records what changed in each software release. It reads Git commit history and release-pipeline reports, then groups changes using common commit and changelog conventions.