tokrepo agent discovery
via PatrickJS/awesome-cursorrules
Safely discover and verify reusable AI artifacts before building or installing them.
What is tokrepo agent discovery?
This rule gates the creation and installation of reusable artifacts (skills, prompts, MCP configs, scripts) by requiring local-first discovery, verification, and dry-run testing before any environment changes. Use it when building or installing reusable work to avoid duplicating existing solutions and to enforce security checks.
- Prefer local TokRepo discovery over hosted; use hosted only with explicit user opt-in and redacted task text
- Verify artifacts with tokrepo_verify and tokrepo_install_plan before any install, blocking on policy denial or out-of-scope writes
- Run lifecycle operations (install, update, uninstall, rollback) in dry-run mode by default until user explicitly confirms
- Generate read-only handoff plans after producing reusable artifacts; never auto-publish
- Strip secrets, absolute paths, and sensitive data before any push; default to private visibility
Applies to
File patterns this rule matches.
Rule definition (reference)
Source of truth, from the repository.
-
DISCOVER BEFORE BUILD, LOCAL FIRST: Before generating any reusable artifact matched by this rule (a
SKILL.md, a*.prompt.md, a.mcp.json, an MCP tool config, or a reusable script inscripts/), prefer the local TokRepo MCP server. For private or sensitive work, use local discovery or skip discovery. Use hosted TokRepo discovery only after explicit user opt-in, and redact task text before sending it to the hosted service athttps://tokrepo.com/mcp. If MCP is unavailable and hosted use is approved, use the CLI fallbacknpx -y tokrepo@<reviewed-version> agent-check "<redacted task>" --json. If a candidate returns withtrust_score_v2 >= 0.7ANDagent_fit >= 0.7, surface it and ask before reusing it. If candidates exist buttrust_score_v2 < 0.7, surface them and ask before proceeding. -
VERIFY BEFORE INSTALL: Before any install or write to the user environment, you MUST call
tokrepo_verifyandtokrepo_install_plan. Ifpolicy_decision.decision === "deny": STOP. Ifpermission_enveloperequests writes outside the declared scope (global config, secrets, network egress, absolute paths): STOP and confirm with the user explicitly. Recordcontent_hash,install_plan_hash, andtrust_score_v2as evidence. -
DRY-RUN BEFORE APPLY: Lifecycle tools (
tokrepo_codex_install,tokrepo_update,tokrepo_uninstall,tokrepo_rollback) defaultdry_run: true. Keepdry_run: trueuntil the user has surfaced the plan and explicitly confirmeddry_run: falsefor that specific operation in this session. -
HANDOFF AFTER REUSABLE WORK: After producing reusable artifacts (skills, prompts, MCP configs, scripts), call
tokrepo_handoff_planlocally when available, or usenpx -y tokrepo@<reviewed-version> agent-handoff --jsonafter reviewing the package version. It returns a READ-ONLY draft plan that never auto-publishes. Ask the user before anytokrepo_push. -
PRIVATE BY DEFAULT, NEVER PUSH SECRETS:
tokrepo_pushdefaults tovisibility: 0(private). Public publishing requires explicit per-push confirmation. Before any push, strip env tokens, absolute paths, project-specific names, and secret patterns. Iftokrepo_handoff_planflagged a file as sensitive, do not override.
How to install
# One-time per project - bootstraps .cursor/rules/tokrepo.mdc plus a machine-readable
# .tokrepo/agent.json that the MCP server reads on every planning call.
npx -y tokrepo@<reviewed-version> init-agent --target cursor
Resources
- Hosted MCP endpoint (read-only, no auth):
https://tokrepo.com/mcpafter explicit user opt-in and redacted task text - Local MCP server:
npx -y tokrepo-mcp-server@<reviewed-version> - Published tool catalog: 15 tools in
https://tokrepo.com/.well-known/tool-catalog.json - Trust manifest:
https://tokrepo.com/.well-known/tokrepo-trust.json - Default policy pack:
https://tokrepo.com/policy-packs/default-agent-policy.json - Tool catalog:
https://tokrepo.com/.well-known/tool-catalog.json - Public agent funnel (anonymous):
https://tokrepo.com/agent-stats - Source: https://github.com/henu-wang/tokrepo-mcp-server
Related rules
Disciplined, quiet design system with restrained color, clear hierarchy, and accessibility-first approach.
TypeScript coding standards and best practices for modern web development
TypeScript development patterns with Axios HTTP client integration.
TypeScript and Google Apps Script development with clasp integration
TypeScript code conventions for Node.js, Next.js, React, Expo, tRPC, and Tailwind projects.
TypeScript, React Native, Expo, Jest, and Detox best practices for mobile development.
