Tokrepo Agent Discovery
Use TokRepo discovery safely before rebuilding reusable AI artifacts. Prefer local discovery or skip for private work; use hosted discovery only with user opt-in and redacted task text. Gates installs through tokrepo_verify + tokrepo_install_plan; uses tokrepo_handoff_plan after producing reusable work.
Awesome CursorRulesv10 stars · 0 forks · 0 makes≈786 tokens
-
DISCOVER BEFORE BUILD, LOCAL FIRST: Before generating any reusable artifact matched by this rule (a
SKILL.md, a*.prompt.md, a.mcp.json, an MCP tool config, or a reusable script inscripts/), prefer the local TokRepo MCP server. For private or sensitive work, use local discovery or skip discovery. Use hosted TokRepo discovery only after explicit user opt-in, and redact task text before sending it to the hosted service athttps://tokrepo.com/mcp. If MCP is unavailable and hosted use is approved, use the CLI fallbacknpx -y tokrepo@<reviewed-version> agent-check "<redacted task>" --json. If a candidate returns withtrust_score_v2 >= 0.7ANDagent_fit >= 0.7, surface it and ask before reusing it. If candidates exist buttrust_score_v2 < 0.7, surface them and ask before proceeding. -
VERIFY BEFORE INSTALL: Before any install or write to the user environment, you MUST call
tokrepo_verifyandtokrepo_install_plan. Ifpolicy_decision.decision === "deny": STOP. Ifpermission_enveloperequests writes outside the declared scope (global config, secrets, network egress, absolute paths): STOP and confirm with the user explicitly. Recordcontent_hash,install_plan_hash, andtrust_score_v2as evidence. -
DRY-RUN BEFORE APPLY: Lifecycle tools (
tokrepo_codex_install,tokrepo_update,tokrepo_uninstall,tokrepo_rollback) defaultdry_run: true. Keepdry_run: trueuntil the user has surfaced the plan and explicitly confirmeddry_run: falsefor that specific operation in this session. -
HANDOFF AFTER REUSABLE WORK: After producing reusable artifacts (skills, prompts, MCP configs, scripts), call
tokrepo_handoff_planlocally when available, or usenpx -y tokrepo@<reviewed-version> agent-handoff --jsonafter reviewing the package version. It returns a READ-ONLY draft plan that never auto-publishes. Ask the user before anytokrepo_push. -
PRIVATE BY DEFAULT, NEVER PUSH SECRETS:
tokrepo_pushdefaults tovisibility: 0(private). Public publishing requires explicit per-push confirmation. Before any push, strip env tokens, absolute paths, project-specific names, and secret patterns. Iftokrepo_handoff_planflagged a file as sensitive, do not override.
How to install
# One-time per project - bootstraps .cursor/rules/tokrepo.mdc plus a machine-readable
# .tokrepo/agent.json that the MCP server reads on every planning call.
npx -y tokrepo@<reviewed-version> init-agent --target cursor
Resources
- Hosted MCP endpoint (read-only, no auth):
https://tokrepo.com/mcpafter explicit user opt-in and redacted task text - Local MCP server:
npx -y tokrepo-mcp-server@<reviewed-version> - Published tool catalog: 15 tools in
https://tokrepo.com/.well-known/tool-catalog.json - Trust manifest:
https://tokrepo.com/.well-known/tokrepo-trust.json - Default policy pack:
https://tokrepo.com/policy-packs/default-agent-policy.json - Tool catalog:
https://tokrepo.com/.well-known/tool-catalog.json - Public agent funnel (anonymous):
https://tokrepo.com/agent-stats - Source: https://github.com/henu-wang/tokrepo-mcp-server