Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/andr-ca/agentharness/database-conventionsgit clone --depth 1 https://github.com/andr-ca/agentharnessWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00040 | $0.01184 |
| Opus 5 | $0.00020 | $0.00592 |
| Sonnet 5 | $0.00008 | $0.00237 |
| Haiku 4.5 | $0.00004 | $0.00118 |
Grade A, and why
database-conventions scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 134 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Database Conventions
Design and operational guidelines for relational databases (PostgreSQL primary dialect; MySQL/SQLite notes included where they differ). Apply these when creating schemas, reviewing migrations, or writing queries.
Naming
- Tables:
snake_case, plural (users,audit_logs,order_items) - Columns:
snake_case, singular (user_id,created_at,is_active) - Primary keys:
id(serial/UUID) - Foreign keys:
<referenced_table_singular>_id(user_id,order_id) - Booleans:
is_orhas_prefix (is_active,has_verified_email) - Timestamps:
created_at,updated_at,deleted_at(UTC, with timezone)
Schema design
- Every table has a primary key. Prefer UUID (
gen_random_uuid()) for distributed or externally-exposed IDs; serial/bigserial for internal join tables where IDs never leave the DB. - Always store timestamps with timezone (
TIMESTAMPTZin Postgres). - Soft-delete via
deleted_at IS NULLfilter, notDELETE— unless you have a clear data retention policy that requires hard deletes. - Avoid
TEXTfor constrained values — use anENUMor a lookup table so the DB enforces the constraint.
-- Good: constrained status field
CREATE TYPE order_status AS ENUM ('pending', 'paid', 'shipped', 'cancelled');
CREATE TABLE orders (
id UUID PRIMARY KEY DEFAULT gen_random_uuid(),
user_id UUID NOT NULL REFERENCES users(id),
status order_status NOT NULL DEFAULT 'pending',
total_cents INTEGER NOT NULL CHECK (total_cents >= 0),
created_at TIMESTAMPTZ NOT NULL DEFAULT NOW(),
updated_at TIMESTAMPTZ NOT NULL DEFAULT NOW()
);
Indexes
- Every foreign key column gets an index (Postgres doesn't auto-index FKs).
- Add an index on any column used in a
WHERE,ORDER BY, orJOINin frequently-run queries. - Composite indexes: column order matters — put equality conditions first, range/sort columns last.
- Don't index every column — indexes slow writes and consume storage.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 134 lines · 40 tokens per session scan A 53ae25f7ffd3
database-conventions is a cursor rule published in the GitHub repository andr-ca/agentharness (1 stars, last pushed yesterday), licensed MIT. It adds 40 tokens to every session and 1,184 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
dreamd-recall
Recall lessons, decisions, and prior context from the .agent/ memory daemon. Use when starting work in a project that has a .agent/ folder, when the user references a past decision, or when you are about to make a choice that has a documented prior.
handoff
Export a Waybill Bundle by default, or import one when explicitly requested.
ui-motion-workflow
Orchestrate motion-aware UI work by sequencing direction, provider choice, implementation, and browser validation.
lemoncrow.execute
LemonCrow execute mode reference for Cursor.
prompt-routing
Route tasks to the correct Universal AI Engineering Prompt.
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.