Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/bravew/trove/trove-typescriptgit clone --depth 1 https://github.com/bravew/troveWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00721 |
| Opus 5 | $0.00000 | $0.00360 |
| Sonnet 5 | $0.00000 | $0.00144 |
| Haiku 4.5 | $0.00000 | $0.00072 |
Grade A, and why
trove-typescript scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 63 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Trove · v2026.7.4
Session Init
This skill ships Trove conventions. Prefer existing project patterns over generic best practices when they conflict.
If a sibling skill in this plugin matches the request more directly, defer to it. See AGENTS.md (or docs/routing.md in the marketplace) for the per-plugin routing index.
TypeScript Type-System Discipline
The type checker is a proof assistant. Model the domain so wrong states don't compile. On .tsx, defer to trove-react / trove-react-best-practices for component patterns; this skill owns the plain type discipline underneath them.
Core rules
| Rule | Do | Not |
|---|---|---|
| Illegal states | Discriminated union with a kind/status tag |
boolean + optional field pairs |
| Identity | Branded primitives (string & { readonly __brand: 'UserId' }) |
bare string for ids |
| External data | unknown + parse at the boundary |
any |
| Casts | satisfies to check shape while keeping literals |
as SomeType |
| Exhaustiveness | const _exhaustive: never = x in the default branch |
unhandled union members |
| Type guards | Guards that actually narrow and are verified | x as Foo inside the guard |
| Derive | Types derived from a schema (Zod/valibot infer) |
hand-kept parallel types |
The canonical example
// BAD — admits the meaningless { completed: true, completedAt: undefined }
type Task = { completed: boolean; completedAt?: Date };
// GOOD — the bad state cannot be constructed
type Task =
| { status: 'open' }
| { status: 'done'; completedAt: Date };
Boundaries
Validate once, at the edge (network, config, user input). Past the boundary, trust your domain types and keep logic pure. "Parse, don't validate": a parser returns a more precise type or fails; it doesn't just check and discard what it learned.
function parseUser(raw: unknown): User {
return UserSchema.parse(raw); // unknown -> User, or throws at the boundary
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 63 lines · 721 tokens per session scan A 5c2b4756ea63
trove-typescript is a cursor rule published in the GitHub repository bravew/trove (10 stars, last pushed 3d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 721 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
as-contract-cast-smell
// ❌ WRONG — bypasses the family ContractSerializer seam const contract = JSON.parse(raw) as Contract; const contract = JSON.parse(raw) as Contract .
no-barrel-files
Avoid barrel files and unnecessary re-exports.
vue-typescript-patterns
Cursor rule "vue-typescript-patterns" from soaring-xiongkulu/easyaiot, covering vue3 + typescript 开发规范, vue 组件规范, vue sfc 组件规范, typescript 规范 and 状态管理.
project-overview
这是一个基于 uniapp + Vue3 + TypeScript + Vite5 + UnoCSS 的跨平台开发框架。.
compose-resource-lifecycles-with-layermerge
Cursor rule "compose-resource-lifecycles-with-layermerge" from PaulJPhilp/EffectPatterns, covering compose resource lifecycles with layer.merge and example.
frontend-patterns
React/TypeScript patterns for src/ code.