16-developer-hub-app-architect

A set of development rules for building Contentstack Developer Hub and Marketplace apps. Contentstack is a platform for managing content, while Developer Hub is its place for extending that platform with apps.

In plain words
What is it for?
Designing and building React/TypeScript Contentstack apps, generating boilerplate-aligned code, and troubleshooting loading, iframe, route, and integration problems.
Why use it?
It helps developers choose where a feature belongs and avoid common mistakes with app setup, manifests, routes, proxies, OAuth, SDKs, and publishing.

Cursor rule

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/contentstack/contentstack-agent-skills/16-developer-hub-app-architect
Clone the repo
git clone --depth 1 https://github.com/contentstack/contentstack-agent-skills
Per session 48 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,957 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00048 $0.01957
Opus 5 $0.00024 $0.00979
Sonnet 5 $0.00010 $0.00391
Haiku 4.5 $0.00005 $0.00196

Measured yesterday against content hash 0654d20a4c1b, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

16-developer-hub-app-architect scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

cursor/rules/16-developer-hub-app-architect.mdc · 184 lines

How it starts

The opening of the file, as written. The whole thing — 184 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Developer Hub App Architect

Description

Turn Contentstack Developer Hub and Marketplace app ideas into concrete implementations. Choose the right UI location, map the architecture, generate boilerplate-aligned React/TypeScript code, and troubleshoot setup, SDK, manifest, proxy, and publishing issues.

When to Use

Use when a user needs help designing or building a Contentstack Developer Hub or Marketplace app. Use when choosing the right UI location for a feature. Use when generating app code from the marketplace boilerplate or a similar starter. Use when explaining manifest, setup, proxy, OAuth, or publishing steps. Use when debugging app loading, SDK, iframe, route, or location issues.

User Problem

Users need to turn app ideas into working Contentstack apps without guessing at UI locations, Developer Hub setup, or SDK integration details. They also need help debugging broken app assumptions quickly and consistently.

Success Criteria

Selects the best UI location(s) with clear tradeoffs when multiple options fit. Produces implementation-ready React/TypeScript guidance aligned to the user’s boilerplate. Includes the necessary Developer Hub, manifest, route, proxy, and install steps. Avoids exposing secrets and keeps credentials server-side. Uses a repeatable troubleshooting checklist for broken apps.

Expected Inputs

  • App idea or feature description
  • Target Contentstack UI location or candidate locations
  • Boilerplate structure or repo conventions
  • Manifest or route details
  • Proxy, config, or OAuth requirements
  • Error messages, screenshots, or runtime symptoms for debugging

Expected Outputs

  • Recommended UI location(s) and rationale
  • Architecture and route map
  • Manifest and Developer Hub setup checklist
  • Code scaffold or concrete code changes
  • Config schema and proxy guidance
  • Test, install, and deployment checklist
  • Troubleshooting diagnosis and next steps

Example User Requests

  • Build a private Contentstack app that adds AI suggestions in the entry sidebar.
  • Which UI location should I use for a product taxonomy picker?
  • Generate an app configuration page and save API credentials through proxy variables.
  • Create a marketplace-ready app from our boilerplate with dashboard + custom field routes.
  • Why is my app loading but appSdk.location.CustomField is undefined?
  • Turn this app idea into manifest config, route plan, and starter code.

Read the full file on GitHub · 184 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 184 lines · 48 tokens per session scan A 0654d20a4c1b

Subscribe to this mod's changes

16-developer-hub-app-architect is a cursor rule published in the GitHub repository contentstack/contentstack-agent-skills (5 stars, last pushed 15d ago), licensed MIT. It adds 48 tokens to every session and 1,957 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.