common-mistakes

common-mistakes is a cursor rule for Cursor from enuno/unifi-mcp-server. It costs 0 tokens per session (567 once invoked), scanned A, original, Apache-2.0.

A set of coding rules and checks for avoiding common mistakes in Python and agent-tool projects. It covers asynchronous code, type hints, tests, safety checks, logging, and project guidelines.

In plain words
What is it for?
Use it when writing or reviewing Python code, especially code that performs changes or other risky operations. It gives guidance for testing, safe dry runs, resource handling, typed data models, and pre-commit checks.
Why use it?
It helps prevent slow or unsafe code, missing tests, exposed secrets, and changes that ignore the project's rules. It also encourages test-driven development (TDD), where tests are written before the code.

Cursor rule for Cursor

Written for Cursor: installed under .cursor/. Also seen: mentions CLAUDE.md; mentions AGENTS.md.

Good fit Use it when writing or reviewing Python code, especially code that performs…

Compare 6 cursor rules from other repositories ↓
Install with agentmods
npx agentmods add rules/enuno/unifi-mcp-server/common-mistakes
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Clone the repo
git clone --depth 1 https://github.com/enuno/unifi-mcp-server

Made for: Cursor.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for common-mistakes

README.md
[![agentmods](https://agentmods.dev/badge/rules/enuno/unifi-mcp-server/common-mistakes.svg)](https://agentmods.dev/rules/enuno/unifi-mcp-server/common-mistakes)
Your own site
<a href="https://agentmods.dev/rules/enuno/unifi-mcp-server/common-mistakes"><img src="https://agentmods.dev/badge/rules/enuno/unifi-mcp-server/common-mistakes.svg" alt="Measured on agentmods" height="20"></a>
Per session 0 Nothing until a file matches its globs; then the whole rule loads.
When invoked 567 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00000 $0.00567
Opus 5 $0.00000 $0.00283
Sonnet 5 $0.00000 $0.00113
Haiku 4.5 $0.00000 $0.00057

Measured 7d ago against content hash 72661660b353, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade A, and why

common-mistakes scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/common-mistakes.mdc · 72 lines

How it starts

The opening of the file, as written. The whole thing — 72 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Common Mistakes to Avoid

❌ DON'T

  • Use synchronous blocking calls in async functions
  • Omit type hints or use Any unnecessarily
  • Skip tests for new features
  • Forget confirm=True safety checks on mutating operations
  • Expose sensitive data in logs
  • Commit without running pre-commit hooks
  • Mix sync and async code improperly
  • Return untyped dicts when Pydantic models are appropriate
  • Ignore project guidelines (CLAUDE.md, AGENTS.md) when editing command/agent assets or MCP tool instructions

✅ DO

  • Use async/await consistently
  • Provide comprehensive type hints
  • Write tests first (TDD)
  • Implement dry-run mode for dangerous operations
  • Mask passwords and keys in logs
  • Run full test suite before committing
  • Use async with for resource management
  • Define Pydantic models for complex data structures
  • Follow project guidelines in CLAUDE.md and AGENTS.md for consistent development practices

Quick Commands

# Development
uv run mcp dev src/main.py      # Run with MCP Inspector

# Testing
pytest                          # Run all tests
pytest -m unit                  # Unit tests only
pytest -m integration           # Integration tests only
pytest --cov=src --cov-report=html  # With coverage report

# Code Quality
black src/ tests/               # Format
isort src/ tests/               # Sort imports
ruff check src/ tests/ --fix   # Lint and fix
mypy src/                       # Type check
bandit -r src/                  # Security scan

# Pre-commit
pre-commit run --all-files      # Run all hooks

Key Resources

Remember

  • Safety First: Require confirm=True for all network modifications
  • Test Everything: 80%+ coverage is not optional
  • Type Everything: Type hints improve code quality and catch bugs
  • Document Well: Future you (and other developers) will thank you
  • Async Always: This is an async-first project - respect the pattern
  • Security Matters: Never expose credentials or sensitive data

Read the full file on GitHub · 72 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 7d ago First seen · 72 lines · 0 tokens per session scan A 72661660b353

Subscribe to this mod's changes

common-mistakes is a cursor rule published in the GitHub repository enuno/unifi-mcp-server (245 stars, last pushed 4d ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 567 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.