database-patterns

A set of guidelines for changing and using a database safely, including its table structure, validation rules, and migrations. A migration is a recorded change that updates a database from one structure to another.

In plain words
What is it for?
Use it when changing database tables, generating or testing migrations, writing database operations, or defining keys, timestamps, and relationships between tables.
Why use it?
It helps prevent database changes from breaking validation, losing data, or leaving development and test databases out of sync. It also standardizes error handling and multi-table updates.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/floriscornel/todo-mcp/database-patterns
Clone the repo
git clone --depth 1 https://github.com/floriscornel/todo-mcp

Made for: Cursor.

Per session 316 This file is loaded in full into every session.
When invoked 316 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00316 $0.00316
Opus 5 $0.00158 $0.00158
Sonnet 5 $0.00063 $0.00063
Haiku 4.5 $0.00032 $0.00032

Measured 2d ago against content hash d7f9e5fcfd3d, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

database-patterns scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/database-patterns.mdc · 52 lines

What it actually says

Database Development Patterns

Schema Changes

When modifying src/db/schema.ts:

  1. Update Schema First:

    • Modify tables in schema.ts
    • Update Zod validation schemas accordingly
    • Ensure type safety between database and validation
  2. Generate Migration:

    npm run db:generate
    
  3. Test Migration:

    • Apply to development database: npm run db:migrate
    • Verify migration works with test database
    • Check that rollback is possible if needed

Database Operations

  • Use the todoDb interface from src/db/index.ts
  • All database operations should be type-safe with Drizzle
  • Use transactions for operations that modify multiple tables
  • Handle database errors gracefully with proper error types

Schema Patterns

  • Use generatedAlwaysAsIdentity() for primary keys
  • Include createdAt timestamp with defaultNow()
  • Use appropriate varchar lengths based on UI constraints
  • Foreign keys should have proper references with cascade rules

Migration Best Practices

  • Keep migrations focused and atomic
  • Test migrations with real data scenarios
  • Include both up and down migrations when possible
  • Document complex migrations with comments

Connection Management

  • Use environment variables for database URLs
  • Separate test and development databases
  • Connection pooling is handled by the postgres library
  • Always close connections in tests

@src/db/schema.ts @src/db/postgres.ts

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 52 lines · 316 tokens per session scan A d7f9e5fcfd3d

Subscribe to this mod's changes

database-patterns is a cursor rule published in the GitHub repository floriscornel/todo-mcp (2 stars, last pushed 6mo ago), licensed MIT. It adds 316 tokens to every session, about $0.0016 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.