Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/fumito-ito/mdcvalultWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/fumito-ito/mdcvalult/guidelines-for-building-convex-projects)<a href="https://agentmods.dev/rules/fumito-ito/mdcvalult/guidelines-for-building-convex-projects"><img src="https://agentmods.dev/badge/rules/fumito-ito/mdcvalult/guidelines-for-building-convex-projects/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/rules/fumito-ito/mdcvalult/guidelines-for-building-convex-projects"><img src="https://agentmods.dev/badge/rules/fumito-ito/mdcvalult/guidelines-for-building-convex-projects.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.06287 |
| Opus 5 | $0.00000 | $0.03143 |
| Sonnet 5 | $0.00000 | $0.01257 |
| Haiku 4.5 | $0.00000 | $0.00629 |
Grade A, and why
guidelines-for-building-convex-projects scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
95% identical to convex-cursorrules-prompt-file — 7 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 677 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Convex guidelines
Function guidelines
New function syntax
- ALWAYS use the new function syntax for Convex functions. For example:
typescript import { query } from "./_generated/server"; import { v } from "convex/values"; export const f = query({ args: {}, returns: v.null(), handler: async (ctx, args) => { // Function body }, });
Http endpoint syntax
- HTTP endpoints are defined in
convex/http.tsand require anhttpActiondecorator. For example:typescript import { httpRouter } from "convex/server"; import { httpAction } from "./_generated/server"; const http = httpRouter(); http.route({ path: "/echo", method: "POST", handler: httpAction(async (ctx, req) => { const body = await req.bytes(); return new Response(body, { status: 200 }); }), }); - HTTP endpoints are always registered at the exact path you specify in the
pathfield. For example, if you specify/api/someRoute, the endpoint will be registered at/api/someRoute.
Validators
-
Below is an example of an array validator: ```typescript import { mutation } from "./_generated/server"; import { v } from "convex/values";
export default mutation({ args: { simpleArray: v.array(v.union(v.string(), v.number())), }, handler: async (ctx, args) => { //... }, }); ``` -
Below is an example of a schema with validators that codify a discriminated union type: ```typescript import { defineSchema, defineTable } from "convex/server"; import { v } from "convex/values";
export default defineSchema({ results: defineTable( v.union( v.object({ kind: v.literal("error"), errorMessage: v.string(), }), v.object({ kind: v.literal("success"), value: v.number(), }), ), ) }); ``` -
Always use the
v.null()validator when returning a null value. Below is an example query that returns a null value: ```typescript import { query } from "./_generated/server"; import { v } from "convex/values";export const exampleQuery = query({ args: {}, returns: v.null(), handler: async (ctx, args) => { console.log("This query returns a null value"); return null; }, }); ``` -
Here are the valid Convex types along with their respective validators: Convex Type | TS/JS type | Example Usage | Validator for argument validation and schemas | Notes | | ----------- | ------------| -----------------------| -----------------------------------------------| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | Id | string |
doc._id|v.id(tableName)| | | Null | null |null|v.null()| JavaScript'sundefinedis not a valid Convex value. Functions the returnundefinedor do not return will returnnullwhen called from a client. Usenullinstead. | | Int64 | bigint |3n|v.int64()| Int64s only support BigInts between -2^63 and 2^63-1. Convex supportsbigints in most modern browsers. | | Float64 | number |3.1|v.number()| Convex supports all IEEE-754 double-precision floating point numbers (such as NaNs). Inf and NaN are JSON serialized as strings. | | Boolean | boolean |true|v.boolean()| | String | string |"abc"|v.string()| Strings are stored as UTF-8 and must be valid Unicode sequences. Strings must be smaller than the 1MB total size limit when encoded as UTF-8. | | Bytes | ArrayBuffer |new ArrayBuffer(8)|v.bytes()| Convex supports first class bytestrings, passed in asArrayBuffers. Bytestrings must be smaller than the 1MB total size limit for Convex types. | | Array | Array] |[1, 3.2, "abc"]|v.array(values)| Arrays can have at most 8192 values. | | Object | Object |{a: "abc"}|v.object({property: value})| Convex only supports "plain old JavaScript objects" (objects that do not have a custom prototype). Objects can have at most 1024 entries. Field names must be nonempty and not start with "$" or "". | | Record | Record |{"a": "1", "b": "2"}|v.record(keys, values)| Records are objects at runtime, but can have dynamic keys. Keys must be only ASCII characters, nonempty, and not start with "$" or "". |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 677 lines · 6,287 tokens per session scan A 43d13c5a0832
guidelines-for-building-convex-projects is a cursor rule published in the GitHub repository fumito-ito/mdcvalult (33 stars, last pushed 1y ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 6,287 tokens. A static security scan graded it A with 0 findings. It is 95% identical to convex-cursorrules-prompt-file, differing in 7 lines, and is treated as a copy.
Other cursor rules, from other repositories
trigger
Guidelines for writing PostgreSQL triggers, which are database actions that run automatically when data changes. They explain when a trigger is appropriate and how to keep its function safe and predictable.
rulesforconvex
description: Convex guidelines globs: alwaysApply: true.
ehs-ims-conventions
EHS IMS app — RBAC, data layer, tRPC, migrations, AI boundaries.
startup-migration-bounded-work
Production djangostartup migrate must be bounded; never run makemigrations in production.
schema
Scalable and secure schema design patterns for relational databases, NoSQL, and APIs. / TR: İlişkisel veri tabanları, NoSQL ve API'ler için ölçeklenebilir ve güvenli şema tasarım kalıpları.
redis_rate_limiting
Complete guide for implementing Redis-based rate limiting with authentication troubleshooting and FastAPI integration.