Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/hoshikitsunoda/figma-plugins-vibe-coding-template/figma-main-threadgit clone --depth 1 https://github.com/hoshikitsunoda/figma-plugins-vibe-coding-templateWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/hoshikitsunoda/figma-plugins-vibe-coding-template/figma-main-thread)<a href="https://agentmods.dev/rules/hoshikitsunoda/figma-plugins-vibe-coding-template/figma-main-thread"><img src="https://agentmods.dev/badge/rules/hoshikitsunoda/figma-plugins-vibe-coding-template/figma-main-thread.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00707 |
| Opus 5 | $0.00000 | $0.00353 |
| Sonnet 5 | $0.00000 | $0.00141 |
| Haiku 4.5 | $0.00000 | $0.00071 |
Grade A, and why
figma-main-thread scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 118 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Figma Main Thread (Plugin Sandbox) Rules
This code runs in Figma's plugin sandbox with access to the figma.* API.
Available APIs
figma.currentPage- Current page and its childrenfigma.root- Document rootfigma.createRectangle(),figma.createFrame(), etc. - Node creationfigma.getNodeById(id)- Retrieve nodes by IDfigma.loadFontAsync()- Required before setting textfigma.notify()- Show toast notificationsfigma.ui.postMessage()- Send data to UI
Critical Patterns
Store IDs, Not References
Node references become stale after async operations:
// ❌ BAD - node reference may be stale after await
const node = figma.currentPage.selection[0];
await someAsyncOperation();
node.name = "New Name"; // May fail!
// ✓ GOOD - re-fetch by ID after async
const nodeId = figma.currentPage.selection[0]?.id;
await someAsyncOperation();
const node = figma.getNodeById(nodeId);
if (node) node.name = "New Name";
Font Loading
Always load fonts before setting text content:
// ✓ Required before setting characters
const textNode = figma.createText();
await figma.loadFontAsync({ family: "Inter", style: "Regular" });
textNode.characters = "Hello World";
Node Type Guards
Check node type before accessing type-specific properties:
// ✓ Use type guards
if (node.type === "FRAME") {
console.log(node.layoutMode); // Safe - FRAME has layoutMode
}
// ✓ Or use 'in' operator
if ("fills" in node) {
console.log(node.fills);
}
Node Traversal
Prefer built-in methods over manual recursion:
// ✓ GOOD - use findAll/findOne
const textNodes = figma.currentPage.findAll((n) => n.type === 'TEXT')
const firstFrame = figma.currentPage.findOne((n) => n.type === 'FRAME')
// ❌ AVOID - manual recursion is error-prone
function findAllText(node) { ... }
Serializing Nodes for UI
Never send raw nodes - extract only needed data:
// ✓ GOOD - serialize to plain object
function serializeNode(node: SceneNode) {
return {
id: node.id,
name: node.name,
type: node.type,
width: "width" in node ? node.width : 0,
height: "height" in node ? node.height : 0,
};
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 118 lines · 0 tokens per session scan A c3b4700d4390
figma-main-thread is a cursor rule published in the GitHub repository hoshikitsunoda/figma-plugins-vibe-coding-template (21 stars, last pushed 8mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 707 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
ponytail
Ponytail, lazy senior dev mode. Always pick the simplest solution that works.
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
cli-error-handling
CLI command error handling patterns.
prefer-direct-imports-over-module-mocks
Prefer extracting a testable core over vi.mock / vi.resetModules when unit tests need to reach production logic entangled with config, env, or singletons.
control-plane-descriptors
Control plane descriptor and instance implementation patterns.