Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/jpke/cursor-vibe-coding-template/template_setupgit clone --depth 1 https://github.com/jpke/cursor-vibe-coding-templateWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00846 | $0.00846 |
| Opus 5 | $0.00423 | $0.00423 |
| Sonnet 5 | $0.00169 | $0.00169 |
| Haiku 4.5 | $0.00085 | $0.00085 |
Grade A, and why
template_setup scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 65 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Template Setup Workflow
Agent-Driven Initialization
When a user prompts "initialize this project as ", I will ONLY handle template setup (do NOT include TaskMaster or PRD work):
-
Copy
.cursor/.mcp.json.exampleto.cursor/mcp.jsonand prompt user for their API keys -
Remove template-specific content and customize for their project:
- Move
README.mdtodocs/how_to_use_this_template.mdto preserve template documentation - Copy
.cursor/templates/project_readme.mdto the project root asREADME.mdto create the new project-specific README - Update the new
README.mdby replacing[Project Name]placeholder with user-provided name or "My Project" - Update
SECURITY.mdto remove template references - Remove or update any hardcoded paths in configuration files
Environment File Distinction:
- Template
.env.example: Contains TaskMaster CLI configuration (ANTHROPIC_API_KEY, PERPLEXITY_API_KEY, etc.) - Project
.env: Will contain application-specific configuration (database URLs, app API keys, etc.) - Never mix these: TaskMaster configuration is separate from project application configuration
- Move
-
Enable Issues (if GitHub repository):
gh api repos/OWNER/REPO --method PATCH --field has_issues=true -
Set Branch Protection Rules (if GitHub repository):
gh api repos/OWNER/REPO/branches/main/protection \ --method PUT \ --field required_status_checks='{"strict":true,"contexts":[],"checks":[]}' \ --field required_pull_request_reviews='{"dismiss_stale_reviews":false,"require_code_owner_reviews":false,"require_last_push_approval":false,"required_approving_review_count":1}' \ --field required_signatures='{"enabled":false}' \ --field enforce_admins='{"enabled":false}' \ --field required_linear_history='{"enabled":false}' \ --field allow_force_pushes='{"enabled":true}' \ --field allow_deletions='{"enabled":false}' \ --field block_creations='{"enabled":false}' \ --field required_conversation_resolution='{"enabled":false}' \ --field lock_branch='{"enabled":false}' \ --field allow_fork_syncing='{"enabled":false}'
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 65 lines · 846 tokens per session scan A ffe4f9d4f386
template_setup is a cursor rule published in the GitHub repository jpke/cursor-vibe-coding-template (16 stars, last pushed 1y ago), licensed MIT. It adds 846 tokens to every session, about $0.0042 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
90-devops-deployment
Docker, CI/CD, AWS, Vercel, and VPS deployment rules.
00-global-architect
Global default behavior for the entire repository.
55-data-model-versioning
Dataset versioning, model checkpoint management, and training reproducibility rules.
85-error-observability
Error handling, logging, and observability rules.
30-database-postgres
PostgreSQL and persistence rules.
35-api-contracts
API versioning, contracts, and schema evolution rules.