template_setup

Project-initialization rules for adapting a reusable coding template to a new project.

In plain words
What is it for?
Use them when starting a project from the template, creating its README and configuration, and enabling the required repository settings.
Why use it?
They separate template setup from application configuration and prevent old template content, paths, and secrets from being carried into the project.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/jpke/cursor-vibe-coding-template/template_setup
Clone the repo
git clone --depth 1 https://github.com/jpke/cursor-vibe-coding-template

Made for: Cursor.

Per session 846 This file is loaded in full into every session.
When invoked 846 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00846 $0.00846
Opus 5 $0.00423 $0.00423
Sonnet 5 $0.00169 $0.00169
Haiku 4.5 $0.00085 $0.00085

Measured yesterday against content hash ffe4f9d4f386, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

template_setup scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/template_setup.mdc · 65 lines

How it starts

The opening of the file, as written. The whole thing — 65 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Template Setup Workflow

Agent-Driven Initialization

When a user prompts "initialize this project as ", I will ONLY handle template setup (do NOT include TaskMaster or PRD work):

  1. Copy .cursor/.mcp.json.example to .cursor/mcp.json and prompt user for their API keys

  2. Remove template-specific content and customize for their project:

    • Move README.md to docs/how_to_use_this_template.md to preserve template documentation
    • Copy .cursor/templates/project_readme.md to the project root as README.md to create the new project-specific README
    • Update the new README.md by replacing [Project Name] placeholder with user-provided name or "My Project"
    • Update SECURITY.md to remove template references
    • Remove or update any hardcoded paths in configuration files

    Environment File Distinction:

    • Template .env.example: Contains TaskMaster CLI configuration (ANTHROPIC_API_KEY, PERPLEXITY_API_KEY, etc.)
    • Project .env: Will contain application-specific configuration (database URLs, app API keys, etc.)
    • Never mix these: TaskMaster configuration is separate from project application configuration
  3. Enable Issues (if GitHub repository):

    gh api repos/OWNER/REPO --method PATCH --field has_issues=true
    
  4. Set Branch Protection Rules (if GitHub repository):

    gh api repos/OWNER/REPO/branches/main/protection \
      --method PUT \
      --field required_status_checks='{"strict":true,"contexts":[],"checks":[]}' \
      --field required_pull_request_reviews='{"dismiss_stale_reviews":false,"require_code_owner_reviews":false,"require_last_push_approval":false,"required_approving_review_count":1}' \
      --field required_signatures='{"enabled":false}' \
      --field enforce_admins='{"enabled":false}' \
      --field required_linear_history='{"enabled":false}' \
      --field allow_force_pushes='{"enabled":true}' \
      --field allow_deletions='{"enabled":false}' \
      --field block_creations='{"enabled":false}' \
      --field required_conversation_resolution='{"enabled":false}' \
      --field lock_branch='{"enabled":false}' \
      --field allow_fork_syncing='{"enabled":false}'
    

Read the full file on GitHub · 65 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 65 lines · 846 tokens per session scan A ffe4f9d4f386

Subscribe to this mod's changes

template_setup is a cursor rule published in the GitHub repository jpke/cursor-vibe-coding-template (16 stars, last pushed 1y ago), licensed MIT. It adds 846 tokens to every session, about $0.0042 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.