component-builder

A Figma rule set for building reusable interface components such as buttons, inputs, cards, badges, chips, and modals. It organizes component variations by type, size, and state, using the design system's tokens and styles.

In plain words
What is it for?
Use it when creating a Figma component library or adding standard interface components with reusable variants and design-system connections.
Why use it?
It helps keep components consistent and makes their design choices easier to carry into code later. It also defines places where icons, text, or other components can be inserted.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/jrpease/throughline/component-builder
Clone the repo
git clone --depth 1 https://github.com/jrpease/throughline

Made for: Cursor.

Per session 99 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 5,614 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00099 $0.05614
Opus 5 $0.00049 $0.02807
Sonnet 5 $0.00020 $0.01123
Haiku 4.5 $0.00010 $0.00561

Measured 2d ago against content hash 756d8d5138cd, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

component-builder scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

adapters/cursor/.cursor/rules/component-builder.mdc · 399 lines

How it starts

The opening of the file, as written. The whole thing — 399 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Component builder

Creates the foundational component set in Figma: well-structured components with variant matrices, bound to the system's tokens/styles, with slots typed so they translate cleanly to code later.

Prerequisites

Needs tokens (tokens.semanticBuilt true) — offer to run token-builder if missing. Needs a live Figma connection (offer figma-environment-setup if not). Use the mechanism in figma.mechanism.

Before scripting any figma_execute, read .throughline/references/figma-scripting.md — the single-bridge-instance preflight, the resize() axis-lock trap (collapses auto-layout frames to ~10px), the dynamic-page async setters, and why large WRAP grids time out. These cause silent, screenshot-invisible corruption if not handled up front.

Recommend icons first (soft gate). Almost every foundational component (button, input, select, chip…) takes an icon prop, so the icon set should usually exist before components — otherwise icon slots have no targets. If icons.built is false, recommend running icon-system-builder first and explain why in one plain sentence, but let the user override and build icon-less if they want (some intentionally do). This is a recommendation, not a hard block.

Model tip (#3): this skill does heavy structural reasoning — variant matrices, slot contracts. It runs on your session model; Sonnet is a solid default and Opus helps for large or intricate component sets. See the model guide in the ThroughLine README.

Step 1 — Capture framework + brainstorm the set and variant matrices

First, check the scope. If the user wants to retrofit or migrate an existing codebase rather than build a clean set — e.g. converting a hand-rolled component/motion layer to shadcn, or any change that re-architects the system — this has outgrown a single skill. Follow .throughline/references/scaling-up-handoff.md: surface the risks and major parts, confirm scope, and brainstorm/plan before building (handing off to Superpowers if it's available, else planning natively — never required). For a normal from-the-system build, continue here.

Read the full file on GitHub · 399 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 399 lines · 99 tokens per session scan A 756d8d5138cd

Subscribe to this mod's changes

component-builder is a cursor rule published in the GitHub repository jrpease/throughline (76 stars, last pushed 4d ago), licensed MIT. It adds 99 tokens to every session and 5,614 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.