repository-builder

A setup guide that turns a design-system folder into a monorepo—a single repository containing multiple related packages—using pnpm and Turborepo.

In plain words
What is it for?
It is for creating workspace files, token and UI packages, an apps folder, Git configuration, environment-file examples, and the steps needed to connect the project to GitHub.
Why use it?
It provides an organized path from a plain folder to local version control, a GitHub repository, pull requests, and continuous integration.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/jrpease/throughline/repository-builder
Clone the repo
git clone --depth 1 https://github.com/jrpease/throughline

Made for: Cursor.

Per session 136 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 2,379 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00136 $0.02379
Opus 5 $0.00068 $0.01189
Sonnet 5 $0.00027 $0.00476
Haiku 4.5 $0.00014 $0.00238

Measured 2d ago against content hash 5a8174fe7f93, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

repository-builder scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

adapters/cursor/.cursor/rules/repository-builder.mdc · 182 lines

How it starts

The opening of the file, as written. The whole thing — 182 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Repository builder

Turns the user's working folder into a scalable monorepo and advances their version-control stage. Defaults: pnpm + Turborepo, with a layout ready to grow into a full app:

my-design-system/
├── design-system.json        (the manifest, already here)
├── package.json              (workspace root)
├── pnpm-workspace.yaml
├── turbo.json
├── .gitignore
├── .env.example
├── packages/
│   ├── tokens/               (synced token output lands here — skill 6)
│   └── ui/                   (components / Storybook live here — skill 7)
└── apps/                     (empty, ready for a Next.js app later)

Calibrate first

Read user.codingLevel from the manifest and .throughline/references/coding-level.md. Everything below describes the actions, which are identical for every user. How much you explain each concept scales with the level — new gets plain- language teaching of repos, env files, and secrets; comfortable gets terse action statements. The hard secret-safety rules never scale.

The folder → local-git → github progression

Scope check first. If the user is bringing an existing app to retrofit or migrate (not scaffolding a clean monorepo) — or the repo work is entangled with a larger re-architecture — that has outgrown this skill. Follow .throughline/references/scaling-up-handoff.md: surface risks and major parts, confirm scope, and brainstorm/plan first (handing off to Superpowers if available, else planning natively — never required). For a normal scaffold-from-scratch, continue here.

The user is at one of three workspace.stage values. This skill advances them one step at a time, introducing each concept only when its payoff is concrete. Read the current stage from the manifest and pick up where they are.

Stage A → scaffold the monorepo (still just a folder)

Create the workspace files (root package.json, pnpm-workspace.yaml, turbo.json, packages/tokens, packages/ui, apps/, a sensible .gitignore, and a .env.example). Record repo.packageManager = pnpm, repo.monorepo = turborepo.

Read the full file on GitHub · 182 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 182 lines · 136 tokens per session scan A 5a8174fe7f93

Subscribe to this mod's changes

repository-builder is a cursor rule published in the GitHub repository jrpease/throughline (76 stars, last pushed 4d ago), licensed MIT. It adds 136 tokens to every session and 2,379 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.