retrofit-planner

retrofit-planner is a cursor rule for Cursor from jrpease/throughline. It costs 106 tokens per session (2,131 once invoked), scanned A, original, MIT.

A planner for updating an established design system and its code and design files in a controlled sequence. A brownfield project is an existing system that already contains live work.

In plain words
What is it for?
Use it to migrate an existing Figma file and application to shared design tokens, coordinate the retrofit phases, resume interrupted work, and verify the result.
Why use it?
It reduces the risk of breaking a mature product by separating auditing, design updates, code changes, documentation, and cleanup with approval points between phases.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/jrpease/throughline/retrofit-planner
Clone the repo
git clone --depth 1 https://github.com/jrpease/throughline

Made for: Cursor.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for retrofit-planner

README.md
[![agentmods](https://agentmods.dev/badge/rules/jrpease/throughline/retrofit-planner.svg)](https://agentmods.dev/rules/jrpease/throughline/retrofit-planner)
Your own site
<a href="https://agentmods.dev/rules/jrpease/throughline/retrofit-planner"><img src="https://agentmods.dev/badge/rules/jrpease/throughline/retrofit-planner.svg" alt="Measured on agentmods" height="20"></a>
Per session 106 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 2,131 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00106 $0.02131
Opus 5 $0.00053 $0.01066
Sonnet 5 $0.00021 $0.00426
Haiku 4.5 $0.00011 $0.00213

Measured 5d ago against content hash 28896c0a5e9c, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-05, from the pricing page.

Security

Grade A, and why

retrofit-planner scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

adapters/cursor/.cursor/rules/retrofit-planner.mdc · 161 lines

How it starts

The opening of the file, as written. The whole thing — 161 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Retrofit planner (orchestrator)

Sequences a brownfield retrofit through the safe seven-phase order (with docs inserted as a gated Phase 6.5), gating each phase on a human confirmation. Like component-pipeline, this skill holds zero domain logic of its own — it is a sequencer that invokes the real skills and the phase work, and only updates the manifest fields it owns (retrofit.*, completedSkills). All the actual work lives in the skills it calls, so this orchestrator doesn't rot when they improve.

Before anything, read .throughline/references/brownfield-retrofit.md — the read discipline, the 7 guardrails, the safe sequence, and the verification triad are the rules this skill enforces as gates.

When to use vs. the individual skills

Use this for a complete retrofit, especially across multiple sessions. For a single isolated step (just the audit, just the crosswalk), run that skill directly. This is the "converge my mature system onto tokens, end to end, without breaking the live app" flow.

Calibrate

Read user.codingLevel (.throughline/references/coding-level.md). A retrofit touches Figma, tokens, code, CI, and a live app — for new users explain each phase and why its ordering matters the first time; for comfortable users be terse. The phases and gates are identical across levels.

Prerequisites

Read the manifest. This orchestrator assumes a brownfield situation (tokens.intakeMode: "retrofit", or workspace.origin is an existing repo/monorepo). If the audit hasn't run yet (audit.ranAt is null), start at the audit phase below. If none of the brownfield markers are set, this is probably greenfield — point the user to the normal build skills instead.

Decision-journal offer (default-on)

At the start of a retrofit, offer to scaffold a decision journal at docs/design-system/ with specs/ plans/ spikes/ findings/ decisions/ handoffs/. Recommend yes — retrofits are multi-session and the journal is the human decision trail (complementary to the manifest's machine state) — but allow the user to decline. Record the choice in retrofit.journalScaffolded. This is the only artifact this skill creates directly.

Read the full file on GitHub · 161 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 161 lines · 106 tokens per session scan A 28896c0a5e9c

Subscribe to this mod's changes

retrofit-planner is a cursor rule published in the GitHub repository jrpease/throughline (76 stars, last pushed 4d ago), licensed MIT. It adds 106 tokens to every session and 2,131 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.