token-builder

A guide for building a two-level design-token system as Figma variables. Design tokens are named values for choices such as colors, spacing, type sizes, borders, corners, and shadows.

In plain words
What is it for?
Use it to create Figma color ramps, spacing scales, typography scales, corner-radius values, border values, shadows, and light or dark brand modes.
Why use it?
It organizes reusable design values into primitive building blocks and semantic values, with separate categories and light or dark modes.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/jrpease/throughline/token-builder
Clone the repo
git clone --depth 1 https://github.com/jrpease/throughline

Made for: Cursor.

Per session 106 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 5,833 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00106 $0.05833
Opus 5 $0.00053 $0.02916
Sonnet 5 $0.00021 $0.01167
Haiku 4.5 $0.00011 $0.00583

Measured 2d ago against content hash a94bb9f6a9e8, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

token-builder scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

adapters/cursor/.cursor/rules/token-builder.mdc · 382 lines

How it starts

The opening of the file, as written. The whole thing — 382 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Token builder

Critical collection rule: this system uses one collection per category per tier — never one giant Primitives + one giant Semantic. Color, spacing, typography, radius, and border each get their own primitive collection and their own semantic collection. This is non-negotiable: modes (Light/Dark, Desktop/Mobile) belong to a collection, so mixing categories in one collection forces unrelated variables to share the same mode axis.

Model tip (#3): building a coherent token system (ramps, type scale, modes, primitive→semantic aliasing) is reasoning-heavy. It runs on your session model — Sonnet is a solid default; Opus helps for large or multi-mode systems. See the model guide in the ThroughLine README.

Creates a two-tier design token system as Figma variables. Each tier is split into one collection per category (color, spacing, type, radius, border) so every category owns its own modes — see Step 1 for why. Within a collection, Figma variables are grouped with / and omit the category prefix (the collection already carries it); the sync layer later derives the dotted logical name (color.gray.50) by prefixing the collection's category.

  • Primitives — raw values with no meaning attached: gray/50, space/4 in their category's primitive collection. The full palette of possible values.
  • Semantic — meaning-bearing tokens that alias onto primitives: bg/default{gray/50}, text/primary{gray/900}. This is the layer the rest of the system consumes.

The power of two tiers: change a primitive once and every semantic token referencing it updates automatically, which cascades through sheets, components, and synced code. Preserving these aliases (not flattening them) is what makes runtime theming work later, so always create semantic tokens as references to primitives, never as copied literal values.

Prerequisites

This skill needs a live Figma connection. Read the manifest (.throughline/references/manifest-schema.md for the schema) and check figma.connected. Then do a cheap liveness read to confirm the connection is actually live right now. If it isn't, say so plainly and offer to run the figma-environment-setup skill first: "Figma isn't connected yet — want me to set that up? It's a one-time thing." Don't proceed until Figma is reachable.

Read the full file on GitHub · 382 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 382 lines · 106 tokens per session scan A a94bb9f6a9e8

Subscribe to this mod's changes

token-builder is a cursor rule published in the GitHub repository jrpease/throughline (76 stars, last pushed 4d ago), licensed MIT. It adds 106 tokens to every session and 5,833 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.