Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/kensaurus/cursor-kenji/full-stack-ship-disciplinegit clone --depth 1 https://github.com/kensaurus/cursor-kenjiWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/kensaurus/cursor-kenji/full-stack-ship-discipline)<a href="https://agentmods.dev/rules/kensaurus/cursor-kenji/full-stack-ship-discipline"><img src="https://agentmods.dev/badge/rules/kensaurus/cursor-kenji/full-stack-ship-discipline.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00053 | $0.00543 |
| Opus 5 | $0.00026 | $0.00271 |
| Sonnet 5 | $0.00011 | $0.00109 |
| Haiku 4.5 | $0.00005 | $0.00054 |
Grade A, and why
full-stack-ship-discipline scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Full-Stack Ship Discipline
A feature is not done when the UI compiles — it is done when the flow works end-to-end against the remote backend the user actually hits. The recurring failure this prevents: a migration file authored beside a feature is never deployed, the live API 404s, and the bug masquerades as a UI issue.
- Inventory backend dependencies first. Before editing components ask: does this read/write data, call an RPC, or depend on a table / column / function / policy / bucket / secret? Fix those in the same turn.
- Deploy schema, don't just author it. Supabase:
apply_migration/execute_sqlon the confirmedproject_id, then verify in the same turn — re-queryinformation_schema/pg_proc/pg_policies, exercise the surface asanon/authenticated, checkget_logsandget_advisors. Other stacks: run the real deploy command (prisma migrate deploy,drizzle-kit push,rails db:migrate, …) against the confirmed environment before the turn ends. - Keep file and deploy in sync. SQL applied via MCP also gets a matching
versioned file in the repo's migrations folder. Do not
git pushunless the user asked in this turn. - Edge functions, secrets, RLS, buckets, and cron jobs count as schema —
deploy and configure them with the UI change (
verify_jwt, CORS, keys). - Never re-ask before deploying schema the user asked to ship; always ask
before mutating production data (
DELETE/TRUNCATE/UPDATEon real rows). - Do not attach during a present-then-stop pass. If the active skill is
plan-*or a read-onlyaudit-*, emit findings/plan only — do notapply_migrationor deploy until the user approves a phase.
Done means: remote objects verified to exist, anon + authenticated paths exercised, migration file on disk, and the frontend observed hitting a 200 — not a stale 404.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 38 lines · 53 tokens per session scan A 4827fa758b34
full-stack-ship-discipline is a cursor rule published in the GitHub repository kensaurus/cursor-kenji (9 stars, last pushed 8d ago), licensed MIT. It adds 53 tokens to every session and 543 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other cursor rules, from other repositories
query-patterns
Database query patterns, optimization, and safety rules. Apply when writing or editing queries.
schema-design
Database schema design conventions and standards. Apply when designing schema or migrations.
migration-rules
Database migration patterns and safety rules. Apply when creating or editing migrations.
integration-testing
Integration testing patterns and database test setup.
sql
Rules for SQL files (queries, migrations, stored procs).
mysql-auto
This rule enforces MySQL-specific best practices to enhance readability, performance, security, and maintainability. It targets MySQL features (e.g., storage engines, character sets) and common pitfalls, and adds concrete guidance for schema design and creation.