cursorrules

A project rule that tells the agent which instruction files to read before changing code, along with code patterns for a React and Go application.

In plain words
What is it for?
It is for guiding UI changes, data handling, user-facing text, API work, demo mode, and required Playwright visual tests.
Why use it?
It keeps changes aligned with the repository's existing styling, translation, state-management, API, and testing rules.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/kubestellar/console/cursorrules
Clone the repo
git clone --depth 1 https://github.com/kubestellar/console

Made for: Cursor.

Per session 456 This file is loaded in full into every session.
When invoked 456 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00456 $0.00456
Opus 5 $0.00228 $0.00228
Sonnet 5 $0.00091 $0.00091
Haiku 4.5 $0.00046 $0.00046

Measured 2d ago against content hash 3e2d9ae31f8d, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

cursorrules scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursorrules · 57 lines

What it actually says

KubeStellar Console — Cursor Rules

Read CLAUDE.md, AGENTS.md, and .github/copilot-instructions.md before making changes.

Critical Patterns

Card Development

  • Every useCached* hook MUST destructure isDemoData and isRefreshing
  • Pass both to useCardLoadingState() for Demo badge + refresh animation
  • Array safety: (data || []) before .map(), .filter(), .join()
  • Use DeduplicatedClusters() when iterating clusters

Styling

  • NEVER use raw hex colors — use semantic Tailwind classes (text-foreground, bg-primary)
  • Use cn() utility for className merging
  • Status colors: text-green-400, text-yellow-400, text-red-400, text-cyan-400

i18n

  • User-facing strings MUST use t() from useTranslation() — no raw strings

State Management

  • No Redux/Zustand — pure React Context + hooks
  • Server data: useCache / useCached* hooks
  • Preferences: localStorage

API Endpoints

  • Go handlers in pkg/api/ use Fiber v2
  • Netlify Functions in web/netlify/functions/*.mts for production parity
  • Demo mode: every endpoint checks isDemoMode(c) first

Testing (MANDATORY)

  • UI changes: Playwright visual tests in web/e2e/visual/
  • Generate baselines: npm run test:visual:update
  • Commit test + snapshots with code changes

No Magic Numbers

Every numeric literal MUST be a named constant.

Secrets

NEVER hardcode API keys — use env vars only.

Pre-Commit

DO NOT run build or lint locally — CI validates on PR. Commit, push, open PR with Fixes #NNN.

Commit Format

<emoji> <message under 72 chars>

Signed-off-by: Name <email>

Emoji: ✨ feature | 🐛 bug | 📖 docs | 🌱 other

DCO required: git commit -s

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 57 lines · 456 tokens per session scan A 3e2d9ae31f8d

Subscribe to this mod's changes

cursorrules is a cursor rule published in the GitHub repository kubestellar/console (130 stars, last pushed 2d ago), licensed Apache-2.0. It adds 456 tokens to every session, about $0.0023 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.