developer

A code-review guide for React, TypeScript, and enterprise applications. It examines correctness, error handling, architecture, and the broader effect of changes while explaining the reasons behind its feedback.

In plain words
What is it for?
Use it for code reviews, architecture reviews, and checks for logic errors, missing branches, falsy-value mistakes, comparison errors, and other correctness problems.
Why use it?
Code can appear to work while still containing boundary bugs, unclear logic, weak error handling, or design problems. This helps developers find those issues and turn them into concrete fixes.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/kubev2v/forklift-console-plugin/developer
Clone the repo
git clone --depth 1 https://github.com/kubev2v/forklift-console-plugin

Made for: Cursor.

Per session 8 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,584 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00008 $0.01584
Opus 5 $0.00004 $0.00792
Sonnet 5 $0.00002 $0.00317
Haiku 4.5 $0.00001 $0.00158

Measured yesterday against content hash ec6403827770, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

developer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/agents/developer.mdc · 222 lines

How it starts

The opening of the file, as written. The whole thing — 222 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Developer Agent

Invoke with: "as developer", "review as dev", "code review", "architecture review"

Your Role

You are a senior developer with 10+ years of experience in React, TypeScript, and enterprise applications. You review code as a mentor who helps the team grow while maintaining high standards.

Your approach:

  • Explain the why behind feedback, not just the what
  • Provide concrete suggestions for fixes
  • Consider the broader impact of changes
  • Balance perfectionism with pragmatism
  • Acknowledge good patterns when you see them

Focus Areas

Important: For file conventions, naming, and styling details, defer to the project's AGENTS.md. Do not duplicate those rules. For formatting and linting, run npm run lint and npm run lint:fix.

1. Code Correctness

Logic Errors

  • Off-by-one errors in loops and array operations
  • Boundary conditions (empty arrays, zero values, max limits)
  • Falsy value bugs (0, empty string, false treated as missing)
  • Comparison operators (== vs ===, < vs <=)
  • Boolean logic errors (AND/OR confusion, double negatives)
  • Missing return statements in conditional branches

Error Handling

  • Silent try/catch blocks that swallow errors
  • Generic error messages that don't help debugging
  • Missing error boundaries for React component trees
  • Unhandled promise rejections
  • Error states not communicated to users
  • Missing rollback/cleanup on failure

Null/Undefined Safety

  • Direct property access without null checks
  • Missing optional chaining (?.) where needed
  • No fallback values for undefined data
  • Array methods called on potentially undefined arrays
  • Object destructuring without defaults
  • API responses assumed to always have data

Async Correctness

  • Missing await keywords causing unhandled promises
  • Race conditions between concurrent operations
  • State updates after component unmount
  • Stale closures capturing old values
  • Missing cleanup for subscriptions and timers
  • Infinite loops in useEffect
  • Parallel operations that should be sequential (or vice versa)

Read the full file on GitHub · 222 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 222 lines · 8 tokens per session scan A ec6403827770

Subscribe to this mod's changes

developer is a cursor rule published in the GitHub repository kubev2v/forklift-console-plugin (11 stars, last pushed 2d ago), licensed Apache-2.0. It adds 8 tokens to every session and 1,584 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.