Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/louisbrulenaudet/monorepo-template/tanstack-querygit clone --depth 1 https://github.com/louisbrulenaudet/monorepo-templateWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/louisbrulenaudet/monorepo-template/tanstack-query)<a href="https://agentmods.dev/rules/louisbrulenaudet/monorepo-template/tanstack-query"><img src="https://agentmods.dev/badge/rules/louisbrulenaudet/monorepo-template/tanstack-query.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00415 |
| Opus 5 | $0.00000 | $0.00208 |
| Sonnet 5 | $0.00000 | $0.00083 |
| Haiku 4.5 | $0.00000 | $0.00042 |
Grade A, and why
tanstack-query scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
TanStack Query (v5) Rules
TanStack Query owns all server state. Depth: skill tanstack-query. This is a client SPA - ignore SSR/dehydrate/HydrationBoundary.
Repo invariants
- Never fetch in
useEffect+useState, and never mirror query data into local state. - Define queries with
queryOptions()insrc/services/worker-api/<feature>-query-options.tsnext to<feature>.ts. Reuse the same object foruseQuery/useSuspenseQuery/ensureQueryData/setQueryData- do not inline{ queryKey, queryFn }at call sites. - Keys under the backend namespace, hierarchical (
['worker-api','…']). Promote to a key factory once a feature has several related queries. Keys must be JSON-serializable. queryFndelegates tofetchJsonWithSchema(forwardssignal, throws on non-OK, validates with shared Zod - neveras T). See contracts.mdc.- One module-singleton
QueryClientinsrc/config/query-client.ts- nevernew QueryClient()in a component. Mount<ReactQueryDevtools>behindimport.meta.env.DEVonly. - Mutations: invalidate via
invalidateQueriesby default; full optimistic ritual only when needed (cancelQueries→ snapshot →setQueryData→ rollback →invalidateQueries). - Route loaders warm with
ensureQueryData(opts); components read the sameopts(see tanstack-router.mdc).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 20 lines · 0 tokens per session scan A 4bd0c54bdc24
tanstack-query is a cursor rule published in the GitHub repository louisbrulenaudet/monorepo-template (19 stars, last pushed 5d ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 415 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other cursor rules, from other repositories
nextjs15-supabase-cursorrules-prompt-file
27 architecture rules preventing AI hallucinations: insecure auth (getSession vs getUser), synchronous params, deprecated imports, missing RLS, and Stripe key exposure. Built for Cursor Agent and Claude Code.
python-fastapi-scalable-api-cursorrules-prompt-fil
Cursor rules for Python FastAPI development with scalable API integration.
react-graphql-apollo-client-cursorrules-prompt-file
Cursor rules for GraphQL development with Apollo Client integration.
react-query-cursorrules-prompt-file
Cursor rules for React development with React Query integration.
react-typescript-symfony-cursorrules-prompt-file
Cursor rules for React development with TypeScript and Symfony integration.
state-management
Frontend state management patterns and best practices. Apply when managing client state.