mongodb

Rules for designing MongoDB databases, including document structure, indexes, queries, and aggregation pipelines.

In plain words
What is it for?
They guide decisions about embedding or linking data, creating indexes, checking query plans, paginating results, and processing data in batches.
Why use it?
They help prevent slow searches, oversized documents, unnecessary data reads, and queries that scan an entire collection.

Cursor rule

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/nedcodes-ok/cursor-doctor/mongodb
Clone the repo
git clone --depth 1 https://github.com/nedcodes-ok/cursor-doctor
Per session 484 This file is loaded in full into every session.
When invoked 484 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00484 $0.00484
Opus 5 $0.00242 $0.00242
Sonnet 5 $0.00097 $0.00097
Haiku 4.5 $0.00048 $0.00048

Measured 2d ago against content hash e578058ee1f1, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

mongodb scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

pro-kit/templates/tools/mongodb.mdc · 51 lines

How it starts

The opening of the file, as written. The whole thing — 51 lines — stays where its author put it; the contents beside it link to each section on GitHub.

MongoDB Cursor Rules

You are an expert MongoDB developer. Follow these rules:

Schema Design

  • Design for access patterns: embed what you read together
  • Embed when: 1:1 or 1:few, data is read together, child doesnt exist alone
  • Reference when: 1:many (unbounded), data accessed independently, many:many
  • Avoid unbounded arrays — they cause document growth and slow updates
  • Use Mongoose schemas with strict mode for application-level validation

Indexing

  • Index fields used in queries, sorts, and aggregation match stages
  • Compound indexes: equality fields first, sort fields next, range last (ESR rule)
  • Use explain() to verify queries use indexes — no collection scans in production
  • Unique indexes for natural keys. Sparse indexes for optional fields
  • TTL indexes for auto-expiring documents (sessions, logs)
  • Text indexes for search, but Atlas Search for anything serious

Queries

  • Projection: return only needed fields, not entire documents
  • Use $match early in aggregation pipelines to reduce working set
  • Avoid $where and $regex without index prefix — they scan everything
  • Use bulkWrite for batch operations, not loops of single writes
  • Cursor-based pagination (sort + range query) over skip/limit

Aggregation

  • Pipeline stages ordered: $match → $project → $group → $sort
  • $lookup for joins — use pipeline form for filtered joins
  • $facet for multi-dimension results in a single query
  • Use $merge or $out to materialize views for dashboards

Data Modeling

  • _id: ObjectId by default, custom IDs only when migrating from another DB
  • Timestamps: createdAt/updatedAt with Mongoose timestamps option
  • Soft deletes with deletedAt field and partial index on active docs
  • Store monetary values as integers (cents) — never floats
  • Use change streams for real-time reactions, not polling

Operations

  • Replica sets for production — never standalone
  • Read preference: secondaryPreferred for analytics, primary for consistency
  • Connection pooling: tune maxPoolSize based on load
  • Monitor slow queries with profiler level 1

Read the full file on GitHub · 51 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 51 lines · 484 tokens per session scan A e578058ee1f1

Subscribe to this mod's changes

mongodb is a cursor rule published in the GitHub repository nedcodes-ok/cursor-doctor (9 stars, last pushed 5mo ago), licensed MIT. It adds 484 tokens to every session, about $0.0024 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.