Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/obviousworks/vibe-coding-ai-rules/001-code-stylegit clone --depth 1 https://github.com/obviousworks/vibe-coding-ai-rulesWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00297 | $0.00297 |
| Opus 5 | $0.00148 | $0.00148 |
| Sonnet 5 | $0.00059 | $0.00059 |
| Haiku 4.5 | $0.00030 | $0.00030 |
Grade A, and why
001-code-style scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Code Style & Conventions
Naming Conventions
- Files: {{FILE_NAMING}} (e.g., kebab-case.tsx, snake_case.py)
- Components: PascalCase
- Functions: camelCase with verb prefixes (getUserData, calculateTotal)
- Variables: camelCase with auxiliary verbs for booleans (isLoading, hasError)
- Constants: UPPER_SNAKE_CASE
- Types/Interfaces: PascalCase
Formatting
- Indentation: {{INDENTATION}} (e.g., 2 spaces)
- Line Length: {{LINE_LENGTH}} max (e.g., 100 chars)
- Quotes: {{QUOTE_STYLE}} (e.g., single quotes)
- Semicolons: {{SEMICOLONS}} (e.g., required)
- Trailing Commas: always in multi-line structures
Readability
Code must be immediately understandable. Use descriptive naming. Maintain clear structure. Readable code over clever code.
Do's
- Use explicit return types for functions
- Prefer composition over inheritance
- Use const assertions for literal types
- Implement proper error boundaries
Don'ts
- No
anytypes — useunknownwith type guards - No unhandled promise rejections
- No inline styles (use CSS framework)
- No business logic in UI components
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 38 lines · 297 tokens per session scan A 863b41da9396
001-code-style is a cursor rule published in the GitHub repository obviousworks/vibe-coding-ai-rules (88 stars, last pushed 2mo ago), licensed MIT. It adds 297 tokens to every session, about $0.0015 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
tools
(none|read|write|network|exec) and risk (low|medium|high|critical). These drive the permission classifier — be honest.
ios-app-store-validator
App Store validation for iOS projects.
task_structure_example.mouse
TaskID: MOUSE#TASK0001 # Example. MUST be unique & sequential. Title: "Example Task: Process User Survey Data and Generate Insights Report" Description: | This task involves processing raw user survey data, performing analysis, and generating a comprehensive insights report.
Deep-Learning-Developer
You are an expert in deep learning, transformers, diffusion models, and LLM development, with a focus on Python libraries such as PyTorch, Diffusers, Transformers, and Gradio.
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.