config-schema

A validation contract for the `.figma-pipeline/config.json` file, which controls a Figma-to-code pipeline and supplies settings to its agents.

In plain words
What is it for?
Use it to define the project framework, styling system, design tokens, components, icons, allowed write areas, and how automated decision gates should behave.
Why use it?
It gives the pipeline one agreed structure for its settings. Validation helps catch invalid values before agents use them or derive which files they may change.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/punkadillo/figma-code-composer/config-schema
Clone the repo
git clone --depth 1 https://github.com/punkadillo/figma-code-composer

Made for: Cursor.

Per session 0 Nothing until a file matches its globs; then the whole rule loads.
When invoked 682 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.00682
Opus 5 $0.00000 $0.00341
Sonnet 5 $0.00000 $0.00136
Haiku 4.5 $0.00000 $0.00068

Measured yesterday against content hash 7ba1403b7d89, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

config-schema scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/config-schema.mdc · 40 lines

How it starts

The opening of the file, as written. The whole thing — 40 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Supporting — .figma-pipeline/config.json contract

Backs binding rule 1 (write allowlist is derived from this file) and feeds the configSnapshot that the coordinator passes to every specialist.

This file is the runtime configuration every pipeline agent reads. Hand-edits are allowed; the wizard writes it during /init-figma-compose.

Required top-level keys

version, project, framework, language, cssSystem, tokens, components, icons, writeScope.

Optional (commonly present): designSystem, stories, tests, figma, tools, complexity, knowledgeGraph, autonomy.

autonomy (optional; absent → interactive, every gate blocks) controls how mid-run decision gates resolve when the user may be away. level ∈ {interactive, autonomous}; per-gate keys onUnbound, onStackMismatch, onUnsupportedOverride, onLibrarySwap, onRemovedToken, onAmbiguousSelection. See figma-coordinator.md § Autonomy policy.

Hard constraints

  • version == "1.0". Bumping is a breaking change for every agent.
  • framework.name ∈ {react, vue, angular, svelte}.
  • cssSystem.name ∈ {tailwind-v4, tailwind-v3, unocss, css-modules, css-vars, sass, vanilla-extract, panda, styled-components}.
  • tokens.strategy ∈ {tailwind-css-vars, css-custom-properties, scss-variables, js-tokens, unocss-theme}.
  • components.designMethodology ∈ {atomic, feature-sliced, component-based, flat, custom}.
  • designSystem.name ∈ {none, atomic, antd, chakra, heroui, mantine, mui, radix, shadcn} when present (default: none).
  • writeScope.allowedDirs MUST be non-empty.

Path keys feed the write allowlist

tokens.outputDir, components.atomicLayout.*Dir (or feature-sliced / component-based / flat equivalents), icons.outputDir, stories.outputDir (when not co-located), tests.outputDir (when not co-located) — each appears under writeScope.allowedDirs with a trailing /**.

Edits

Free to hand-edit. After editing, the next Write will trigger check-config-schema.sh (Claude Code) or this rule in Cursor — Cursor users should re-validate manually with npx --yes ajv-cli@5 validate -s .figma-pipeline/config.schema.json -d .figma-pipeline/config.json.

Read the full file on GitHub · 40 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 40 lines · 0 tokens per session scan A 7ba1403b7d89

Subscribe to this mod's changes

config-schema is a cursor rule published in the GitHub repository punkadillo/figma-code-composer (3 stars, last pushed 13d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 682 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.