clean-code

A set of clean-code rules for maintaining software that is already used by customers. It asks developers to remove obvious clutter, preserve public interfaces, and improve code they are already changing.

In plain words
What is it for?
Use it when adding features, fixing bugs, refactoring, or reviewing code in a live SDK. It covers unused code, naming, duplication, public APIs, and the impact on integrators.
Why use it?
It helps prevent small inconsistencies and unused code from accumulating. It also highlights the risk that changes to exported types, functions, or behavior can break other applications.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/solvapay/solvapay-sdk/clean-code
Clone the repo
git clone --depth 1 https://github.com/solvapay/solvapay-sdk

Made for: Cursor.

Per session 392 This file is loaded in full into every session.
When invoked 392 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00392 $0.00392
Opus 5 $0.00196 $0.00196
Sonnet 5 $0.00078 $0.00078
Haiku 4.5 $0.00039 $0.00039

Measured 2d ago against content hash fb3ec66363ef, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

clean-code scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/clean-code.mdc · 45 lines

What it actually says

Clean Code Standards

No Broken Windows

Fix problems as you encounter them. Don't leave:

  • Commented-out code
  • Unused imports, variables, or functions
  • Inconsistent naming or patterns
  • Copy-pasted code that should be abstracted

If you touch a file, leave it cleaner than you found it.

Move Fast, Break Nothing

We are post-launch with live customers. The SDK is consumed directly by integrators -- changes here have immediate downstream impact.

  • Refactor code you're already touching to make it better -- the boy scout rule applies
  • Don't refactor unrelated code while working on a task unless it's a small obvious fix
  • Don't rename public APIs, change type signatures, or restructure exports just because you can -- changes must have a reason
  • Consider integrator impact before changing any exported type, function signature, or behavior
  • When in doubt about whether a change is breaking, flag it rather than just doing it
  • Delete genuinely unused code paths -- but verify they're unused first

Prefer the Right Solution

When implementing features:

  1. Do it right the first time - don't plan to "fix it later"
  2. Improve existing patterns - if something looks wrong, fix it while you're there. Don't change things that work just because they look different from what you'd write
  3. Simplify aggressively - less code is better code
  4. Use proper types - avoid any, define clear interfaces
  5. Name things clearly - code should read like documentation

When Refactoring

If you see code that could be improved while working on a task:

  • Small fixes: just do them
  • Medium refactors: mention them and do them if related to the task
  • Large refactors: flag them but stay focused on the current task
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 45 lines · 392 tokens per session scan A fb3ec66363ef

Subscribe to this mod's changes

clean-code is a cursor rule published in the GitHub repository solvapay/solvapay-sdk (5 stars, last pushed 2d ago), licensed MIT. It adds 392 tokens to every session, about $0.0020 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.