Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/timurgaleev/vibestackWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/timurgaleev/vibestack/patterns)<a href="https://agentmods.dev/rules/timurgaleev/vibestack/patterns"><img src="https://agentmods.dev/badge/rules/timurgaleev/vibestack/patterns/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/rules/timurgaleev/vibestack/patterns"><img src="https://agentmods.dev/badge/rules/timurgaleev/vibestack/patterns.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00311 | $0.00311 |
| Opus 5 | $0.00156 | $0.00156 |
| Sonnet 5 | $0.00062 | $0.00062 |
| Haiku 4.5 | $0.00031 | $0.00031 |
Grade A, and why
patterns scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Common Patterns
API Response Format
interface ApiResponse<T> {
success: boolean
data?: T
error?: string
meta?: {
total: number
page: number
limit: number
}
}
Custom Hooks Pattern
export function useDebounce<T>(value: T, delay: number): T {
const [debouncedValue, setDebouncedValue] = useState<T>(value)
useEffect(() => {
const handler = setTimeout(() => setDebouncedValue(value), delay)
return () => clearTimeout(handler)
}, [value, delay])
return debouncedValue
}
Repository Pattern
interface Repository<T> {
findAll(filters?: Filters): Promise<T[]>
findById(id: string): Promise<T | null>
create(data: CreateDto): Promise<T>
update(id: string, data: UpdateDto): Promise<T>
delete(id: string): Promise<void>
}
Skeleton Projects
When implementing new functionality:
- Search for battle-tested skeleton projects
- Use parallel subagents to evaluate options:
- Security assessment
- Extensibility analysis
- Relevance scoring
- Implementation planning
- Clone best match as foundation
- Iterate within proven structure
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 62 lines · 311 tokens per session scan A e92f4a6b31f8
patterns is a cursor rule published in the GitHub repository timurgaleev/vibestack (6 stars, last pushed yesterday), licensed MIT. It adds 311 tokens to every session, about $0.0016 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-19.
Other cursor rules, from other repositories
graphql-apollo-client-usage
A usage guide for fetching, changing, and subscribing to GraphQL data with Apollo Client in React. It covers loading and error states, cache updates, refetching, and reusable GraphQL fragments.
apollo-provider-setup
A setup rule for placing ApolloProvider at the root of a React application. ApolloProvider makes one configured Apollo Client available to all child components.
next-js-server-actions
A guide for Next.js server actions, which let server-side code handle requests from an application interface, with validation and structured error responses.
data-fetching-rules-for-server-components
A set of rules for fetching data inside Next.js 14 server components, which render on the server rather than in the browser.
next-js-app-routing-guidelines
A set of rules for building pages and components in the app directory of a Next.js application. Next.js is a framework for building web applications with React.
django-templates
Guidelines for using Django’s template system to turn data into HTML pages, with Django REST Framework serializers for JSON responses.