Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/timurgaleev/vibestackWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/timurgaleev/vibestack/style)<a href="https://agentmods.dev/rules/timurgaleev/vibestack/style"><img src="https://agentmods.dev/badge/rules/timurgaleev/vibestack/style/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/rules/timurgaleev/vibestack/style"><img src="https://agentmods.dev/badge/rules/timurgaleev/vibestack/style.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00563 | $0.00563 |
| Opus 5 | $0.00282 | $0.00282 |
| Sonnet 5 | $0.00113 | $0.00113 |
| Haiku 4.5 | $0.00056 | $0.00056 |
Grade A, and why
style scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 101 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Coding Style
Surgical Changes
Every changed line must trace directly back to the user's request. Adjacent "improvements" inflate the diff, make review harder, and cause unintended regressions.
MUST NOT
- "Improve" neighboring code, formatting, or comments along the way.
- Refactor something that is not broken.
- Change existing style to your own preference (quotes, indentation, line breaks, import order).
- Add type hints, docstrings, or comments that were not asked for.
- Slip in a new abstraction, flag, setting, or option nobody requested.
- Delete unrelated dead code — mention it and propose it as separate work.
- Mix two purposes into one commit or PR.
MUST
- Match the existing style, naming, and formatting exactly.
- Clean up only the imports, variables, and functions your own change orphaned.
- State "behavior is unchanged" explicitly when the refactor is behavior-preserving.
Immutability (CRITICAL)
ALWAYS create new objects, NEVER mutate:
// WRONG: Mutation
function updateUser(user, name) {
user.name = name // MUTATION!
return user
}
// CORRECT: Immutability
function updateUser(user, name) {
return {
...user,
name
}
}
File Organization
MANY SMALL FILES > FEW LARGE FILES:
- High cohesion, low coupling
- 200-400 lines typical, 800 max
- Extract utilities from large components
- Organize by feature/domain, not by type
Error Handling
ALWAYS handle errors comprehensively:
try {
const result = await riskyOperation()
return result
} catch (error) {
console.error('Operation failed:', error)
throw new Error('Detailed user-friendly message')
}
Input Validation
ALWAYS validate user input:
import { z } from 'zod'
const schema = z.object({
email: z.string().email(),
age: z.number().int().min(0).max(150)
})
const validated = schema.parse(input)
Code Quality Checklist
Before marking work complete:
- Code is readable and well-named
- Functions are small (<50 lines)
- Files are focused (<800 lines)
- No deep nesting (>4 levels)
- Proper error handling
- No hardcoded values
- No mutation (immutable patterns used)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 101 lines · 563 tokens per session scan A 39dd21a395dc
style is a cursor rule published in the GitHub repository timurgaleev/vibestack (6 stars, last pushed yesterday), licensed MIT. It adds 563 tokens to every session, about $0.0028 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-19.
Other cursor rules, from other repositories
tech-writer
Guide the AI to act as a Senior Technical Writer, focusing on clear and concise documentation.
ai-expert
Guide the AI to act as an AI/ML/MLOps Expert, integrating modern AI tooling, including AI agents, AI-powered IDEs, MCP servers, and online AI-powered tools.
back-end-dev
Guide the AI to act as a Senior Back-End Developer, focusing on modern back-end languages and frameworks.
product-owner
Guide the AI to act as a Senior Product Owner with strong UI/UX design capabilities, focusing on user-centric product development.
devops
Guide the AI to act as a Modern DevOps Engineer, specializing in AWS, Azure, and Google Cloud Platform.
architect
Guide the AI to act as a Software Architect, focusing on system design and scalability.