Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/vibestackdev/vibe-stack/react19-patternsgit clone --depth 1 https://github.com/vibestackdev/vibe-stackWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00571 |
| Opus 5 | $0.00000 | $0.00285 |
| Sonnet 5 | $0.00000 | $0.00114 |
| Haiku 4.5 | $0.00000 | $0.00057 |
Grade A, and why
react19-patterns scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 85 lines — stays where its author put it; the contents beside it link to each section on GitHub.
React 19 / Next.js 15 Migration Traps
RULE 1: useFormStatus Must Be Inside
useFormStatus() only works when the component using it is a CHILD of a <form>
element that uses a Server Action. It does NOT work if used in the same component
that renders the form.
// ❌ WRONG — useFormStatus returns { pending: false } always
'use client'
export function MyForm() {
const { pending } = useFormStatus() // Always false here
return (
<form action={createItem}>
<Button disabled={pending}>Submit</Button>
</form>
)
}
// ✅ CORRECT — extract the submit button to a child component
'use client'
import { useFormStatus } from 'react-dom'
function SubmitButton() {
const { pending } = useFormStatus()
return <Button disabled={pending}>{pending ? 'Saving...' : 'Submit'}</Button>
}
export function MyForm() {
return (
<form action={createItem}>
<SubmitButton />
</form>
)
}
RULE 2: useActionState Replaces useFormState
useFormState is DEPRECATED in React 19. Use useActionState instead.
// ❌ DEPRECATED
import { useFormState } from 'react-dom'
// ✅ CORRECT — React 19
import { useActionState } from 'react'
const [state, formAction, isPending] = useActionState(serverAction, initialState)
RULE 3: ref Is a Regular Prop in React 19
forwardRef() is no longer required. ref is passed as a regular prop.
// ❌ DEPRECATED — verbose, unnecessary in React 19
const MyInput = forwardRef<HTMLInputElement, InputProps>((props, ref) => {
return <input ref={ref} {...props} />
})
// ✅ CORRECT — React 19
function MyInput({ ref, ...props }: InputProps & { ref?: React.Ref<HTMLInputElement> }) {
return <input ref={ref} {...props} />
}
RULE 4: use() Hook for Promises and Context
React 19 use() can unwrap Promises in render. Use it instead of useEffect for
data fetching in client components.
// ✅ React 19 — use() for context (replaces useContext)
import { use } from 'react'
const theme = use(ThemeContext)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 85 lines · 0 tokens per session scan A 5747cf9d418f
react19-patterns is a cursor rule published in the GitHub repository vibestackdev/vibe-stack (7 stars, last pushed 2d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 571 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
cursor
SEO audit and implementation for Next.js, Remix, and React SPAs. Auto-attached to page, layout, and route files. Covers meta tags, Open Graph, Twitter cards, JSON-LD, sitemaps, robots.txt, i18n/hreflang, and image SEO.
diagnose
name: Issue Re-Diagnosis and Fix Template description: Template for AI to re-diagnose and fix issues that weren't resolved previously. globs.
always-on
Cursor rule "always-on" from jjcall/vibeship-boilerplate, covering core persona, how you work in this project, how you verify and validate, when you should ask for feedback or approval and how you communicate.
request
name: Issue Re-Diagnosis and Fix Template description: Template for AI to re-diagnose and fix issues that weren't resolved previously. globs.
upgrade-tests
// ✅ CORRECT: Upgrade package pattern await using ctx = testReactResource(appRouter, { server: { // server configuration }, client(opts) { return { links: [ httpLink({ url: opts.httpUrl, // client configuration }), ], }; }, }).
react-query-tests
// ✅ CORRECT: Legacy React Query pattern const ctx = konn() .beforeEach(() => createAppRouter()) .afterEach((ctx) => ctx?.close?.()) .done().