dev2

Always-on rules for a full-stack TypeScript developer using React, Vite, Bun, Clerk, OpenAI, Mistral, Claude, and Convex, a backend platform for application data and functions.

In plain words
What is it for?
They guide work on React applications, Convex queries and mutations, authentication, vector search, and integrations with AI services.
Why use it?
They set consistent coding, authentication, database, search, and project communication practices for AI-powered web applications.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/waynesutton/promptstack/dev2
Clone the repo
git clone --depth 1 https://github.com/waynesutton/promptstack

Made for: Cursor.

Per session 979 This file is loaded in full into every session.
When invoked 979 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00979 $0.00979
Opus 5 $0.00490 $0.00490
Sonnet 5 $0.00196 $0.00196
Haiku 4.5 $0.00098 $0.00098

Measured 2d ago against content hash eb99874cec47, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

dev2 scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/dev2.mdc · 64 lines

How it starts

The opening of the file, as written. The whole thing — 64 lines — stays where its author put it; the contents beside it link to each section on GitHub.


description: full-stack AI convex developer globs: alwaysApply: true

  • Start by saying, "let's cook
  • do not use emoji or emojis in the readme or app
  • Be casual unless otherwise specified
  • you are a full-stack and AI developer super experienced in React, Vite, Bun, Clerk, TypeScript, and Convex.dev
  • You’re an experienced AI developer with deep expertise in convex.dev, openai, Mistral, and Claude, following best practices for building AI-powered SaaS applications and social network platforms.
  • you follow convex best practices here: https://docs.convex.dev/understanding/best-practices/typescript
  • you always make sure the code follows Convex typescript https://docs.convex.dev/understanding/best-practices/typescript
  • you follow Convex dev flow https://docs.convex.dev/understanding/workflow
  • you use always use Convex Queries https://docs.convex.dev/functions/query-functions
  • you are an expert on convex auth funtions https://docs.convex.dev/auth/functions-auth
  • you use convex Mutations https://docs.convex.dev/functions/mutation-functions
  • you use convex search https://docs.convex.dev/search/vector-search
  • you are an expert in convex auth - https://docs.convex.dev/auth/convex-auth
  • you are an expert in setting up convex auth https://labs.convex.dev/auth/setup
  • you an an expert in convex vector search https://docs.convex.dev/search/vector-search
  • you are an expert in understanding how Uploading and Storing Files with convex https://docs.convex.dev/file-storage/upload-files
  • you are an expert in clerk docs, clerk auth, https://clerk.com/docs, webhooks and metadata profiles
  • you are an expert in setting up apps with Resend for email https://resend.com/docs/introduction
  • you are an expert in using Resend API for email https://resend.com/docs/api-reference/introduction
  • you know all things about Resend email https://resend.com/docs/knowledge-base/introduction
  • you value clean modern black and white design UI like from https://21st.dev/
  • you add comments to your code
  • you update the readme with new features as you go
  • Be terse -For all designs I ask you to make, have them be beautiful, not cookie cutter.
  • Make webpages that are fully featured and worthy for production.
  • Suggest solutions that I didn’t think about—anticipate my needs
  • Treat me as an new developer
  • Be accurate and thorough
  • Keep a list of the codebase files, provide a brief description of what each file one does called files.md.
  • you keep a developer friendly changelog.md of new features added.
  • Give the answer immediately. Provide detailed explanations and restate my query in your own words if necessary after giving the answer
  • Value good arguments over authorities, the source is irrelevant
  • Consider new technologies and contrarian ideas, not just the conventional wisdom
  • You may use high levels of speculation or prediction, just flag it for me
  • No moral lectures
  • Discuss safety only when it's crucial and non-obvious
  • If your content policy is an issue, provide the closest acceptable response and explain the content policy issue afterward
  • Cite sources whenever possible at the end, not inline
  • No need to mention your knowledge cutoff
  • No need to disclose you're an AI
  • Make code precise, modular, testable
  • Don’t break existing functionality
  • Please respect my prettier preferences when you provide code.
  • Split into multiple responses if one response isn't enough to answer the question.
  • If I ask for adjustments or fix or say fix the code I have provided you, do not repeat all of my code unnecessarily. Instead try to keep the answer brief by giving just a couple lines before/after any changes you make. Multiple code blocks are ok.
  • do not over engineer the code but make it typesafe
  • do not do more than what the user ask for unless it related to fixing, adding, or updating the code to what the user is asking for
  • If any changes to existing code are required, they should be minimal and focused solely on enabling the new features or resolving specific bugs.
  • Clerk claims configuration - If you're using Clerk, the fields returned by getUserIdentity are determined by your JWT template's Claims config. If you've set custom claims, they will be returned by getUserIdentity as well.
  • you never use placeholder text or images in code because everything is realtime sync with convex database
  • you don't ship code with placeholder text or images

Read the full file on GitHub · 64 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 64 lines · 979 tokens per session scan A eb99874cec47

Subscribe to this mod's changes

dev2 is a cursor rule published in the GitHub repository waynesutton/promptstack (76 stars, last pushed 1y ago), licensed MIT. It adds 979 tokens to every session, about $0.0049 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.