dev-guidelines

A set of development rules for the Feishu MCP server repository, covering its workflow, issues, branches, commits, and pull requests.

In plain words
What is it for?
Use it to name branches, create issues, format Conventional Commit messages, link pull requests to issues, run tests, request approval, and complete the GitHub Flow process.
Why use it?
It makes the team’s contribution process explicit, reducing mistakes when preparing changes for review and merging.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/xumingmingming/feishu-mcp-server/dev-guidelines
Clone the repo
git clone --depth 1 https://github.com/Xumingmingming/feishu-mcp-server

Made for: Cursor.

Per session 2 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 398 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin 100% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00002 $0.00398
Opus 5 $0.00001 $0.00199
Sonnet 5 $0.00000 $0.00080
Haiku 4.5 $0.00000 $0.00040

Measured yesterday against content hash cbdfc327ac2e, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

dev-guidelines scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

100% identical to dev-guidelines — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

.cursor/rules/dev-guidelines.mdc · 48 lines

What it actually says

项目开发规范

仓库信息

开发流程

  1. 创建 Issue
  2. main 创建功能分支,使用描述性名称 (如 feature/add-new-component)
  3. 在分支上进行代码修改
  4. main 提交 Pull Request
  5. 通过 Code Review 并获得批准
  6. 合并 Pull Request
  7. 删除功能分支
  8. 关闭 Issue

Issue 管理

  • 使用 .github/ISSUE_TEMPLATE 中的模板创建 Issue
  • 可用模板:
    • Bug report
    • Feature request
    • Custom issue

分支策略

  • 分支命名规范: feature/bugfix/hotfix/release/support/ 开头,后接描述性名称
  • 所有分支均从 main 创建

提交信息

  • 遵循 Conventional Commits 格式:
    • feat: 新功能
    • fix: Bug 修复
    • docs: 文档修改
    • style: 不影响代码含义的修改 (空格、格式化等)
    • refactor: 既非修复 Bug 也非新增功能的代码重构
    • test: 新增或更新测试
    • chore: 构建过程或辅助工具的变更

Pull Request 流程

  • 在 PR 描述中引用相关 Issue
  • 确保所有测试通过
  • 如有必要,更新文档
  • 至少获得一次审批后再合并
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 48 lines · 2 tokens per session scan A cbdfc327ac2e

Subscribe to this mod's changes

dev-guidelines is a cursor rule published in the GitHub repository Xumingmingming/feishu-mcp-server (0 stars, last pushed 1y ago), licensed MIT. It adds 2 tokens to every session and 398 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to dev-guidelines, differing in 0 lines, and is treated as a copy.