Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/zackiles/cursor-mcp-manager/with-javascript-vibegit clone --depth 1 https://github.com/zackiles/cursor-mcp-managerWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.01735 |
| Opus 5 | $0.00000 | $0.00868 |
| Sonnet 5 | $0.00000 | $0.00347 |
| Haiku 4.5 | $0.00000 | $0.00173 |
Grade A, and why
with-javascript-vibe scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
95% identical to with-javascript-vibe — 6 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 194 lines — stays where its author put it; the contents beside it link to each section on GitHub.
CODING STYLE GUIDE - JAVASCRIPT AND TYPESCRIPT (MANDATORY OR STRONGLY ENCOURAGED)
Naming
- snake_case for file names.
- camelCase for instance names.
- PascalCase for class and symbol names.
- UPPER_SNAKE_CASE for constants.
Code Ordering
- Remote Imports
- Local Imports
- Hoisted Variables and References
- Methods
- Exports
Syntax
- Favor modern ECMAScript ES2024 Typescript 5.7 features and patterns:
- Object & array destructuring
- Optional chaining (
?.) & nullish coalescing (??) - Arrow functions & implicit returns
- Template literals (``) for string interpolation
- Spread (
...) & rest parameters - Proxy and Reflect
- Private class fields
- Atomics for concurrency
- Logical assignment operators
- WeakRefs, BigInt, Crypto, SharedArrayBuffer
- TextEncoder, TextDecoder, WebSocketStream, etc.
- Semicolon Usage
- Always follow the existing codebase's semicolon style
- If the codebase uses semicolons, include them consistently
- If the codebase omits semicolons, ensure they are not added
- When in doubt, verify the style in multiple files before making assumptions
- For new codebases, default to no semicolons unless specified otherwise
New Methods That Excite You As Javascript Developer
- Map(), WeakMap(), Set(), WeakSet(), WeakRef()
- Reflect()
- Proxy()
- BigInt()
- SharedArrayBuffer()
- structuredClone()
- TypedArray()
- Symbol()
- FinalizationRegistry()
- New utilitiy methods: str.toCapitalCase(), array.toReversed()
- toWellFormed()
- AllocateArrayBuffer()
- DataVieww()
- Float64Array(), Uint8ClampedArray(), Uint32Array()
- globalThis()
- Promise.withResolvers()
- Promise.try()
- Temporal.Now.zonedDateTimeISO()
- new Realm()
Examples of Modern
- Atomic waitSync()
const sharedArray = new Int32Array(new SharedArrayBuffer(1024));
// Example usage in a hypothetical shared memory scenario
function performSynchronizedOperation(index, value) {
Atomics.waitSync(sharedArray, index, 0); // Wait until condition is met
sharedArray[index] = value;
Atomics.notify(sharedArray, index, 1); // Notify other threads of the update
}
- Regular Expressions with the v Flag and Set Notation
// Using set notation to match characters with specific Unicode properties
const regex = /\p{Script=Greek}/v;
- Pipeline Operator (|>)
// Output of one function is passed as input to the next. This makes code easier to read and helps organize complex transformations
const processedValue = -10
|> (n => Math.max(0, n))
|> (n => Math.pow(n, 1/3))
|> Math.ceil;
- Records and Tuples (|>)
const userProfile = #{ username: "Alice", age: 30 };
const updatedProfile = userProfile.with({ age: 31 });
console.log(updatedProfile); // #{ username: "Alice", age: 31 }
console.log(userProfile); // #{ username: "Alice", age: 30 } (remains unchanged)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 194 lines · 1,735 tokens per session scan A 65d9a3404cb1
with-javascript-vibe is a cursor rule published in the GitHub repository zackiles/cursor-mcp-manager (3 stars, last pushed 1y ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 1,735 tokens. A static security scan graded it A with 0 findings. It is 95% identical to with-javascript-vibe, differing in 6 lines, and is treated as a copy.
Other cursor rules, from other repositories
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
cli-error-handling
CLI command error handling patterns.
prefer-direct-imports-over-module-mocks
Prefer extracting a testable core over vi.mock / vi.resetModules when unit tests need to reach production logic entangled with config, env, or singletons.
control-plane-descriptors
Control plane descriptor and instance implementation patterns.
family-instance-domain-actions
Family instance domain action implementation patterns.