From 4e8dbc44234cc0cf760dff0aa1a45efa60e28b40 Mon Sep 17 00:00:00 2001 From: PatrickJS Date: Tue, 12 May 2026 21:40:44 -0700 Subject: [PATCH 01/10] Remove legacy Python FastAPI cursor rules Remove the obsolete rules/cursorrules-file-cursor-ai-python-fastapi-api rule set (deleted .cursorrules, README.md and multiple .mdc rule files) and clean up README.md by removing the duplicate Python (FastAPI) entry. This prunes deprecated/duplicated Cursor rules for FastAPI and reduces confusion in the rules index. --- README.md | 1 - .../.cursorrules | 69 ------------------- .../README.md | 16 ----- .../error-handling-priorities.mdc | 12 ---- .../fastapi-blocking-operations.mdc | 8 --- .../fastapi-components-and-validation.mdc | 6 -- .../fastapi-conditional-statements.mdc | 7 -- .../fastapi-dependencies.mdc | 8 --- .../fastapi-dependency-injection.mdc | 5 -- .../fastapi-file-structure.mdc | 5 -- .../fastapi-function-definitions.mdc | 6 -- .../fastapi-middleware.mdc | 8 --- .../fastapi-performance-metrics.mdc | 5 -- .../fastapi-performance-optimization.mdc | 8 --- .../fastapi-startup-and-shutdown-events.mdc | 5 -- .../python-general-style.mdc | 11 --- 16 files changed, 180 deletions(-) delete mode 100644 rules/cursorrules-file-cursor-ai-python-fastapi-api/.cursorrules delete mode 100644 rules/cursorrules-file-cursor-ai-python-fastapi-api/README.md delete mode 100644 rules/cursorrules-file-cursor-ai-python-fastapi-api/error-handling-priorities.mdc delete mode 100644 rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-blocking-operations.mdc delete mode 100644 rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-components-and-validation.mdc delete mode 100644 rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-conditional-statements.mdc delete mode 100644 rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-dependencies.mdc delete mode 100644 rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-dependency-injection.mdc delete mode 100644 rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-file-structure.mdc delete mode 100644 rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-function-definitions.mdc delete mode 100644 rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-middleware.mdc delete mode 100644 rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-performance-metrics.mdc delete mode 100644 rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-performance-optimization.mdc delete mode 100644 rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-startup-and-shutdown-events.mdc delete mode 100644 rules/cursorrules-file-cursor-ai-python-fastapi-api/python-general-style.mdc diff --git a/README.md b/README.md index 94c01968..9ec6a801 100644 --- a/README.md +++ b/README.md @@ -153,7 +153,6 @@ By creating a `.cursorrules` file in your project's root directory, you can leve - [Node.js (MongoDB, JWT, Express, React)](./rules/nodejs-mongodb-jwt-express-react-cursorrules-promp/.cursorrules) - Cursor rules for Node.js development with MongoDB, JWT, Express, and React integration. - [Rails 8 (Basic Setup)](./rules/rails-cursorrules-prompt-file/rails-basics.mdx) - Cursor rules for Rails development with basic setup. - [Python (FastAPI)](./rules/py-fast-api/.cursorrules) - Cursor rules for Python FastAPI backend development and best practices. -- [Python (FastAPI)](./rules/cursorrules-file-cursor-ai-python-fastapi-api/.cursorrules) - Cursor rules for Python FastAPI development with API integration. - [Python 3.12 (FastAPI Best Practices)](./rules/python-312-fastapi-best-practices-cursorrules-prom/.cursorrules) - Cursor rules for Python FastAPI development with best practices. - [Python (Django Best Practices)](./rules/python-django-best-practices-cursorrules-prompt-fi/.cursorrules) - Cursor rules for Python Django development with best practices. - [Python (FastAPI Best Practices)](./rules/python-fastapi-best-practices-cursorrules-prompt-f/.cursorrules) - Cursor rules for Python FastAPI development with best practices. diff --git a/rules/cursorrules-file-cursor-ai-python-fastapi-api/.cursorrules b/rules/cursorrules-file-cursor-ai-python-fastapi-api/.cursorrules deleted file mode 100644 index 02c5bd51..00000000 --- a/rules/cursorrules-file-cursor-ai-python-fastapi-api/.cursorrules +++ /dev/null @@ -1,69 +0,0 @@ -You are an expert in Python, FastAPI, and scalable API development. - -Key Principles - -- Write concise, technical responses with accurate Python examples. -- Use functional, declarative programming; avoid classes where possible. -- Prefer iteration and modularization over code duplication. -- Use descriptive variable names with auxiliary verbs (e.g., is_active, has_permission). -- Use lowercase with underscores for directories and files (e.g., routers/user_routes.py). -- Favor named exports for routes and utility functions. -- Use the Receive an Object, Return an Object (RORO) pattern. - -Python/FastAPI - -- Use def for pure functions and async def for asynchronous operations. -- Use type hints for all function signatures. Prefer Pydantic models over raw dictionaries for input validation. -- File structure: exported router, sub-routes, utilities, static content, types (models, schemas). -- Avoid unnecessary curly braces in conditional statements. -- For single-line statements in conditionals, omit curly braces. -- Use concise, one-line syntax for simple conditional statements (e.g., if condition: do_something()). - -Error Handling and Validation - -- Prioritize error handling and edge cases: - - Handle errors and edge cases at the beginning of functions. - - Use early returns for error conditions to avoid deeply nested if statements. - - Place the happy path last in the function for improved readability. - - Avoid unnecessary else statements; use the if-return pattern instead. - - Use guard clauses to handle preconditions and invalid states early. - - Implement proper error logging and user-friendly error messages. - - Use custom error types or error factories for consistent error handling. - -Dependencies - -- FastAPI -- Pydantic v2 -- Async database libraries like asyncpg or aiomysql -- SQLAlchemy 2.0 (if using ORM features) - -FastAPI-Specific Guidelines - -- Use functional components (plain functions) and Pydantic models for input validation and response schemas. -- Use declarative route definitions with clear return type annotations. -- Use def for synchronous operations and async def for asynchronous ones. -- Minimize @app.on_event("startup") and @app.on_event("shutdown"); prefer lifespan context managers for managing startup and shutdown events. -- Use middleware for logging, error monitoring, and performance optimization. -- Optimize for performance using async functions for I/O-bound tasks, caching strategies, and lazy loading. -- Use HTTPException for expected errors and model them as specific HTTP responses. -- Use middleware for handling unexpected errors, logging, and error monitoring. -- Use Pydantic's BaseModel for consistent input/output validation and response schemas. - -Performance Optimization - -- Minimize blocking I/O operations; use asynchronous operations for all database calls and external API requests. -- Implement caching for static and frequently accessed data using tools like Redis or in-memory stores. -- Optimize data serialization and deserialization with Pydantic. -- Use lazy loading techniques for large datasets and substantial API responses. - -Key Conventions - -1. Rely on FastAPI’s dependency injection system for managing state and shared resources. -2. Prioritize API performance metrics (response time, latency, throughput). -3. Limit blocking operations in routes: - - Favor asynchronous and non-blocking flows. - - Use dedicated async functions for database and external API operations. - - Structure routes and dependencies clearly to optimize readability and maintainability. - -Refer to FastAPI documentation for Data Models, Path Operations, and Middleware for best practices. - diff --git a/rules/cursorrules-file-cursor-ai-python-fastapi-api/README.md b/rules/cursorrules-file-cursor-ai-python-fastapi-api/README.md deleted file mode 100644 index a94c16b1..00000000 --- a/rules/cursorrules-file-cursor-ai-python-fastapi-api/README.md +++ /dev/null @@ -1,16 +0,0 @@ -# .cursorrules file Cursor AI Python FastAPI API - -Author: Caio Barbieri - -## What you can build -API Performance Monitoring Tool: A web app that uses FastAPI to track, analyze, and optimize API performance metrics such as response time, latency, and throughput. It will provide real-time dashboards and alerts for performance issues.Async API Wrapper Generator: A command-line tool that generates FastAPI-based Python code for interfacing with external APIs. It will automatically include async functions for non-blocking API operations and error-handling patterns.Validation and Error Handling Library: A Python library that provides utilities and decorators for consistent error handling and input validation using Pydantic in FastAPI projects. It will focus on guard clauses, custom error types, and error logging.Database Interaction Utility: A lightweight Python package that facilitates the use of async database libraries with SQLAlchemy 2.0 in FastAPI, focusing on optimizing query performance and using lazy loading techniques.FastAPI Middleware Suite: A collection of pre-built middleware for FastAPI applications focusing on logging, error monitoring, performance optimization, and security enhancements.Scalable API Bootstrapping Service: A web-based service that allows users to generate boilerplate code for scalable FastAPI applications, adhering to best practices in API development, modular file structures, and dependency injection patterns.Pydantic Schema Generator: A GUI application that generates Pydantic models and schemas from JSON or YAML files, aiding in the consistent use of input/output validation and response schemas in FastAPI projects.Cache Management Plugin: A FastAPI plugin that facilitates the integration and management of caching strategies using tools like Redis for optimizing the performance of frequently accessed endpoints.Async Workflow Orchestrator: A tool for managing complex async workflows and I/O-bound tasks in FastAPI applications, providing templates and patterns for building robust and non-blocking routes.FastAPI Route Optimizer: An IDE plugin or script that reviews FastAPI code to suggest optimizations for route definitions, dependency injection usage, and async operation patterns to enhance readability and performance. - -## Benefits - - -## Synopsis - - -## Overview of .cursorrules prompt -The .cursorrules file outlines key principles and guidelines for developing scalable APIs using Python and FastAPI. It emphasizes writing concise and technical responses with accurate code examples, adhering to functional programming principles, and employing modular and iterative approaches to reduce code duplication. The file provides detailed instructions on Python/FastAPI usage, including the structure of files and functions, error handling, and dependency requirements. It highlights performance optimization tactics such as using asynchronous operations, caching, and lazy loading. Key conventions include the reliance on FastAPI's dependency injection system, focusing on API performance metrics, and limiting blocking operations. It encourages adherence to FastAPI's best practices for data models, path operations, and middleware. - diff --git a/rules/cursorrules-file-cursor-ai-python-fastapi-api/error-handling-priorities.mdc b/rules/cursorrules-file-cursor-ai-python-fastapi-api/error-handling-priorities.mdc deleted file mode 100644 index 3bf401e3..00000000 --- a/rules/cursorrules-file-cursor-ai-python-fastapi-api/error-handling-priorities.mdc +++ /dev/null @@ -1,12 +0,0 @@ ---- -description: Emphasizes the importance of prioritizing error handling and edge cases in Python code. -globs: **/*.py ---- -- Prioritize error handling and edge cases: - - Handle errors and edge cases at the beginning of functions. - - Use early returns for error conditions to avoid deeply nested if statements. - - Place the happy path last in the function for improved readability. - - Avoid unnecessary else statements; use the if-return pattern instead. - - Use guard clauses to handle preconditions and invalid states early. - - Implement proper error logging and user-friendly error messages. - - Use custom error types or error factories for consistent error handling. \ No newline at end of file diff --git a/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-blocking-operations.mdc b/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-blocking-operations.mdc deleted file mode 100644 index 015d5894..00000000 --- a/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-blocking-operations.mdc +++ /dev/null @@ -1,8 +0,0 @@ ---- -description: Limits blocking operations in routes, favoring asynchronous and non-blocking flows. -globs: **/routers/*.py ---- -- Limit blocking operations in routes: - - Favor asynchronous and non-blocking flows. - - Use dedicated async functions for database and external API operations. - - Structure routes and dependencies clearly to optimize readability and maintainability. \ No newline at end of file diff --git a/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-components-and-validation.mdc b/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-components-and-validation.mdc deleted file mode 100644 index 129f39c9..00000000 --- a/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-components-and-validation.mdc +++ /dev/null @@ -1,6 +0,0 @@ ---- -description: Specifies the use of functional components and Pydantic models for input validation in FastAPI routes. -globs: **/routers/*.py ---- -- Use functional components (plain functions) and Pydantic models for input validation and response schemas. -- Use declarative route definitions with clear return type annotations. \ No newline at end of file diff --git a/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-conditional-statements.mdc b/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-conditional-statements.mdc deleted file mode 100644 index d7ed7af7..00000000 --- a/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-conditional-statements.mdc +++ /dev/null @@ -1,7 +0,0 @@ ---- -description: Outlines the preferred style for conditional statements in Python files. -globs: **/*.py ---- -- Avoid unnecessary curly braces in conditional statements. -- For single-line statements in conditionals, omit curly braces. -- Use concise, one-line syntax for simple conditional statements (e.g., if condition: do_something()). \ No newline at end of file diff --git a/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-dependencies.mdc b/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-dependencies.mdc deleted file mode 100644 index e4464eb0..00000000 --- a/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-dependencies.mdc +++ /dev/null @@ -1,8 +0,0 @@ ---- -description: Lists essential dependencies for FastAPI projects. -globs: **/requirements.txt ---- -- FastAPI -- Pydantic v2 -- Async database libraries like asyncpg or aiomysql -- SQLAlchemy 2.0 (if using ORM features) \ No newline at end of file diff --git a/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-dependency-injection.mdc b/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-dependency-injection.mdc deleted file mode 100644 index e18eaee3..00000000 --- a/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-dependency-injection.mdc +++ /dev/null @@ -1,5 +0,0 @@ ---- -description: Emphasizes the reliance on FastAPI’s dependency injection system for managing state and shared resources. -globs: **/dependencies/*.py ---- -- Rely on FastAPI’s dependency injection system for managing state and shared resources. \ No newline at end of file diff --git a/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-file-structure.mdc b/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-file-structure.mdc deleted file mode 100644 index 23006c77..00000000 --- a/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-file-structure.mdc +++ /dev/null @@ -1,5 +0,0 @@ ---- -description: Defines the preferred file structure for FastAPI router modules. -globs: **/routers/*.py ---- -- File structure: exported router, sub-routes, utilities, static content, types (models, schemas). \ No newline at end of file diff --git a/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-function-definitions.mdc b/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-function-definitions.mdc deleted file mode 100644 index 4e2435d1..00000000 --- a/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-function-definitions.mdc +++ /dev/null @@ -1,6 +0,0 @@ ---- -description: Specifies the use of 'def' and 'async def' for function definitions within FastAPI routers. -globs: **/routers/*.py ---- -- Use def for pure functions and async def for asynchronous operations. -- Use type hints for all function signatures. Prefer Pydantic models over raw dictionaries for input validation. \ No newline at end of file diff --git a/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-middleware.mdc b/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-middleware.mdc deleted file mode 100644 index aa436242..00000000 --- a/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-middleware.mdc +++ /dev/null @@ -1,8 +0,0 @@ ---- -description: Specifies the use of middleware for logging, error monitoring, and performance optimization in FastAPI applications. -globs: **/middleware/*.py ---- -- Use middleware for logging, error monitoring, and performance optimization. -- Use HTTPException for expected errors and model them as specific HTTP responses. -- Use middleware for handling unexpected errors, logging, and error monitoring. -- Use Pydantic's BaseModel for consistent input/output validation and response schemas. \ No newline at end of file diff --git a/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-performance-metrics.mdc b/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-performance-metrics.mdc deleted file mode 100644 index bdbd5098..00000000 --- a/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-performance-metrics.mdc +++ /dev/null @@ -1,5 +0,0 @@ ---- -description: Prioritizes API performance metrics in FastAPI applications, focusing on response time, latency, and throughput. -globs: **/*.py ---- -- Prioritize API performance metrics (response time, latency, throughput). \ No newline at end of file diff --git a/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-performance-optimization.mdc b/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-performance-optimization.mdc deleted file mode 100644 index df6a39ed..00000000 --- a/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-performance-optimization.mdc +++ /dev/null @@ -1,8 +0,0 @@ ---- -description: Outlines performance optimization techniques for FastAPI applications, including asynchronous operations and caching. -globs: **/*.py ---- -- Minimize blocking I/O operations; use asynchronous operations for all database calls and external API requests. -- Implement caching for static and frequently accessed data using tools like Redis or in-memory stores. -- Optimize data serialization and deserialization with Pydantic. -- Use lazy loading techniques for large datasets and substantial API responses. \ No newline at end of file diff --git a/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-startup-and-shutdown-events.mdc b/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-startup-and-shutdown-events.mdc deleted file mode 100644 index e60473a5..00000000 --- a/rules/cursorrules-file-cursor-ai-python-fastapi-api/fastapi-startup-and-shutdown-events.mdc +++ /dev/null @@ -1,5 +0,0 @@ ---- -description: Recommends minimizing the use of startup and shutdown events in favor of lifespan context managers. -globs: **/main.py ---- -- Minimize @app.on_event("startup") and @app.on_event("shutdown"); prefer lifespan context managers for managing startup and shutdown events. \ No newline at end of file diff --git a/rules/cursorrules-file-cursor-ai-python-fastapi-api/python-general-style.mdc b/rules/cursorrules-file-cursor-ai-python-fastapi-api/python-general-style.mdc deleted file mode 100644 index b61c6dea..00000000 --- a/rules/cursorrules-file-cursor-ai-python-fastapi-api/python-general-style.mdc +++ /dev/null @@ -1,11 +0,0 @@ ---- -description: Applies general Python style guidelines including functional programming preferences and naming conventions. -globs: **/*.py ---- -- Write concise, technical responses with accurate Python examples. -- Use functional, declarative programming; avoid classes where possible. -- Prefer iteration and modularization over code duplication. -- Use descriptive variable names with auxiliary verbs (e.g., is_active, has_permission). -- Use lowercase with underscores for directories and files (e.g., routers/user_routes.py). -- Favor named exports for routes and utility functions. -- Use the Receive an Object, Return an Object (RORO) pattern. \ No newline at end of file From 6ff5b68c1a48cc6aff3054934beb75eb65042380 Mon Sep 17 00:00:00 2001 From: PatrickJS Date: Tue, 12 May 2026 21:46:22 -0700 Subject: [PATCH 02/10] Run trusted repo-hygiene on PRs; add rule metadata Restrict workflow permissions and run hygiene checks against a trusted base for pull requests: grant read-only contents permission, checkout the PR base to .trusted-base, and execute the trusted check-repo-hygiene script for PRs. Update the hygiene script to change README external-listing messaging and adjust its behavior; update tests to match the new expectations and add a new workflow-security.test.mjs to assert the workflow changes. Add/adjust many rule files (rules-new/*.mdc) to include globs/alwaysApply metadata and minor formatting fixes, and add several .cursorrules files (Rails, Solidity/Web3, Svelte5, Vue/Nuxt) to populate rule content. --- .github/workflows/main.yml | 16 +++++ .../automl-hyperparameter-optimization.mdc | 55 +++++++++++++++ rules-new/beefreeSDK.mdc | 3 +- rules-new/blender-python-addon.mdc | 52 ++++++++++++++ rules-new/clean-code.mdc | 5 +- rules-new/codequality.mdc | 5 +- rules-new/database.mdc | 3 +- rules-new/embedded-stm32-hal.mdc | 55 +++++++++++++++ rules-new/fastapi.mdc | 3 +- rules-new/fortran.mdc | 66 ++++++++++++++++++ rules-new/gamemaker-gml.mdc | 53 +++++++++++++++ rules-new/gitflow.mdc | 4 +- rules-new/google-adk.mdc | 52 ++++++++++++++ rules-new/harmony-arkts.mdc | 54 +++++++++++++++ rules-new/kubestellar-console.mdc | 1 + rules-new/medusa.mdc | 3 +- rules-new/nativescript.mdc | 1 + rules-new/nextjs.mdc | 3 +- rules-new/node-express.mdc | 3 +- rules-new/python.mdc | 3 +- rules-new/react-router-v7.mdc | 52 ++++++++++++++ rules-new/react.mdc | 3 +- rules-new/ros-ros2.mdc | 44 ++++++++++++ rules-new/rust-general.mdc | 52 ++++++++++++++ rules-new/rust.mdc | 1 + rules-new/svelte.mdc | 3 +- rules-new/tailwind.mdc | 3 +- rules-new/tensorflow-deep-learning.mdc | 54 +++++++++++++++ rules-new/toss-style-design-system.mdc | 67 +++++++++++++++++++ rules-new/typescript.mdc | 3 +- rules-new/vue.mdc | 3 +- .../.cursorrules | 34 ++++++++++ .../.cursorrules | 45 ++++++++++++- .../.cursorrules | 9 ++- .../.cursorrules | 47 ++++++++++++- scripts/check-repo-hygiene.mjs | 5 +- scripts/check-repo-hygiene.test.mjs | 19 +++++- scripts/workflow-security.test.mjs | 17 +++++ 38 files changed, 871 insertions(+), 30 deletions(-) create mode 100644 rules-new/automl-hyperparameter-optimization.mdc create mode 100644 rules-new/blender-python-addon.mdc create mode 100644 rules-new/embedded-stm32-hal.mdc create mode 100644 rules-new/fortran.mdc create mode 100644 rules-new/gamemaker-gml.mdc create mode 100644 rules-new/google-adk.mdc create mode 100644 rules-new/harmony-arkts.mdc create mode 100644 rules-new/react-router-v7.mdc create mode 100644 rules-new/ros-ros2.mdc create mode 100644 rules-new/rust-general.mdc create mode 100644 rules-new/tensorflow-deep-learning.mdc create mode 100644 rules-new/toss-style-design-system.mdc create mode 100644 scripts/workflow-security.test.mjs diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index 1ffa9d60..c9664cc4 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -6,6 +6,9 @@ on: push: branches: [main] +permissions: + contents: read + jobs: repo-hygiene: runs-on: ubuntu-latest @@ -72,5 +75,18 @@ jobs: git diff --name-only "$base"...HEAD > .changed-files git diff --unified=0 "$base"...HEAD -- README.md > .readme.diff || true + - name: Checkout trusted base checks + if: github.event_name == 'pull_request' + uses: actions/checkout@v4 + with: + ref: ${{ github.event.pull_request.base.sha }} + path: .trusted-base + fetch-depth: 1 + + - name: Run trusted repo hygiene checks + if: github.event_name == 'pull_request' + run: node .trusted-base/scripts/check-repo-hygiene.mjs --root "$GITHUB_WORKSPACE" --changed-files .changed-files --diff-file .readme.diff + - name: Run repo hygiene checks + if: github.event_name != 'pull_request' run: node scripts/check-repo-hygiene.mjs --changed-files .changed-files --diff-file .readme.diff diff --git a/rules-new/automl-hyperparameter-optimization.mdc b/rules-new/automl-hyperparameter-optimization.mdc new file mode 100644 index 00000000..a663a30d --- /dev/null +++ b/rules-new/automl-hyperparameter-optimization.mdc @@ -0,0 +1,55 @@ +--- +description: AutoML and hyperparameter optimization rules for Python ML projects using Ray Tune, Optuna, PyCaret, and time-series AutoML libraries +globs: ["**/*.py", "**/*.ipynb", "pyproject.toml", "requirements*.txt", "environment*.yml"] +alwaysApply: false +--- + +# AutoML and Hyperparameter Optimization Rules + +## Scope + +- Use AutoML to accelerate model exploration, not to bypass problem framing, validation design, or explainability. +- Start with a simple baseline model and fixed metric before launching a search. +- Keep training, evaluation, feature generation, and search configuration separate. +- Record datasets, splits, metric definitions, random seeds, library versions, and search spaces for every run. + +## Experiment Design + +- Define the target metric before selecting tooling. +- Use nested validation or a final untouched test split for model selection claims. +- Use time-aware splits for time-series problems; never shuffle across time boundaries. +- Prevent leakage by fitting preprocessing only on training folds. +- Include simple baselines such as linear models, random forests, or naive time-series forecasts. +- Use early stopping and resource limits for expensive searches. +- Prefer structured search spaces with domain-informed ranges over arbitrary broad grids. + +## Tooling + +- Use Ray Tune or Optuna for custom training loops, distributed trials, pruning, and scheduler control. +- Use PyCaret for quick low-code comparisons when the dataset and metric are straightforward. +- Use AutoTS, Merlion, PyAF, or project-approved time-series tooling when forecast-specific validation, seasonality, and horizon handling matter. +- Store run metadata in MLflow, Weights & Biases, TensorBoard, or a project-approved tracker. +- Use `uv` or the existing project package manager for reproducible environments. + +## Search Spaces + +- Keep search spaces explicit and reviewed. +- Use log-scale sampling for learning rates, regularization, tree counts, and other scale-sensitive values. +- Constrain model complexity to avoid unrealistic training time or memory use. +- Include preprocessing choices only when they can be applied without leakage. +- Do not tune on the test set. + +## Reporting + +- Report the selected model, metric, confidence interval or variance, validation scheme, and final test result. +- Include the best parameters and the search budget. +- Compare the chosen model against the baseline and at least one non-AutoML alternative. +- Document operational constraints such as inference latency, memory use, retraining cost, and explainability. + +## Common Mistakes + +- Do not treat leaderboard rank as proof of production readiness. +- Do not mix train/test data during feature engineering. +- Do not run massive searches before validating labels and data quality. +- Do not ignore class imbalance, calibration, or business cost asymmetry. +- Do not deploy an AutoML model without reproducible training code and pinned dependencies. diff --git a/rules-new/beefreeSDK.mdc b/rules-new/beefreeSDK.mdc index 1891f591..3715824b 100644 --- a/rules-new/beefreeSDK.mdc +++ b/rules-new/beefreeSDK.mdc @@ -1,6 +1,7 @@ --- description: Guidelines and best practices for building applications with [Beefree SDK](https://docs.beefree.io/beefree-sdk), including installation, authentication, configuration, customization, and template management globs: **/*.{ts,tsx,js,jsx,html,css} +alwaysApply: false --- # Beefree SDK Guidelines @@ -557,4 +558,4 @@ Reference the complete project at Beefree SDK [multiple-versions-concept](https: -``` \ No newline at end of file +``` diff --git a/rules-new/blender-python-addon.mdc b/rules-new/blender-python-addon.mdc new file mode 100644 index 00000000..6ad76fcd --- /dev/null +++ b/rules-new/blender-python-addon.mdc @@ -0,0 +1,52 @@ +--- +description: Blender Python add-on rules for operators, panels, properties, registration, testing, and API-safe scripting +globs: ["**/*.py", "blender_manifest.toml", "__init__.py"] +alwaysApply: false +--- + +# Blender Python Add-on Rules + +## Add-on Structure + +- Keep add-on entry points in `__init__.py` with clear `register()` and `unregister()` functions. +- Group operators, panels, properties, preferences, and utilities into separate modules for non-trivial add-ons. +- Use `bl_info` or `blender_manifest.toml` according to the Blender version and packaging target. +- Keep UI labels concise and user-facing text translatable where appropriate. + +## API Usage + +- Use `bpy.types.Operator` for actions, `bpy.types.Panel` for UI, and `bpy.types.PropertyGroup` for grouped settings. +- Define `bl_idname`, `bl_label`, and `bl_options` explicitly. +- Validate context in `poll()` before enabling operators. +- Use `invoke()` for interactive setup and `execute()` for the actual operation. +- Return `{'FINISHED'}` or `{'CANCELLED'}` consistently. +- Use dependency graph updates and evaluated objects when reading final scene state. + +## Data and Properties + +- Register custom properties through `PropertyGroup` classes instead of loose global state. +- Store add-on preferences in `AddonPreferences`. +- Use `PointerProperty`, `CollectionProperty`, and typed properties with names and descriptions. +- Clean up custom properties and handlers during `unregister()`. + +## Safety and Performance + +- Do not run destructive scene operations without explicit user action. +- Avoid blocking UI work in modal operators; use timers or modal state machines for long operations. +- Batch mesh changes and use `bmesh` when editing mesh data programmatically. +- Avoid repeatedly scanning large scenes in draw methods. +- Keep file paths configurable and use Blender path utilities. + +## Testing and Debugging + +- Test scripts in a clean Blender profile and a representative production scene. +- Add smoke tests that import the add-on, register it, run core operators, and unregister cleanly. +- Log actionable messages with `self.report()` for user-facing operator feedback. +- Keep version-specific API differences isolated behind helper functions. + +## Common Mistakes + +- Do not forget to unregister classes, handlers, timers, and keymaps. +- Do not mutate Blender data from panel `draw()` methods. +- Do not assume an active object, selected object, or mode without checking context. +- Do not hardcode absolute asset paths. diff --git a/rules-new/clean-code.mdc b/rules-new/clean-code.mdc index 5ee88e32..52c0c9a3 100644 --- a/rules-new/clean-code.mdc +++ b/rules-new/clean-code.mdc @@ -1,6 +1,7 @@ --- description: Guidelines for writing clean, maintainable, and human-readable code. Apply these rules when writing or reviewing code to ensure consistency and quality. -globs: +globs: ["**/*"] +alwaysApply: false --- # Clean Code Guidelines @@ -52,4 +53,4 @@ globs: ## Version Control - Write clear commit messages - Make small, focused commits -- Use meaningful branch names \ No newline at end of file +- Use meaningful branch names diff --git a/rules-new/codequality.mdc b/rules-new/codequality.mdc index 3f335f39..7d54e8cd 100644 --- a/rules-new/codequality.mdc +++ b/rules-new/codequality.mdc @@ -1,6 +1,7 @@ --- description: Code Quality Guidelines -globs: +globs: ["**/*"] +alwaysApply: false --- # Code Quality Guidelines @@ -44,4 +45,4 @@ Don't suggest updates or changes to files when there are no actual modifications Always provide links to the real files, not x.md. ## No Current Implementation -Don't show or discuss the current implementation unless specifically requested. \ No newline at end of file +Don't show or discuss the current implementation unless specifically requested. diff --git a/rules-new/database.mdc b/rules-new/database.mdc index d5befc86..583e285f 100644 --- a/rules-new/database.mdc +++ b/rules-new/database.mdc @@ -1,6 +1,7 @@ --- description: Database best practices focusing on Prisma and Supabase integration globs: prisma/**/*, src/db/**/*, **/*.prisma, supabase/**/* +alwaysApply: false --- # Database Best Practices @@ -83,4 +84,4 @@ globs: prisma/**/*, src/db/**/*, **/*.prisma, supabase/**/* - Implement proper versioning - Handle errors properly - Document schema properly -- Monitor database health \ No newline at end of file +- Monitor database health diff --git a/rules-new/embedded-stm32-hal.mdc b/rules-new/embedded-stm32-hal.mdc new file mode 100644 index 00000000..c67127bd --- /dev/null +++ b/rules-new/embedded-stm32-hal.mdc @@ -0,0 +1,55 @@ +--- +description: Embedded C/C++ rules for MCU, STM32, HAL, interrupts, DMA, memory constraints, and hardware-focused testing +globs: ["**/*.c", "**/*.h", "**/*.cpp", "**/*.hpp", "**/*.ioc", "CMakeLists.txt", "Makefile", "platformio.ini"] +alwaysApply: false +--- + +# Embedded MCU, STM32, and HAL Rules + +## Project Structure + +- Keep board support, drivers, middleware, application logic, and tests separate. +- Isolate generated CubeMX or vendor code from hand-written application code. +- Put hardware abstraction behind narrow interfaces so logic can be tested without hardware. +- Document clock tree, pin mappings, peripheral ownership, and interrupt priorities. + +## STM32 HAL and Peripherals + +- Initialize peripherals in one place and avoid hidden reconfiguration. +- Check return values from HAL calls and handle timeout/error cases. +- Keep blocking HAL calls out of time-critical paths. +- Use DMA for high-throughput UART, SPI, I2C, ADC, or timer capture paths when appropriate. +- Document buffer ownership and lifetime for DMA operations. +- Use `volatile` only for memory shared with ISRs or hardware registers. + +## Interrupts and Concurrency + +- Keep ISRs short and deterministic. +- Defer heavy work from interrupts to the main loop, RTOS task, or event queue. +- Protect shared data with critical sections, atomics, queues, or RTOS primitives. +- Avoid dynamic allocation in interrupts. +- Make interrupt priority decisions explicit. + +## Memory and Timing + +- Avoid heap allocation in firmware unless the project explicitly allows it. +- Check stack usage for ISRs and RTOS tasks. +- Keep lookup tables `const` so they can live in flash. +- Use fixed-width integer types for hardware-facing code. +- Add timeouts for hardware waits. +- Treat watchdog configuration as part of application design, not a late add-on. + +## Testing and Debugging + +- Unit test pure logic on host builds. +- Use hardware-in-the-loop tests for peripheral behavior. +- Add assertions for impossible hardware states in debug builds. +- Use SWD/JTAG, logic analyzers, and serial logs with rate limits. +- Keep fault handlers useful: capture reset reason, fault registers, and build version when possible. + +## Common Mistakes + +- Do not modify generated files unless the workflow preserves changes. +- Do not busy-wait forever on hardware flags. +- Do not share buffers between DMA and CPU without synchronization. +- Do not assume peripheral reset state after low-power modes. diff --git a/rules-new/fastapi.mdc b/rules-new/fastapi.mdc index 24207d0a..d5e93945 100644 --- a/rules-new/fastapi.mdc +++ b/rules-new/fastapi.mdc @@ -1,6 +1,7 @@ --- description: FastAPI best practices and patterns for building modern Python web APIs globs: **/*.py, app/**/*.py, api/**/*.py +alwaysApply: false --- # FastAPI Best Practices @@ -83,4 +84,4 @@ globs: **/*.py, app/**/*.py, api/**/*.py - Use proper type hints - Keep documentation updated - Document error scenarios -- Use proper versioning \ No newline at end of file +- Use proper versioning diff --git a/rules-new/fortran.mdc b/rules-new/fortran.mdc new file mode 100644 index 00000000..62a18e32 --- /dev/null +++ b/rules-new/fortran.mdc @@ -0,0 +1,66 @@ +--- +description: Modern Fortran rules for scientific computing, modules, explicit interfaces, kind parameters, memory safety, and testing +globs: ["**/*.f", "**/*.f90", "**/*.f95", "**/*.f03", "**/*.f08", "**/*.for", "**/*.ftn", "CMakeLists.txt", "*.cmake", "Makefile"] +alwaysApply: false +--- + +# Fortran Programming Guidelines + +## Basic Principles + +- Use modern Fortran standards such as Fortran 2003, 2008, or newer. +- Use `implicit none` in every program unit. +- Put procedures in modules to provide explicit interfaces. +- Keep modules focused and place each major module in its own file. +- Prefer clear, structured code over clever language tricks. +- Avoid obsolete features such as COMMON blocks, GOTO-heavy control flow, and numeric labels. + +## Kinds and Types + +- Define numeric kind parameters in one shared module, such as `kind_mod`. +- Use `real(kind=dp)` or the project-approved real kind for floating point values. +- Use `integer(kind=i4)` or the project-approved integer kind for integer values. +- Define constants such as pi explicitly. +- Include units in comments for physical quantities. +- Use derived types to group related data instead of passing many primitive arguments. + +## Naming and Style + +- Use lowercase for language keywords and most identifiers. +- Use underscores for multi-word names. +- Avoid names that differ only by case. +- Use descriptive names for procedures and state. +- Repeat the procedure or module name after `end` statements. +- Keep indentation consistent in `do`, `if`, `select case`, and module blocks. + +## Procedures + +- Keep subroutines and functions short and single-purpose. +- Use `intent(in)`, `intent(out)`, or `intent(inout)` for every dummy argument. +- Keep functions free of side effects whenever possible. +- Prefer early validation and clear returns over deep nesting. +- Use `use, only:` when importing from modules. + +## Memory and Arrays + +- Prefer allocatable arrays over pointers unless pointer semantics are required. +- Check allocation state and array sizes before use. +- Deallocate allocatable arrays when their lifetime is not naturally scoped. +- Specify array bounds clearly when they matter. +- Avoid unnecessary dynamic allocation in hot loops. + +## Testing and Build + +- Use CMake, fpm, Make, or the project-standard build system consistently. +- Compile with warnings enabled and treat important warnings as failures in CI. +- Add unit tests for public procedures and integration tests for numerical workflows. +- Test boundary conditions, invalid inputs, and representative scientific cases. +- Verify numerical tolerances explicitly rather than relying on exact floating point equality. + +## Common Mistakes + +- Do not declare variables after executable code unless using a block construct. +- Do not assume `random_number` is a function; it is a subroutine. +- Do not write to stdout from pure procedures. +- Do not declare the same variable twice in the same scope. +- Do not assume pi, dp, or project kinds already exist without importing or defining them. diff --git a/rules-new/gamemaker-gml.mdc b/rules-new/gamemaker-gml.mdc new file mode 100644 index 00000000..d8abbb22 --- /dev/null +++ b/rules-new/gamemaker-gml.mdc @@ -0,0 +1,53 @@ +--- +description: GameMaker Language (GML) rules for scripts, objects, events, rooms, data structures, and performance-minded game code +globs: ["**/*.gml", "**/*.yy", "**/*.yyp"] +alwaysApply: false +--- + +# GameMaker GML Rules + +## Code Organization + +- Keep object event code short and move reusable behavior into scripts or functions. +- Use clear prefixes or naming conventions for scripts, objects, sprites, rooms, and globals. +- Prefer functions over copy-pasted event blocks. +- Keep create-step-draw responsibilities separate. +- Put initialization in Create, simulation in Step, and rendering-only work in Draw. + +## GML Style + +- Use descriptive variable names and avoid one-letter names outside small loops. +- Prefer local variables with `var` or function-scoped declarations over unnecessary instance variables. +- Use constants, enums, and macros for repeated identifiers, layer names, states, and collision groups. +- Guard optional instance references with `instance_exists`. +- Keep global state minimal and document it. + +## Gameplay Architecture + +- Use finite state machines for player, enemy, UI, and game-flow states. +- Keep collision logic explicit and deterministic. +- Separate input collection from action execution. +- Use alarms, timelines, or explicit timers consistently; do not mix patterns without reason. +- Store save data through structured maps/structs and version the save format. + +## Performance + +- Avoid expensive searches such as broad `instance_find` or repeated collision scans in every Step event. +- Cache frequently used asset IDs, layer IDs, and object references when safe. +- Destroy data structures when no longer needed. +- Use object pooling for frequent projectiles, particles, or short-lived effects when allocation becomes costly. +- Profile before optimizing and keep hot-path code simple. + +## Debugging and Testing + +- Add debug overlays for collision boxes, state, velocity, and AI decisions when useful. +- Use assertions or explicit guard clauses for impossible states. +- Test room transitions, pause/resume, save/load, and controller/keyboard input separately. +- Keep reproducible test rooms for complex mechanics. + +## Common Mistakes + +- Do not put game logic in Draw events. +- Do not create data structures without destroying them. +- Do not rely on room editor instance order for critical behavior. +- Do not hardcode magic numeric state IDs. diff --git a/rules-new/gitflow.mdc b/rules-new/gitflow.mdc index d52c71b2..985057e0 100644 --- a/rules-new/gitflow.mdc +++ b/rules-new/gitflow.mdc @@ -1,5 +1,7 @@ --- description: Gitflow Workflow Rules. These rules should be applied when performing git operations. +globs: ["**/*"] +alwaysApply: false --- # Gitflow Workflow Rules @@ -108,4 +110,4 @@ description: Gitflow Workflow Rules. These rules should be applied when performi 5. After merge to main: - Tag release - Merge back to develop - - Delete hotfix branch \ No newline at end of file + - Delete hotfix branch diff --git a/rules-new/google-adk.mdc b/rules-new/google-adk.mdc new file mode 100644 index 00000000..1f81969c --- /dev/null +++ b/rules-new/google-adk.mdc @@ -0,0 +1,52 @@ +--- +description: Google Agent Development Kit rules for agents, tools, sessions, memory, artifacts, evaluation, and deployment +globs: ["**/*.py", "**/*.ts", "**/*.tsx", "**/*.go", "**/*.java", "pyproject.toml", "package.json"] +alwaysApply: false +--- + +# Google ADK Rules + +## Agent Design + +- Keep each agent focused on a clear goal, persona, and tool set. +- Use LLM agents for flexible reasoning and workflow agents for deterministic orchestration. +- Write instructions that define task boundaries, tool-use rules, and escalation behavior. +- Split multi-agent systems by responsibility rather than by implementation convenience. +- Keep model choices configurable. + +## Tools + +- Give tools narrow, typed inputs and outputs. +- Validate tool arguments before performing side effects. +- Keep secrets, credentials, and privileged APIs out of agent prompts. +- Handle tool errors explicitly and return actionable failure messages. +- Be aware of ADK tool limitations; some built-in tools cannot be combined with other tools on the same agent. + +## Sessions, State, and Memory + +- Use session state for current-conversation data. +- Use memory for cross-session recall and retrieval. +- Keep state small and serializable. +- Do not store large files or binary payloads in session state. +- Make state keys stable and documented. + +## Artifacts + +- Use artifacts for generated files, uploaded files, reports, images, audio, and other binary data. +- Configure an artifact service in the runner before relying on artifact operations. +- Version artifact filenames intentionally and avoid overwriting semantically different outputs. +- Store only references or summaries in state when full content belongs in artifacts. + +## Evaluation and Deployment + +- Add tests for tool behavior, agent routing, prompt regressions, and unsafe tool calls. +- Use trace or event logs to debug agent decisions. +- Keep local development, staging, and production configuration separate. +- Add observability for latency, tool failures, token use, and handoff failures. + +## Common Mistakes + +- Do not make one agent responsible for every workflow. +- Do not let tools accept arbitrary shell, SQL, or HTTP input without validation. +- Do not rely on prompt text for access control. +- Do not hide important side effects behind generic tool names. diff --git a/rules-new/harmony-arkts.mdc b/rules-new/harmony-arkts.mdc new file mode 100644 index 00000000..4d8134dc --- /dev/null +++ b/rules-new/harmony-arkts.mdc @@ -0,0 +1,54 @@ +--- +description: HarmonyOS ArkTS rules for components, state, resources, layout, lifecycle, and accessibility +globs: ["**/*.ets", "**/*.ts", "**/*.json5", "AppScope/**/*", "entry/src/main/**/*"] +alwaysApply: false +--- + +# HarmonyOS ArkTS Rules + +## Component Structure + +- Use `@Component` for component definitions and PascalCase for component structs. +- Keep state declarations near the top of the component. +- Group lifecycle hooks before `build()`. +- Place `build()` last and keep it focused on UI composition. +- Extract complex UI into smaller components. + +## State and Data Flow + +- Use `@State` for component-owned state. +- Use `@Prop` for parent-to-child data. +- Use `@Link` only for intentional two-way binding. +- Keep derived values in methods or computed helpers rather than duplicating state. +- Avoid broad global state unless the project has an established app-state pattern. + +## Layout and Styling + +- Use `Column`, `Row`, `Stack`, `List`, and other ArkUI primitives intentionally. +- Keep layout properties such as width, height, alignment, and layout weight grouped before visual properties. +- Use object notation for margin and padding when sides differ. +- Use logical pixels consistently. +- Use percentage strings for relative sizes. +- Keep reusable spacing, colors, and typography in resources when the project supports it. + +## Events and Lifecycle + +- Use arrow functions for event handlers. +- Keep event handlers short and delegate complex logic to methods. +- Handle async failures explicitly and surface user-facing errors where appropriate. +- Use lifecycle hooks for setup and teardown that genuinely depends on component lifecycle. + +## Resources and Accessibility + +- Use `$r()` for app resources. +- Group resource references consistently. +- Add descriptive labels and focus handling for interactive elements. +- Maintain color contrast and touch target size. +- Test on representative device sizes and orientations. + +## Common Mistakes + +- Do not bury business logic in `build()`. +- Do not use two-way binding when one-way props are enough. +- Do not hardcode repeated strings, colors, and dimensions that belong in resources. +- Do not leave debug `console.log` calls in production code. diff --git a/rules-new/kubestellar-console.mdc b/rules-new/kubestellar-console.mdc index baeb6b3d..b21cfbe9 100644 --- a/rules-new/kubestellar-console.mdc +++ b/rules-new/kubestellar-console.mdc @@ -1,6 +1,7 @@ --- description: KubeStellar Console — Multi-cluster Kubernetes dashboard development rules globs: **/*.tsx, **/*.ts, **/*.go, web/src/**/*.ts, web/src/**/*.tsx, pkg/**/*.go, cmd/**/*.go +alwaysApply: false --- # KubeStellar Console Development Rules diff --git a/rules-new/medusa.mdc b/rules-new/medusa.mdc index 54167489..28b4e375 100644 --- a/rules-new/medusa.mdc +++ b/rules-new/medusa.mdc @@ -1,6 +1,7 @@ --- description: Medusa rules and best practices. These rules should be used when building applications with Medusa. globs: **/*.tsx, **/*.ts, src/**/*.ts, src/**/*.tsx, src/**/*.js, src/**/*.jsx +alwaysApply: false --- You are an expert senior software engineer specializing in modern web development, with deep expertise in TypeScript, Medusa, React.js, and TailwindCSS. @@ -45,4 +46,4 @@ You are an expert senior software engineer specializing in modern web developmen # Additional Resources -- [Medusa Documentation](https://docs.medusajs.com/llms-full.txt) \ No newline at end of file +- [Medusa Documentation](https://docs.medusajs.com/llms-full.txt) diff --git a/rules-new/nativescript.mdc b/rules-new/nativescript.mdc index 1799cf85..20897380 100644 --- a/rules-new/nativescript.mdc +++ b/rules-new/nativescript.mdc @@ -1,6 +1,7 @@ --- description: NativeScript best practices and patterns for mobile applications globs: **/*.tsx, **/*.ts, **/*.vue, **/*.svelte, src/**/*.ts, app/**/*.ts, src/**/*.tsx, app/**/*.tsx, src/**/*.vue, app/**/*.vue, src/**/*.svelte +alwaysApply: false --- # NativeScript Best Practices diff --git a/rules-new/nextjs.mdc b/rules-new/nextjs.mdc index ae7f4e04..db50abcd 100644 --- a/rules-new/nextjs.mdc +++ b/rules-new/nextjs.mdc @@ -1,6 +1,7 @@ --- description: Next.js with TypeScript and Tailwind UI best practices globs: **/*.tsx, **/*.ts, src/**/*.ts, src/**/*.tsx +alwaysApply: false --- # Next.js Best Practices @@ -49,4 +50,4 @@ globs: **/*.tsx, **/*.ts, src/**/*.ts, src/**/*.tsx - Minimize client-side state - Use React Context sparingly - Prefer server state when possible -- Implement proper loading states \ No newline at end of file +- Implement proper loading states diff --git a/rules-new/node-express.mdc b/rules-new/node-express.mdc index bba551b7..00f8fbbe 100644 --- a/rules-new/node-express.mdc +++ b/rules-new/node-express.mdc @@ -1,6 +1,7 @@ --- description: Node.js and Express.js best practices for backend development globs: **/*.js, **/*.ts, src/**/*.ts +alwaysApply: false --- # Node.js and Express.js Best Practices @@ -83,4 +84,4 @@ globs: **/*.js, **/*.ts, src/**/*.ts - Implement proper error handling - Use proper logging - Handle process signals properly -- Document code properly \ No newline at end of file +- Document code properly diff --git a/rules-new/python.mdc b/rules-new/python.mdc index dc4c6e45..f29c75a9 100644 --- a/rules-new/python.mdc +++ b/rules-new/python.mdc @@ -1,6 +1,7 @@ --- description: Python best practices and patterns for modern software development with Flask and SQLite globs: **/*.py, src/**/*.py, tests/**/*.py +alwaysApply: false --- # Python Best Practices @@ -117,4 +118,4 @@ globs: **/*.py, src/**/*.py, tests/**/*.py - Separate dev dependencies - Use proper package versions - Regularly update dependencies -- Check for security vulnerabilities \ No newline at end of file +- Check for security vulnerabilities diff --git a/rules-new/react-router-v7.mdc b/rules-new/react-router-v7.mdc new file mode 100644 index 00000000..d6cbce44 --- /dev/null +++ b/rules-new/react-router-v7.mdc @@ -0,0 +1,52 @@ +--- +description: React Router v7 rules for framework mode, data routers, loaders, actions, route modules, and progressive enhancement +globs: ["app/routes/**/*", "src/routes/**/*", "routes/**/*", "react-router.config.*", "vite.config.*", "**/*.tsx", "**/*.ts"] +alwaysApply: false +--- + +# React Router v7 Rules + +## Route Modules + +- Use route modules as the boundary for route UI, loader data, actions, metadata, and error boundaries. +- Keep route modules small; move shared UI to components and reusable data access to services. +- Prefer file-based routing in framework mode when the project is configured for it. +- Use nested routes for shared layouts and progressive disclosure. +- Export route-specific `ErrorBoundary` components for recoverable route failures. + +## Data Loading + +- Use loaders for route data that should be available before render. +- Keep loaders deterministic and side-effect free. +- Validate params and search params at the loader boundary. +- Return typed data and consume it through route hooks rather than duplicating fetch logic in components. +- Use deferred or streaming patterns only when they improve perceived performance. + +## Mutations + +- Use actions for route mutations and form submissions. +- Prefer `Form`, `useFetcher`, and `useSubmit` for progressive enhancement. +- Revalidate affected loader data after mutations. +- Handle validation errors as typed action data instead of generic exceptions. +- Keep server-only secrets and privileged operations out of client actions. + +## Navigation and State + +- Store shareable state in URL params or search params. +- Keep ephemeral UI state local to components. +- Use pending navigation state to show optimistic or loading UI. +- Avoid global state for data that belongs to route loaders. + +## TypeScript and Testing + +- Type loader and action return values. +- Add tests for route loaders, actions, validation failures, and error boundaries. +- Use integration tests for critical form and navigation flows. +- Mock network and persistence at the route-service boundary. + +## Common Mistakes + +- Do not duplicate loader fetches in `useEffect`. +- Do not mutate data in loaders. +- Do not hide route errors behind a single generic app-level catch-all. +- Do not put auth checks only in components when loader data is protected. diff --git a/rules-new/react.mdc b/rules-new/react.mdc index aabc9b7e..81b57106 100644 --- a/rules-new/react.mdc +++ b/rules-new/react.mdc @@ -1,6 +1,7 @@ --- description: React best practices and patterns for modern web applications globs: **/*.tsx, **/*.jsx, components/**/* +alwaysApply: false --- # React Best Practices @@ -75,4 +76,4 @@ globs: **/*.tsx, **/*.jsx, components/**/* - Implement proper directory structure - Keep styles close to components - Use proper imports/exports -- Document complex component logic \ No newline at end of file +- Document complex component logic diff --git a/rules-new/ros-ros2.mdc b/rules-new/ros-ros2.mdc new file mode 100644 index 00000000..846508c6 --- /dev/null +++ b/rules-new/ros-ros2.mdc @@ -0,0 +1,44 @@ +--- +description: ROS and ROS2 rules for packages, nodes, launch files, messages, services, actions, simulation, and testing +globs: ["**/*.py", "**/*.cpp", "**/*.hpp", "**/*.h", "package.xml", "CMakeLists.txt", "**/*.launch.py", "**/*.msg", "**/*.srv", "**/*.action", "**/*.urdf", "**/*.xacro"] +alwaysApply: false +--- + +# ROS and ROS2 Rules + +## Package Structure + +- Keep packages focused on one robot capability or integration boundary. +- Use `package.xml` and `CMakeLists.txt` or `setup.py` consistently with the package type. +- Keep launch files under `launch/`, configs under `config/`, messages under `msg/`, services under `srv/`, and actions under `action/`. +- Use namespaces and remapping instead of hardcoded topic names when nodes may be reused. + +## Nodes and Interfaces + +- Keep nodes small and composable. +- Use parameters for tunable behavior; declare ROS2 parameters explicitly. +- Prefer messages for state streams, services for quick request/response operations, and actions for long-running goals with feedback. +- Use standard message types before creating custom interfaces. +- Document topic, service, action, frame, and parameter contracts. + +## Timing and Frames + +- Use ROS time when simulation or bag replay matters. +- Use `tf2` for frame transforms and document frame names. +- Avoid blocking callbacks; move long work to timers, worker threads, or actions. +- Set QoS profiles intentionally for sensor data, latched-like config, and reliable command paths. + +## Build and Test + +- Use `colcon build` and keep package dependencies explicit. +- Run linters and formatters used by the workspace. +- Add launch tests or integration tests for multi-node behavior. +- Use simulation, bags, or recorded fixtures for repeatable sensor scenarios. +- Test failure cases such as missing transforms, stale sensor data, and unavailable services. + +## Common Mistakes + +- Do not hardcode absolute paths; use package share directories. +- Do not publish commands without validating frame, units, and timestamp assumptions. +- Do not create custom messages when a standard message fits. +- Do not ignore QoS mismatches between publishers and subscribers. diff --git a/rules-new/rust-general.mdc b/rules-new/rust-general.mdc new file mode 100644 index 00000000..618230db --- /dev/null +++ b/rules-new/rust-general.mdc @@ -0,0 +1,52 @@ +--- +description: General Rust rules for safe, idiomatic application and library development +globs: ["**/*.rs", "Cargo.toml", "Cargo.lock"] +alwaysApply: false +--- + +# Rust General Rules + +## Project Structure + +- Keep crates focused and name modules by domain responsibility. +- Put reusable library code in `src/lib.rs` and binary entry points in `src/main.rs` or `src/bin/`. +- Keep public APIs small and documented. +- Use feature flags deliberately and document non-default features. +- Commit `Cargo.lock` for applications; follow the project convention for libraries. + +## Ownership and Types + +- Prefer borrowing over cloning when ownership is not needed. +- Use owned values at API boundaries when the callee must store data. +- Model domain states with enums and structs instead of strings or booleans. +- Use `Option` for absence and `Result` for fallible operations. +- Avoid `unwrap()` and `expect()` outside tests, examples, and process-startup invariants. + +## Error Handling + +- Use `thiserror` or project-standard custom errors for libraries. +- Use `anyhow` or project-standard context-rich errors for applications. +- Add context when crossing IO, network, database, or parsing boundaries. +- Do not discard errors with `_` unless explicitly documented. + +## Concurrency and Async + +- Use `Send` and `Sync` boundaries intentionally. +- Prefer message passing or owned task inputs for async work. +- Do not hold blocking locks across `.await`. +- Use `tokio::task::spawn_blocking` or equivalent for blocking CPU or IO in async applications. +- Propagate cancellation through futures rather than hiding it in detached tasks. + +## Testing and Quality + +- Run `cargo fmt` and `cargo clippy` before delivery. +- Add unit tests for pure logic and integration tests for public behavior. +- Use property tests for parsers, serializers, and state machines when useful. +- Use benchmarks only after identifying a real performance question. + +## Common Mistakes + +- Do not fight the borrow checker by adding unnecessary `Arc>`. +- Do not expose internal module structure through public APIs by accident. +- Do not allocate in hot loops without measuring. +- Do not use unsafe code unless the invariant is documented and tested. diff --git a/rules-new/rust.mdc b/rules-new/rust.mdc index c1dfa673..4038e6ab 100644 --- a/rules-new/rust.mdc +++ b/rules-new/rust.mdc @@ -1,6 +1,7 @@ --- description: Rust best practices for Solana smart contract development using Anchor framework and Solana SDK globs: programs/**/*.rs, src/**/*.rs, tests/**/*.ts +alwaysApply: false --- # Rust + Solana (Anchor) Best Practices diff --git a/rules-new/svelte.mdc b/rules-new/svelte.mdc index 2d55e9d1..2c2711db 100644 --- a/rules-new/svelte.mdc +++ b/rules-new/svelte.mdc @@ -1,6 +1,7 @@ --- description: Svelte best practices and patterns for modern web applications globs: **/*.svelte, src/**/*.ts, src/**/*.js +alwaysApply: false --- # Svelte Best Practices @@ -83,4 +84,4 @@ globs: **/*.svelte, src/**/*.ts, src/**/*.js - Use proper environment variables - Implement proper code splitting - Use proper asset handling -- Configure proper optimization \ No newline at end of file +- Configure proper optimization diff --git a/rules-new/tailwind.mdc b/rules-new/tailwind.mdc index b9db61d6..af5f3d61 100644 --- a/rules-new/tailwind.mdc +++ b/rules-new/tailwind.mdc @@ -1,6 +1,7 @@ --- description: Tailwind CSS and UI component best practices for modern web applications globs: **/*.css, **/*.tsx, **/*.jsx, tailwind.config.js, tailwind.config.ts +alwaysApply: false --- # Tailwind CSS Best Practices @@ -75,4 +76,4 @@ globs: **/*.css, **/*.tsx, **/*.jsx, tailwind.config.js, tailwind.config.ts - Use proper documentation - Implement proper testing - Follow accessibility guidelines -- Use proper version control \ No newline at end of file +- Use proper version control diff --git a/rules-new/tensorflow-deep-learning.mdc b/rules-new/tensorflow-deep-learning.mdc new file mode 100644 index 00000000..3939a840 --- /dev/null +++ b/rules-new/tensorflow-deep-learning.mdc @@ -0,0 +1,54 @@ +--- +description: TensorFlow and deep learning rules for building, training, evaluating, and deploying neural network models +globs: ["**/*.py", "**/*.ipynb", "pyproject.toml", "requirements*.txt", "environment*.yml"] +alwaysApply: false +--- + +# TensorFlow and Deep Learning Rules + +## Project Structure + +- Separate data loading, model definition, training, evaluation, and serving code. +- Use `tf.data` pipelines for scalable input processing. +- Keep model hyperparameters in typed config files or dataclasses. +- Store checkpoints, logs, and exported models outside source directories. +- Keep notebooks exploratory; move repeatable training code into modules. + +## Model Development + +- Start with a small baseline model and a tiny overfit test before scaling. +- Use Keras layers and models unless lower-level TensorFlow APIs are required. +- Prefer explicit input shapes and named inputs/outputs. +- Use callbacks for checkpointing, early stopping, learning-rate scheduling, and TensorBoard logging. +- Use mixed precision only after validating numerical stability. +- Pin random seeds where reproducibility matters, while documenting nondeterministic GPU behavior. + +## Training + +- Validate data shapes, dtypes, label ranges, and class balance before training. +- Split data before augmentation or normalization fitting. +- Use validation data for tuning and a separate test set for final reporting. +- Track loss curves, metrics, learning rate, and resource use. +- Save the best checkpoint by validation metric, not by final epoch. + +## Evaluation + +- Report task-appropriate metrics such as AUROC, F1, calibration, perplexity, BLEU/ROUGE, or MAE/RMSE. +- Include confusion matrices or error slices for classification tasks. +- Evaluate on edge cases and distribution shifts when data allows. +- Compare against non-neural baselines when the dataset is small or tabular. + +## Deployment + +- Export models with clear input signatures. +- Keep preprocessing consistent between training and serving. +- Add smoke tests that load the exported model and run inference on sample inputs. +- Monitor latency, memory, prediction drift, and input schema changes. + +## Common Mistakes + +- Do not tune architecture before verifying labels and data quality. +- Do not leak validation data through preprocessing or augmentation. +- Do not rely on accuracy alone for imbalanced data. +- Do not deploy a notebook-only model. +- Do not ignore batch size, dtype, and device differences between training and inference. diff --git a/rules-new/toss-style-design-system.mdc b/rules-new/toss-style-design-system.mdc new file mode 100644 index 00000000..ef8b0151 --- /dev/null +++ b/rules-new/toss-style-design-system.mdc @@ -0,0 +1,67 @@ +--- +description: Toss-style UI design rules for disciplined spacing, typography, grayscale hierarchy, restrained color, cards, metrics, dark mode, and accessibility +globs: ["**/*.tsx", "**/*.jsx", "**/*.vue", "**/*.svelte", "**/*.css", "**/*.scss", "tailwind.config.*"] +alwaysApply: false +--- + +# Toss-Style Design System Rules + +## Design Direction + +- Build quiet, high-trust product UI with clear hierarchy, generous spacing, and minimal ornament. +- Use one primary accent color and rely on grayscale for most structure. +- Avoid decorative gradients, unnecessary shadows, and competing accent colors. +- Prioritize readability, confidence, and fast scanning over visual novelty. + +## Typography + +- Use a strict type scale with clear roles for page title, section title, body, supporting text, and metadata. +- Use font weight and color before using large size changes. +- Never use pure black text; use a dark grayscale foreground. +- Keep line height comfortable for body copy and tighter for short labels or metrics. +- For metrics, make the number visually dominant and the unit smaller but still legible. + +## Layout and Rhythm + +- Use consistent spacing tokens. +- Keep related content close and unrelated content separated by whitespace. +- Use section rhythm: summary, details, action, and supporting context. +- Align form fields, values, and controls predictably. +- Avoid nested cards and excessive borders. + +## Cards and Surfaces + +- Use cards only for grouped content that needs a surface. +- Keep card radius restrained and consistent. +- Use subtle shadows or borders, not both heavily. +- Keep shadow opacity low and avoid dramatic elevation. +- Do not place important controls in low-contrast decorative surfaces. + +## Color + +- Use the accent color for primary actions, selected state, links, or critical brand moments. +- Use semantic colors for status only: success, warning, error, and information. +- Keep disabled and secondary states in grayscale. +- Ensure status is never communicated by color alone. + +## Dark Mode + +- Rebuild the grayscale scale for dark mode rather than inverting colors. +- Reduce bright accent intensity on dark backgrounds. +- Preserve contrast between surface, border, and foreground layers. +- Test charts, cards, and form controls in both modes. + +## Accessibility + +- Meet WCAG AA contrast for text and controls. +- Provide visible focus states. +- Keep tap targets large enough for touch. +- Use semantic HTML and labels before adding ARIA. +- Respect reduced motion preferences. + +## Common Mistakes + +- Do not create one-off spacing values. +- Do not mix multiple unrelated accent colors. +- Do not overuse cards to separate every piece of content. +- Do not rely on large hero typography inside dense product screens. diff --git a/rules-new/typescript.mdc b/rules-new/typescript.mdc index b3919bd9..630bbff1 100644 --- a/rules-new/typescript.mdc +++ b/rules-new/typescript.mdc @@ -1,6 +1,7 @@ --- description: TypeScript coding standards and best practices for modern web development globs: **/*.ts, **/*.tsx, **/*.d.ts +alwaysApply: false --- # TypeScript Best Practices @@ -54,4 +55,4 @@ globs: **/*.ts, **/*.tsx, **/*.d.ts - Implement the Repository pattern for data access - Use the Factory pattern for object creation - Leverage dependency injection -- Use the Module pattern for encapsulation \ No newline at end of file +- Use the Module pattern for encapsulation diff --git a/rules-new/vue.mdc b/rules-new/vue.mdc index 54d45384..c191a254 100644 --- a/rules-new/vue.mdc +++ b/rules-new/vue.mdc @@ -1,6 +1,7 @@ --- description: Vue.js best practices and patterns for modern web applications globs: **/*.vue, **/*.ts, components/**/* +alwaysApply: false --- # Vue.js Best Practices @@ -83,4 +84,4 @@ globs: **/*.vue, **/*.ts, components/**/* - Use proper environment variables - Implement proper code splitting - Use proper asset handling -- Configure proper optimization \ No newline at end of file +- Configure proper optimization diff --git a/rules/rails-cursorrules-prompt-file/.cursorrules b/rules/rails-cursorrules-prompt-file/.cursorrules index e69de29b..9a90a6ae 100644 --- a/rules/rails-cursorrules-prompt-file/.cursorrules +++ b/rules/rails-cursorrules-prompt-file/.cursorrules @@ -0,0 +1,34 @@ +# Rails 8 Cursor Rules + +You are an expert Ruby on Rails 8 developer. Prefer Rails conventions, small controllers, clear models, service objects for complex business logic, and Minitest coverage for behavior that can regress. + +## Core Practices + +- Use `bin/rails generate` for Rails artifacts when possible instead of hand-creating framework boilerplate. +- Keep controllers RESTful, focused on HTTP concerns, and free of complex business logic. +- Use `params.expect()` for safer parameter handling in Rails 8 applications. +- Use service objects for multi-step workflows, external integrations, and operations that do not belong in models or controllers. +- Prefer Hotwire (Turbo and Stimulus) for standard Rails interactivity. +- Use Vite only when npm-managed JavaScript dependencies or advanced bundling needs justify it. +- Use Propshaft for the default asset pipeline when Vite is not needed. +- Use Solid Queue, Solid Cache, and Solid Cable when they fit the application deployment model. + +## Data, Security, and Performance + +- Use PostgreSQL for production-style applications unless the project explicitly chooses another database. +- Add indexes for foreign keys, lookup columns, uniqueness constraints, and frequently filtered columns. +- Keep model validations close to the data they protect and database constraints close to the invariants they enforce. +- Use authorization policies for protected resources and avoid scattering permission checks across views. +- Follow OWASP guidance for authentication, authorization, redirects, file uploads, and user-controlled HTML. +- Avoid N+1 queries with `includes`, `preload`, or explicit query objects. +- Use background jobs for slow external calls, mail delivery, and repeatable asynchronous work. + +## Testing and Operations + +- Write model, request/controller, job, mailer, and integration tests with Minitest. +- Use system tests only for high-value browser flows. +- Keep fixtures readable and close to realistic domain examples. +- Check `log/development.log` after significant changes. +- Use `bin/dev` to run local development when the project includes a `Procfile.dev`. + +For the expanded rule set, see `rails-basics.mdx` in this directory. diff --git a/rules/solidity-react-blockchain-apps-cursorrules-prompt-/.cursorrules b/rules/solidity-react-blockchain-apps-cursorrules-prompt-/.cursorrules index dcf93f57..d97be1a4 100644 --- a/rules/solidity-react-blockchain-apps-cursorrules-prompt-/.cursorrules +++ b/rules/solidity-react-blockchain-apps-cursorrules-prompt-/.cursorrules @@ -1 +1,44 @@ -I'm sorry, but it seems like you haven't provided the content of the corrupted file. Could you please provide the text that needs formatting? +You are an expert in Solidity, EVM smart contract security, React, TypeScript, and Web3 application development. + +## Solidity Contracts + +- Use Solidity 0.8.x or newer unless the project has a pinned compiler version. +- Use explicit visibility for every function and state variable. +- Prefer custom errors over revert strings for gas efficiency and typed failure modes. +- Follow Checks-Effects-Interactions and use `ReentrancyGuard` for external-call flows that move value. +- Prefer pull payments over push payments for user withdrawals. +- Use OpenZeppelin contracts for common standards such as ERC20, ERC721, AccessControl, Ownable, Pausable, SafeERC20, TimelockController, and upgradeable patterns. +- Use upgradeable contracts only when the product requires upgrades; document initializer, storage layout, and admin controls. +- Protect privileged actions with multisig and timelocks in production. +- Emit events for all important state changes that off-chain systems need to index. +- Use NatSpec for public and external functions. +- Avoid unbounded loops over user-controlled or growing storage arrays. +- Avoid on-chain randomness unless it uses a verifiable oracle such as Chainlink VRF. +- Use fixed-point integer math for financial calculations; never use floating point assumptions. + +## Testing and Analysis + +- Write unit, integration, and invariant/property tests for critical paths. +- Test revert cases, access control, pausing, upgrade initialization, and edge balances. +- Run static analysis with Slither or the project-approved equivalent. +- Run gas snapshots for hot paths and storage-heavy changes. +- Use fork tests for protocol integrations and mainnet-token assumptions. + +## React and Web3 Frontend + +- Keep wallet connection state separate from contract read/write logic. +- Use typed ABIs and generated contract clients when available. +- Validate chain ID before reads and writes. +- Show clear pending, success, failure, rejected-signature, and wrong-network states. +- Never ask users to sign opaque data; display the human-readable intent and contract address. +- Use BigInt or library-supported integer types for token amounts. +- Format token units at the UI boundary only; keep internal calculations in base units. +- Refetch or subscribe to contract state after successful writes. +- Guard against stale balances, stale allowances, and race conditions around pending transactions. + +## Security UX + +- Display contract addresses, token symbols, and network names for sensitive operations. +- Warn before approvals, unlimited allowances, admin actions, and irreversible transactions. +- Do not store private keys, seed phrases, or raw signatures in local storage. +- Keep API keys and RPC credentials in environment configuration. diff --git a/rules/svelte-5-vs-svelte-4-cursorrules-prompt-file/.cursorrules b/rules/svelte-5-vs-svelte-4-cursorrules-prompt-file/.cursorrules index 016d94f0..502e7ad1 100644 --- a/rules/svelte-5-vs-svelte-4-cursorrules-prompt-file/.cursorrules +++ b/rules/svelte-5-vs-svelte-4-cursorrules-prompt-file/.cursorrules @@ -1,5 +1,5 @@ I'm using svelte 5 instead of svelte 4 here is an overview of the changes. -# .cursorrunes for Svelte 5 +# .cursorrules for Svelte 5 ## Overview of Changes @@ -28,8 +28,6 @@ In Svelte 5, event handlers are treated as standard HTML properties rather than **After (Svelte 5):** ```html + + + -``` \ No newline at end of file +``` diff --git a/rules/deno-integration-techniques-cursorrules-prompt-fil/.cursorrules b/rules/deno-integration-techniques-cursorrules-prompt-fil/.cursorrules index 5a2f5bea..623bdee9 100644 --- a/rules/deno-integration-techniques-cursorrules-prompt-fil/.cursorrules +++ b/rules/deno-integration-techniques-cursorrules-prompt-fil/.cursorrules @@ -1,6 +1,6 @@ This project contains automation scripts and workflows for the @findhow packages, based on the original Deno automation repository. The goal is to provide consistent and efficient automation for the @findhow ecosystem. -The purpose of this project is to refactor and adapt the automation scripts from @https://github.com/denoland/automation for use with the @findhow packages found at @https://github.com/zhorton34/findhow. +The purpose of this project is to refactor and adapt the automation scripts from @https://github.com/denoland/automation for use with the configured @findhow package repositories. When working on this project, Cursor AI should: @@ -11,4 +11,3 @@ When updating documentation: When creating or modifying automation scripts: Remember to thoroughly test all modifications to ensure they work correctly with the @findhow ecosystem before merging changes into the main branch. - diff --git a/rules/rails-cursorrules-prompt-file/README.md b/rules/rails-cursorrules-prompt-file/README.md index ec98ade3..0ef6b753 100644 --- a/rules/rails-cursorrules-prompt-file/README.md +++ b/rules/rails-cursorrules-prompt-file/README.md @@ -1,3 +1,3 @@ # Rails 8 (Basic Setup) -Provides practical, project-level rules and best practices for developing with Rails 8 using Cursor AI. Inspired by [Mawla/cursor_rules](https://github.com/Mawla/cursor_rules) — see that repository for further examples of Rails 8 Cursor rules. +Provides practical, project-level rules and best practices for developing with Rails 8 using Cursor AI. Inspired by the Mawla cursor_rules project. From 0f20b484ecbbf9ff0ab3dc6a50387d6dbb9137c7 Mon Sep 17 00:00:00 2001 From: PatrickJS Date: Tue, 12 May 2026 22:01:21 -0700 Subject: [PATCH 08/10] Verify Manifest schema and sanitize example image URLs Update manifest prompt rules to recommend using a verified or project-shipped Manifest JSON Schema instead of hardcoding the public schema URL, and tighten wording/copy (e.g. "Strictly"). Update README guidance to advise verifying backend docs and schema for the project version. Replace hardcoded external image URLs in the momen ActionFlow examples with a generic "generated-image-url-from-actionflow" placeholder to avoid leaking or relying on specific static assets. --- rules/manifest-yaml-cursorrules-prompt-file/.cursorrules | 6 +++--- rules/manifest-yaml-cursorrules-prompt-file/README.md | 4 +--- .../momen-actionflow-gql-api-rules.mdc | 4 ++-- 3 files changed, 6 insertions(+), 8 deletions(-) diff --git a/rules/manifest-yaml-cursorrules-prompt-file/.cursorrules b/rules/manifest-yaml-cursorrules-prompt-file/.cursorrules index 3c5a38a5..8a1d8dc5 100644 --- a/rules/manifest-yaml-cursorrules-prompt-file/.cursorrules +++ b/rules/manifest-yaml-cursorrules-prompt-file/.cursorrules @@ -14,11 +14,11 @@ When asked to create a backend, execute the following actions: 2. Add the following scripts to `pacakge.json`: "manifest": "node node_modules/manifest/scripts/watch/watch.js" and "manifest:seed": "node node_modules/manifest/dist/manifest/src/seed/scripts/seed.js" 3. Create the `manifest/backend.yml` file and add the manifest code to it. 4. Add the `redhat.vscode-yaml` as recommendation in `.vscode/extensions.json` -5. Add the following `yaml.schemas`: `"https://schema.manifest.build/schema.json": "**/manifest/**.yml"` in `.vscode/settings.json` +5. Configure `yaml.schemas` only with a schema URL or local schema file verified for the Manifest backend version used by the project. **Backend file** On the `manifest/backend.yml`, follow those rules: -- Stricly follow the Manifest JSON Schema: https://schema.manifest.build/schema.json +- Strictly follow the Manifest JSON Schema shipped with the project or verified from the current Manifest backend documentation. - Start by addind a quick name to the app - Limit to 2 or 3 entities maximum - Limit to 4 properties maximum per entity @@ -40,7 +40,7 @@ On the `manifest/backend.yml`, follow those rules: - Do not add "seedCount" and "mainProp" to entities **Documentation** -Refer to the Manifest documentation: https://manifest.build/docs +Refer to the Manifest backend documentation that matches the project's installed version. **Example** This is an example of the content of a `backend.yml` file: diff --git a/rules/manifest-yaml-cursorrules-prompt-file/README.md b/rules/manifest-yaml-cursorrules-prompt-file/README.md index fc04b12f..d42ca43e 100644 --- a/rules/manifest-yaml-cursorrules-prompt-file/README.md +++ b/rules/manifest-yaml-cursorrules-prompt-file/README.md @@ -47,6 +47,4 @@ This prompt file guides the generation of backends with Manifest. It embeds your ## References -- Manifest Docs: https://manifest.build/docs - -- JSON Schema: https://schema.manifest.build/schema.json +- Verify the current Manifest backend documentation and JSON Schema for the version used by your project before configuring editor schema validation. diff --git a/rules/momen-cursurrules-prompt-file/momen-actionflow-gql-api-rules.mdc b/rules/momen-cursurrules-prompt-file/momen-actionflow-gql-api-rules.mdc index 441026a7..baa5c00b 100644 --- a/rules/momen-cursurrules-prompt-file/momen-actionflow-gql-api-rules.mdc +++ b/rules/momen-cursurrules-prompt-file/momen-actionflow-gql-api-rules.mdc @@ -39,7 +39,7 @@ Response: "fz_invoke_action_flow": { "img": { "id": 1020000000000090, - "url": "https://fz-zion-static.functorz.com/202510252359/a64a7eb4793728a1977d3ea9e7b7e4e8/project/2000000000521152/import/1110000000000001/image/636.jpg" + "url": "generated-image-url-from-actionflow" }, "url": "https://momen.app" } @@ -95,7 +95,7 @@ Subscription response: "output": { "img": { "id": 1020000000000089, - "url": "https://fz-zion-static.functorz.com/202510262359/3a5f04371bf68d6c94bb890879101f0a/project/2000000000521152/import/1110000000000001/image/637.jpg" + "url": "generated-image-url-from-actionflow" }, "xyz": { "type": "Point", From a383973e7af2642874ad70ad70a767a2902bca49 Mon Sep 17 00:00:00 2001 From: PatrickJS Date: Tue, 12 May 2026 22:10:38 -0700 Subject: [PATCH 09/10] Address PR review comments --- rules-new/beefreeSDK.mdc | 2 +- rules-new/react.mdc | 2 +- .../.cursorrules | 2 +- .../.cursorrules | 2 +- scripts/workflow-security.test.mjs | 1 + 5 files changed, 5 insertions(+), 4 deletions(-) diff --git a/rules-new/beefreeSDK.mdc b/rules-new/beefreeSDK.mdc index d518e651..ae6e8b29 100644 --- a/rules-new/beefreeSDK.mdc +++ b/rules-new/beefreeSDK.mdc @@ -552,4 +552,4 @@ Reference the complete project at Beefree SDK [multiple-versions-concept](https: -``` +``` diff --git a/rules-new/react.mdc b/rules-new/react.mdc index 81b57106..6cba00db 100644 --- a/rules-new/react.mdc +++ b/rules-new/react.mdc @@ -76,4 +76,4 @@ alwaysApply: false - Implement proper directory structure - Keep styles close to components - Use proper imports/exports -- Document complex component logic +- Document complex component logic diff --git a/rules/beefreeSDK-nocode-content-editor-cursorrules-prompt-file/.cursorrules b/rules/beefreeSDK-nocode-content-editor-cursorrules-prompt-file/.cursorrules index 4f2f9c99..68609541 100644 --- a/rules/beefreeSDK-nocode-content-editor-cursorrules-prompt-file/.cursorrules +++ b/rules/beefreeSDK-nocode-content-editor-cursorrules-prompt-file/.cursorrules @@ -547,4 +547,4 @@ Reference the complete project at Beefree SDK [multiple-versions-concept](https: -``` +``` diff --git a/rules/deno-integration-techniques-cursorrules-prompt-fil/.cursorrules b/rules/deno-integration-techniques-cursorrules-prompt-fil/.cursorrules index 623bdee9..c372bff5 100644 --- a/rules/deno-integration-techniques-cursorrules-prompt-fil/.cursorrules +++ b/rules/deno-integration-techniques-cursorrules-prompt-fil/.cursorrules @@ -1,6 +1,6 @@ This project contains automation scripts and workflows for the @findhow packages, based on the original Deno automation repository. The goal is to provide consistent and efficient automation for the @findhow ecosystem. -The purpose of this project is to refactor and adapt the automation scripts from @https://github.com/denoland/automation for use with the configured @findhow package repositories. +The purpose of this project is to refactor and adapt the automation scripts from [denoland/automation](https://github.com/denoland/automation) for use with the configured @findhow package repositories. When working on this project, Cursor AI should: diff --git a/scripts/workflow-security.test.mjs b/scripts/workflow-security.test.mjs index fd87e354..ded23026 100644 --- a/scripts/workflow-security.test.mjs +++ b/scripts/workflow-security.test.mjs @@ -7,6 +7,7 @@ const codeowners = readFileSync(new URL("../.github/CODEOWNERS", import.meta.url test("repo hygiene workflow grants read-only contents permission", () => { assert.match(workflow, /^permissions:\n\s+contents:\s+read\s*$/m); + assert.doesNotMatch(workflow, /contents:\s*write/); }); test("pull request hygiene runs the trusted base copy of the script", () => { From 0393194cce46936067a2c9b323b34a4587af7da7 Mon Sep 17 00:00:00 2001 From: PatrickJS Date: Tue, 12 May 2026 22:12:16 -0700 Subject: [PATCH 10/10] Clean remaining PR whitespace --- rules-new/clean-code.mdc | 2 +- rules-new/database.mdc | 2 +- rules-new/fastapi.mdc | 2 +- rules-new/gitflow.mdc | 2 +- rules-new/nextjs.mdc | 2 +- rules-new/node-express.mdc | 2 +- rules-new/svelte.mdc | 2 +- rules-new/tailwind.mdc | 2 +- rules-new/typescript.mdc | 2 +- rules-new/vue.mdc | 2 +- 10 files changed, 10 insertions(+), 10 deletions(-) diff --git a/rules-new/clean-code.mdc b/rules-new/clean-code.mdc index 52c0c9a3..ec44ee3b 100644 --- a/rules-new/clean-code.mdc +++ b/rules-new/clean-code.mdc @@ -53,4 +53,4 @@ alwaysApply: false ## Version Control - Write clear commit messages - Make small, focused commits -- Use meaningful branch names +- Use meaningful branch names diff --git a/rules-new/database.mdc b/rules-new/database.mdc index 583e285f..ab36aeca 100644 --- a/rules-new/database.mdc +++ b/rules-new/database.mdc @@ -84,4 +84,4 @@ alwaysApply: false - Implement proper versioning - Handle errors properly - Document schema properly -- Monitor database health +- Monitor database health diff --git a/rules-new/fastapi.mdc b/rules-new/fastapi.mdc index d5e93945..f85697cb 100644 --- a/rules-new/fastapi.mdc +++ b/rules-new/fastapi.mdc @@ -84,4 +84,4 @@ alwaysApply: false - Use proper type hints - Keep documentation updated - Document error scenarios -- Use proper versioning +- Use proper versioning diff --git a/rules-new/gitflow.mdc b/rules-new/gitflow.mdc index 985057e0..2f2025eb 100644 --- a/rules-new/gitflow.mdc +++ b/rules-new/gitflow.mdc @@ -110,4 +110,4 @@ alwaysApply: false 5. After merge to main: - Tag release - Merge back to develop - - Delete hotfix branch + - Delete hotfix branch diff --git a/rules-new/nextjs.mdc b/rules-new/nextjs.mdc index db50abcd..ef216078 100644 --- a/rules-new/nextjs.mdc +++ b/rules-new/nextjs.mdc @@ -50,4 +50,4 @@ alwaysApply: false - Minimize client-side state - Use React Context sparingly - Prefer server state when possible -- Implement proper loading states +- Implement proper loading states diff --git a/rules-new/node-express.mdc b/rules-new/node-express.mdc index 00f8fbbe..d6f52fa4 100644 --- a/rules-new/node-express.mdc +++ b/rules-new/node-express.mdc @@ -84,4 +84,4 @@ alwaysApply: false - Implement proper error handling - Use proper logging - Handle process signals properly -- Document code properly +- Document code properly diff --git a/rules-new/svelte.mdc b/rules-new/svelte.mdc index 2c2711db..f300507a 100644 --- a/rules-new/svelte.mdc +++ b/rules-new/svelte.mdc @@ -84,4 +84,4 @@ alwaysApply: false - Use proper environment variables - Implement proper code splitting - Use proper asset handling -- Configure proper optimization +- Configure proper optimization diff --git a/rules-new/tailwind.mdc b/rules-new/tailwind.mdc index af5f3d61..148eca40 100644 --- a/rules-new/tailwind.mdc +++ b/rules-new/tailwind.mdc @@ -76,4 +76,4 @@ alwaysApply: false - Use proper documentation - Implement proper testing - Follow accessibility guidelines -- Use proper version control +- Use proper version control diff --git a/rules-new/typescript.mdc b/rules-new/typescript.mdc index 630bbff1..1b48765c 100644 --- a/rules-new/typescript.mdc +++ b/rules-new/typescript.mdc @@ -55,4 +55,4 @@ alwaysApply: false - Implement the Repository pattern for data access - Use the Factory pattern for object creation - Leverage dependency injection -- Use the Module pattern for encapsulation +- Use the Module pattern for encapsulation diff --git a/rules-new/vue.mdc b/rules-new/vue.mdc index c191a254..09915dd8 100644 --- a/rules-new/vue.mdc +++ b/rules-new/vue.mdc @@ -84,4 +84,4 @@ alwaysApply: false - Use proper environment variables - Implement proper code splitting - Use proper asset handling -- Configure proper optimization +- Configure proper optimization