~ / rigs / vibestackdev / vibe-stack

vibestackdev/vibe-stack

29 .mdc architecture rules that prevent AI coding assistants from hallucinating insecure auth, deprecated imports, and broken Next.js 15 patterns. Built for Cursor Agent and Claude Code.

↗ GitHub ★ 8 mit updated 3d ago project Claude CodeCodexCursor
share on X
ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
CONTEXT TAX · EVERY TURN
~34.7k tokens
Context hog · median rig: 2.3k · breakdown
GUARDRAILS
0/5
No committed guardrails · details

Copy this rig

# review before running: this installs third-party code
$ claude mcp add github -e GITHUB_PERSONAL_ACCESS_<redacted> -- npx -y @modelcontextprotocol/server-github
$ claude mcp add filesystem -- npx -y @modelcontextprotocol/server-filesystem ./
$ claude mcp add supabase -e SUPABASE_ACCESS_<redacted> -- npx -y @supabase/mcp-server-supabase@latest --read-only
$ claude mcp add browser -- npx -y @anthropic-ai/mcp-server-puppeteer

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ claude mcp add github -e GITHUB_PERSONAL_ACCESS_<redacted> -- npx -y @modelcontextprotocol/server-github
$ claude mcp add filesystem -- npx -y @modelcontextprotocol/server-filesystem ./
$ claude mcp add supabase -e SUPABASE_ACCESS_<redacted> -- npx -y @supabase/mcp-server-supabase@latest --read-only
$ claude mcp add browser -- npx -y @anthropic-ai/mcp-server-puppeteer

This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(**/.env)",
      "Read(~/.ssh/**)",
      "Bash(rm -rf *)",
      "Read(**/*.pem)",
      "Bash(rm -rf /)",
      "Bash(git push --force:*)",
      "Bash(sudo *)",
      "Read(.env)",
      "Bash(rm -rf /*)",
      "Read(./.env.*)",
      "Read(~/.aws/**)",
      "Bash(git push --force*)",
      "Bash(rm -rf:*)",
      "Read(**/*.key)",
      "Read(**/.env.*)",
      "Bash(sudo:*)",
      "Bash(git reset --hard*)",
      "Bash(git reset --hard:*)",
      "Read(.env.*)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(git push *)",
      "Bash(git commit:*)",
      "Bash(rm *)",
      "Bash(rm:*)",
      "Bash(git rebase *)",
      "Bash(wget *)",
      "Bash(npm publish:*)",
      "Bash(git commit *)",
      "Bash(gh pr merge *)"
    ]
  }
}

MCP servers (4)

serversourceest. tokens
GitHub MCP · "github"
env: GITHUB_PERSONAL_ACCESS_TOKEN
npm 18.0k
Filesystem npm 4.2k
Supabase
env: SUPABASE_ACCESS_TOKEN
npm 7.0k
Puppeteer · "browser" npm 2.2k

Cursor rules (29)

ai-collaboration · alwaysapi-designapi-validationcaching-revalidationcontext-managementdatabase-designenv-managementerror-handlingfile-namingfile-uploadsgit-conventionshydration-safetymiddleware-authnextjs15-paramsperformanceproject-context · alwaysreact19-patternssecurityserver-actionsserver-vs-client-componentsshadcn-patternsstripe-paymentsstripe-webhookssupabase-auth-securitysupabase-rlssupabase-ssr-onlytestingtypescript-strictverify-before-use · always

Similar rigs

copied ✓