vibestackdev/vibe-stack
29 .mdc architecture rules that prevent AI coding assistants from hallucinating insecure auth, deprecated imports, and broken Next.js 15 patterns. Built for Cursor Agent and Claude Code.
ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
Copy this rig
# review before running: this installs third-party code $ claude mcp add github -e GITHUB_PERSONAL_ACCESS_<redacted> -- npx -y @modelcontextprotocol/server-github $ claude mcp add filesystem -- npx -y @modelcontextprotocol/server-filesystem ./ $ claude mcp add supabase -e SUPABASE_ACCESS_<redacted> -- npx -y @supabase/mcp-server-supabase@latest --read-only $ claude mcp add browser -- npx -y @anthropic-ai/mcp-server-puppeteer
MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ claude mcp add github -e GITHUB_PERSONAL_ACCESS_<redacted> -- npx -y @modelcontextprotocol/server-github $ claude mcp add filesystem -- npx -y @modelcontextprotocol/server-filesystem ./ $ claude mcp add supabase -e SUPABASE_ACCESS_<redacted> -- npx -y @supabase/mcp-server-supabase@latest --read-only $ claude mcp add browser -- npx -y @anthropic-ai/mcp-server-puppeteer
This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(**/.env)",
"Read(~/.ssh/**)",
"Bash(rm -rf *)",
"Read(**/*.pem)",
"Bash(rm -rf /)",
"Bash(git push --force:*)",
"Bash(sudo *)",
"Read(.env)",
"Bash(rm -rf /*)",
"Read(./.env.*)",
"Read(~/.aws/**)",
"Bash(git push --force*)",
"Bash(rm -rf:*)",
"Read(**/*.key)",
"Read(**/.env.*)",
"Bash(sudo:*)",
"Bash(git reset --hard*)",
"Bash(git reset --hard:*)",
"Read(.env.*)"
],
"ask": [
"Bash(git push:*)",
"Bash(git push *)",
"Bash(git commit:*)",
"Bash(rm *)",
"Bash(rm:*)",
"Bash(git rebase *)",
"Bash(wget *)",
"Bash(npm publish:*)",
"Bash(git commit *)",
"Bash(gh pr merge *)"
]
}
} MCP servers (4)
| server | source | est. tokens |
|---|---|---|
| GitHub MCP · "github" env: GITHUB_PERSONAL_ACCESS_TOKEN | npm | 18.0k |
| Filesystem | npm | 4.2k |
| Supabase env: SUPABASE_ACCESS_TOKEN | npm | 7.0k |
| Puppeteer · "browser" | npm | 2.2k |
Cursor rules (29)
ai-collaboration · alwaysapi-designapi-validationcaching-revalidationcontext-managementdatabase-designenv-managementerror-handlingfile-namingfile-uploadsgit-conventionshydration-safetymiddleware-authnextjs15-paramsperformanceproject-context · alwaysreact19-patternssecurityserver-actionsserver-vs-client-componentsshadcn-patternsstripe-paymentsstripe-webhookssupabase-auth-securitysupabase-rlssupabase-ssr-onlytestingtypescript-strictverify-before-use · always
Similar rigs
floating-astronaut/vibe-coding-kit
Replace your dev team: an operating system for a coordinated Claude Code, Codex and Kimi AI coding team. Docs-first lanes, zero-drift handoffs. MIT.
Pragmatist 22.8k tok ·
Saksham-Bhardwaj/claude-setup
My Claude Code configuration — CLAUDE.md, settings, hooks, and MCP setup
Pragmatist 20.8k tok ·
vladzaharia/dotfiles
—
Automator 28.7k tok ·
haritzloza/nebula
Personal Hyprland dotfiles for CachyOS — gaming, dev, and an embedded Claude AI widget
Pragmatist 25.6k tok ·