AI Rules Generator for Cursor & Claude Code
Stop your AI assistant from leaking Stripe keys, hallucinating phantom packages, or breaking webhook signatures. Select your stack below to generate customized production guardrails in seconds.
Configure Your Stack
Why AI Editors Need Rules
Coding assistants like Cursor, Claude, Lovable, and Bolt are speed demons, but they default to the shortest path. Without strict rules, they regularly read Stripe webhooks as JSON (breaking crypto signatures), drop Supabase RLS, or paste real secret keys directly into client bundles.
Placing this file in your project root forces your assistant to follow launch-ready patterns on every single keystroke.
# .cursorrules: Production Guardrails for AI Coding Assistants
# Generated free by Vibe Code Detector (https://vibecodedetector.com/cursorrules)
You are an expert full-stack engineer building a high-reliability production web application.
Follow these non-negotiable rules on every code generation and refactor:
## Architecture & Framework Conventions
- Use Next.js 15 App Router conventions (app directory, Server Components by default).
- Only mark files with "use client" when browser interactivity, state, or browser APIs are strictly needed.
- Never import server-only modules or secrets into client components.
- Handle route parameters asynchronously matching Next.js 15 signatures (params: Promise<{ slug: string }>).
- Style with Tailwind CSS utility classes. Avoid arbitrary values like w-[347px] unless strictly necessary.
## Secrets & Environment Safety (CRITICAL)
- NEVER hardcode API keys, database passwords, or secret tokens into any source file.
- All sensitive values MUST be read from process.env on the server.
- NEVER prefix sensitive keys with NEXT_PUBLIC_ or VITE_.
- If an API key starts with sk_live_, sk-ant-, sk-proj-, or AKIA, stop immediately and use an environment variable.
## Supabase & Database Security
- Client components MUST use createBrowserClient() with NEXT_PUBLIC_SUPABASE_ANON_KEY only.
- NEVER use SUPABASE_SERVICE_ROLE_KEY on the client or in client-callable actions without explicit server-side authorization.
- Every new Supabase table MUST have Row Level Security enabled (ALTER TABLE ... ENABLE ROW LEVEL SECURITY).
- Always write explicit RLS policies for SELECT, INSERT, UPDATE, and DELETE scoping rows to auth.uid().
## Stripe & Payment Integrity
- In Stripe webhook route handlers, ALWAYS read the raw body as text (e.g. await req.text()), NOT JSON.
- ALWAYS verify webhook signatures with stripe.webhooks.constructEvent(body, sig, process.env.STRIPE_WEBHOOK_SECRET!).
- Acknowledge webhook receipts promptly with a 200 response to prevent Stripe retry storms.
- Never trust client-side prices or payment statuses. All entitlement grants must be triggered by verified webhook events.
## Authorization & IDOR Defense
- In all authenticated API routes and Server Actions, obtain the user ID from the verified session, NEVER from request bodies or URL parameters.
- Verify ownership before updating or deleting any database record (e.g., WHERE id = resourceId AND user_id = session.user.id).
## Dependency Hygiene
- Do NOT invent, assume, or hallucinate npm package names.
- Only import dependencies already declared in package.json.
- If a new package is required, explicitly prompt the user to install it and specify the exact package name.
## Loop & Re-render Prevention
- Ensure useEffect hooks have explicit, minimal dependency arrays to prevent runaway infinite loops.
- Add max retries and exponential backoff to external API and LLM calls to prevent unexpected billing spikes.
## Code Quality Standards
- Write strict TypeScript with explicit types; avoid `any`.
- Keep files focused and under 300 lines. Break large UI blocks into composable subcomponents.
- Handle loading states, error boundaries, and empty states gracefully.How to Install in 30 Seconds
- Click Download above to save the file.
- Move it into the root directory of your repository (right next to your
package.json). - Restart Cursor or Claude Code. Your assistant will automatically follow these rules on every prompt.
Rules protect your future code, but what about what your AI editor already wrote? Run all 108 launch checks across your repository with the Founder Pass ($15 one-time).