RuleStack

Configs

Stacks

Compare

Diff

RuleStack

Configs

Stacks

Compare

Diff

Read API

RuleStack

Configs

Stacks

Compare

Diff

Read API

Diff/thanhtrunggdev-dontbelazy-cursor-rules-csharp-security ↔ thanhtrunggdev-dontbelazy-cursor-agents

Comparison

A · Cursor rules · ThanhTrunggDEV/DontBeLazyB · AGENTS.md · ThanhTrunggDEV/DontBeLazy
What each file covers, counted
DimensionSharedOnly in AOnly in BOverlap
Sections07140%
Commands000—
Section tags21622%

What each file covers

Sections

0 shared · 7 only in A · 14 only in B
  • − C# Security
  • − Secret Management
  • − SQL Injection Prevention
  • − Input Validation
  • − Authentication and Authorization
  • − Error Handling
  • − References
  • + Everything Claude Code (ECC) — Agent Instructions
  • + Core Principles
  • + Available Agents
  • + Agent Orchestration
  • + Security Guidelines
  • + Coding Style
  • + Testing Requirements
  • + Development Workflow
  • + Workflow Surface Policy
  • + Git Workflow
  • + Architecture Patterns
  • + Performance
  • + Project Structure
  • + Success Metrics

Commands

neither file has any

Section tags

2 shared · 1 only in A · 6 only in B
  • − database
  • + build
  • + test
  • + architecture
  • + git-pr
  • + performance
  • + agent-behaviour
  •   code-style
  •   security

Line diff

+150 added−42 removed17 unchanged10.2% identical
ThanhTrunggDEV/DontBeLazy · .cursor/rules/csharp-security.mdc
@@ −1 @@
1---
2paths:
3 - "**/*.cs"
4 - "**/*.csx"
5 - "**/*.csproj"
6 - "**/appsettings*.json"
7---
8# C# Security
9 
10> This file extends [common/security.md](../common/security.md) with C#-specific content.
11 
12## Secret Management
13 
14- Never hardcode API keys, tokens, or connection strings in source code
15- Use environment variables, user secrets for local development, and a secret manager in production
16- Keep `appsettings.*.json` free of real credentials
17 
18```csharp
19// BAD
20const string ApiKey = "sk-live-123";
 
 
21 
22// GOOD
23var apiKey = builder.Configuration["OpenAI:ApiKey"]
24 ?? throw new InvalidOperationException("OpenAI:ApiKey is not configured.");
25```
26 
27## SQL Injection Prevention
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
28 
29- Always use parameterized queries with ADO.NET, Dapper, or EF Core
30- Never concatenate user input into SQL strings
31- Validate sort fields and filter operators before using dynamic query composition
32 
33```csharp
34const string sql = "SELECT * FROM Orders WHERE CustomerId = @customerId";
35await connection.QueryAsync<Order>(sql, new { customerId });
36```
 
 
 
 
37 
38## Input Validation
39 
40- Validate DTOs at the application boundary
41- Use data annotations, FluentValidation, or explicit guard clauses
42- Reject invalid model state before running business logic
43 
44## Authentication and Authorization
 
 
 
 
 
 
 
 
45 
46- Prefer framework auth handlers instead of custom token parsing
47- Enforce authorization policies at endpoint or handler boundaries
48- Never log raw tokens, passwords, or PII
49 
50## Error Handling
51 
52- Return safe client-facing messages
53- Log detailed exceptions with structured context server-side
54- Do not expose stack traces, SQL text, or filesystem paths in API responses
55 
56## References
57 
58See skill: `security-review` for broader application security review checklists.
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
59 
ThanhTrunggDEV/DontBeLazy · .cursor/AGENTS.md
@@ +1 @@
1# Everything Claude Code (ECC) — Agent Instructions
 
 
 
 
 
 
 
2 
3This is a **production-ready AI coding plugin** providing 48 specialized agents, 183 skills, 79 commands, and automated hook workflows for software development.
4 
5**Version:** 1.10.0
6 
7## Core Principles
 
 
8 
91. **Agent-First** — Delegate to specialized agents for domain tasks
102. **Test-Driven** — Write tests before implementation, 80%+ coverage required
113. **Security-First** — Never compromise on security; validate all inputs
124. **Immutability** — Always create new objects, never mutate existing ones
135. **Plan Before Execute** — Plan complex features before writing code
14 
15## Available Agents
 
 
 
16 
17| Agent | Purpose | When to Use |
18|-------|---------|-------------|
19| planner | Implementation planning | Complex features, refactoring |
20| architect | System design and scalability | Architectural decisions |
21| tdd-guide | Test-driven development | New features, bug fixes |
22| code-reviewer | Code quality and maintainability | After writing/modifying code |
23| security-reviewer | Vulnerability detection | Before commits, sensitive code |
24| build-error-resolver | Fix build/type errors | When build fails |
25| e2e-runner | End-to-end Playwright testing | Critical user flows |
26| refactor-cleaner | Dead code cleanup | Code maintenance |
27| doc-updater | Documentation and codemaps | Updating docs |
28| cpp-reviewer | C/C++ code review | C and C++ projects |
29| cpp-build-resolver | C/C++ build errors | C and C++ build failures |
30| docs-lookup | Documentation lookup via Context7 | API/docs questions |
31| go-reviewer | Go code review | Go projects |
32| go-build-resolver | Go build errors | Go build failures |
33| kotlin-reviewer | Kotlin code review | Kotlin/Android/KMP projects |
34| kotlin-build-resolver | Kotlin/Gradle build errors | Kotlin build failures |
35| database-reviewer | PostgreSQL/Supabase specialist | Schema design, query optimization |
36| python-reviewer | Python code review | Python projects |
37| java-reviewer | Java and Spring Boot code review | Java/Spring Boot projects |
38| java-build-resolver | Java/Maven/Gradle build errors | Java build failures |
39| loop-operator | Autonomous loop execution | Run loops safely, monitor stalls, intervene |
40| harness-optimizer | Harness config tuning | Reliability, cost, throughput |
41| rust-reviewer | Rust code review | Rust projects |
42| rust-build-resolver | Rust build errors | Rust build failures |
43| pytorch-build-resolver | PyTorch runtime/CUDA/training errors | PyTorch build/training failures |
44| typescript-reviewer | TypeScript/JavaScript code review | TypeScript/JavaScript projects |
45 
46## Agent Orchestration
 
 
47 
48Use agents proactively without user prompt:
49- Complex feature requests → **planner**
50- Code just written/modified → **code-reviewer**
51- Bug fix or new feature → **tdd-guide**
52- Architectural decision → **architect**
53- Security-sensitive code → **security-reviewer**
54- Autonomous loops / loop monitoring → **loop-operator**
55- Harness config reliability and cost → **harness-optimizer**
56 
57Use parallel execution for independent operations — launch multiple agents simultaneously.
58 
59## Security Guidelines
 
 
60 
61**Before ANY commit:**
62- No hardcoded secrets (API keys, passwords, tokens)
63- All user inputs validated
64- SQL injection prevention (parameterized queries)
65- XSS prevention (sanitized HTML)
66- CSRF protection enabled
67- Authentication/authorization verified
68- Rate limiting on all endpoints
69- Error messages don't leak sensitive data
70 
71**Secret management:** NEVER hardcode secrets. Use environment variables or a secret manager. Validate required secrets at startup. Rotate any exposed secrets immediately.
 
 
72 
73**If security issue found:** STOP → use security-reviewer agent → fix CRITICAL issues → rotate exposed secrets → review codebase for similar issues.
74 
75## Coding Style
 
 
76 
77**Immutability (CRITICAL):** Always create new objects, never mutate. Return new copies with changes applied.
78 
79**File organization:** Many small files over few large ones. 200-400 lines typical, 800 max. Organize by feature/domain, not by type. High cohesion, low coupling.
80 
81**Error handling:** Handle errors at every level. Provide user-friendly messages in UI code. Log detailed context server-side. Never silently swallow errors.
82 
83**Input validation:** Validate all user input at system boundaries. Use schema-based validation. Fail fast with clear messages. Never trust external data.
84 
85**Code quality checklist:**
86- Functions small (<50 lines), files focused (<800 lines)
87- No deep nesting (>4 levels)
88- Proper error handling, no hardcoded values
89- Readable, well-named identifiers
90 
91## Testing Requirements
92 
93**Minimum coverage: 80%**
94 
95Test types (all required):
961. **Unit tests** — Individual functions, utilities, components
972. **Integration tests** — API endpoints, database operations
983. **E2E tests** — Critical user flows
99 
100**TDD workflow (mandatory):**
1011. Write test first (RED) — test should FAIL
1022. Write minimal implementation (GREEN) — test should PASS
1033. Refactor (IMPROVE) — verify coverage 80%+
104 
105Troubleshoot failures: check test isolation → verify mocks → fix implementation (not tests, unless tests are wrong).
106 
107## Development Workflow
108 
1091. **Plan** — Use planner agent, identify dependencies and risks, break into phases
1102. **TDD** — Use tdd-guide agent, write tests first, implement, refactor
1113. **Review** — Use code-reviewer agent immediately, address CRITICAL/HIGH issues
1124. **Capture knowledge in the right place**
113 - Personal debugging notes, preferences, and temporary context → auto memory
114 - Team/project knowledge (architecture decisions, API changes, runbooks) → the project's existing docs structure
115 - If the current task already produces the relevant docs or code comments, do not duplicate the same information elsewhere
116 - If there is no obvious project doc location, ask before creating a new top-level file
1175. **Commit** — Conventional commits format, comprehensive PR summaries
118 
119## Workflow Surface Policy
120 
121- `skills/` is the canonical workflow surface.
122- New workflow contributions should land in `skills/` first.
123- `commands/` is a legacy slash-entry compatibility surface and should only be added or updated when a shim is still required for migration or cross-harness parity.
124 
125## Git Workflow
126 
127**Commit format:** `<type>: <description>` — Types: feat, fix, refactor, docs, test, chore, perf, ci
128 
129**PR workflow:** Analyze full commit history → draft comprehensive summary → include test plan → push with `-u` flag.
130 
131## Architecture Patterns
132 
133**API response format:** Consistent envelope with success indicator, data payload, error message, and pagination metadata.
134 
135**Repository pattern:** Encapsulate data access behind standard interface (findAll, findById, create, update, delete). Business logic depends on abstract interface, not storage mechanism.
136 
137**Skeleton projects:** Search for battle-tested templates, evaluate with parallel agents (security, extensibility, relevance), clone best match, iterate within proven structure.
138 
139## Performance
140 
141**Context management:** Avoid last 20% of context window for large refactoring and multi-file features. Lower-sensitivity tasks (single edits, docs, simple fixes) tolerate higher utilization.
142 
143**Build troubleshooting:** Use build-error-resolver agent → analyze errors → fix incrementally → verify after each fix.
144 
145## Project Structure
146 
147```
148agents/ — 48 specialized subagents
149skills/ — 183 workflow skills and domain knowledge
150commands/ — 79 slash commands
151hooks/ — Trigger-based automations
152rules/ — Always-follow guidelines (common + per-language)
153scripts/ — Cross-platform Node.js utilities
154mcp-configs/ — 14 MCP server configurations
155tests/ — Test suite
156```
157 
158`commands/` remains in the repo for compatibility, but the long-term direction is skills-first.
159 
160## Success Metrics
161 
162- All tests pass with 80%+ coverage
163- No security vulnerabilities
164- Code is readable and maintainable
165- Performance is acceptable
166- User requirements are met
167 
@@ −1 +1 @@
1−---
2−paths:
3− - "**/*.cs"
4− - "**/*.csx"
5− - "**/*.csproj"
6− - "**/appsettings*.json"
7−---
8−# C# Security
1+# Everything Claude Code (ECC) — Agent Instructions
92  
10−> This file extends [common/security.md](../common/security.md) with C#-specific content.
3+This is a **production-ready AI coding plugin** providing 48 specialized agents, 183 skills, 79 commands, and automated hook workflows for software development.
114  
12−## Secret Management
5+**Version:** 1.10.0
136  
14−- Never hardcode API keys, tokens, or connection strings in source code
15−- Use environment variables, user secrets for local development, and a secret manager in production
16−- Keep `appsettings.*.json` free of real credentials
7+## Core Principles
178  
18−```csharp
19−// BAD
20−const string ApiKey = "sk-live-123";
9+1. **Agent-First** — Delegate to specialized agents for domain tasks
10+2. **Test-Driven** — Write tests before implementation, 80%+ coverage required
11+3. **Security-First** — Never compromise on security; validate all inputs
12+4. **Immutability** — Always create new objects, never mutate existing ones
13+5. **Plan Before Execute** — Plan complex features before writing code
2114  
22−// GOOD
23−var apiKey = builder.Configuration["OpenAI:ApiKey"]
24− ?? throw new InvalidOperationException("OpenAI:ApiKey is not configured.");
25−```
15+## Available Agents
2616  
27−## SQL Injection Prevention
17+| Agent | Purpose | When to Use |
18+|-------|---------|-------------|
19+| planner | Implementation planning | Complex features, refactoring |
20+| architect | System design and scalability | Architectural decisions |
21+| tdd-guide | Test-driven development | New features, bug fixes |
22+| code-reviewer | Code quality and maintainability | After writing/modifying code |
23+| security-reviewer | Vulnerability detection | Before commits, sensitive code |
24+| build-error-resolver | Fix build/type errors | When build fails |
25+| e2e-runner | End-to-end Playwright testing | Critical user flows |
26+| refactor-cleaner | Dead code cleanup | Code maintenance |
27+| doc-updater | Documentation and codemaps | Updating docs |
28+| cpp-reviewer | C/C++ code review | C and C++ projects |
29+| cpp-build-resolver | C/C++ build errors | C and C++ build failures |
30+| docs-lookup | Documentation lookup via Context7 | API/docs questions |
31+| go-reviewer | Go code review | Go projects |
32+| go-build-resolver | Go build errors | Go build failures |
33+| kotlin-reviewer | Kotlin code review | Kotlin/Android/KMP projects |
34+| kotlin-build-resolver | Kotlin/Gradle build errors | Kotlin build failures |
35+| database-reviewer | PostgreSQL/Supabase specialist | Schema design, query optimization |
36+| python-reviewer | Python code review | Python projects |
37+| java-reviewer | Java and Spring Boot code review | Java/Spring Boot projects |
38+| java-build-resolver | Java/Maven/Gradle build errors | Java build failures |
39+| loop-operator | Autonomous loop execution | Run loops safely, monitor stalls, intervene |
40+| harness-optimizer | Harness config tuning | Reliability, cost, throughput |
41+| rust-reviewer | Rust code review | Rust projects |
42+| rust-build-resolver | Rust build errors | Rust build failures |
43+| pytorch-build-resolver | PyTorch runtime/CUDA/training errors | PyTorch build/training failures |
44+| typescript-reviewer | TypeScript/JavaScript code review | TypeScript/JavaScript projects |
2845  
29−- Always use parameterized queries with ADO.NET, Dapper, or EF Core
30−- Never concatenate user input into SQL strings
31−- Validate sort fields and filter operators before using dynamic query composition
46+## Agent Orchestration
3247  
33−```csharp
34−const string sql = "SELECT * FROM Orders WHERE CustomerId = @customerId";
35−await connection.QueryAsync<Order>(sql, new { customerId });
36−```
48+Use agents proactively without user prompt:
49+- Complex feature requests → **planner**
50+- Code just written/modified → **code-reviewer**
51+- Bug fix or new feature → **tdd-guide**
52+- Architectural decision → **architect**
53+- Security-sensitive code → **security-reviewer**
54+- Autonomous loops / loop monitoring → **loop-operator**
55+- Harness config reliability and cost → **harness-optimizer**
3756  
38−## Input Validation
57+Use parallel execution for independent operations — launch multiple agents simultaneously.
3958  
40−- Validate DTOs at the application boundary
41−- Use data annotations, FluentValidation, or explicit guard clauses
42−- Reject invalid model state before running business logic
59+## Security Guidelines
4360  
44−## Authentication and Authorization
61+**Before ANY commit:**
62+- No hardcoded secrets (API keys, passwords, tokens)
63+- All user inputs validated
64+- SQL injection prevention (parameterized queries)
65+- XSS prevention (sanitized HTML)
66+- CSRF protection enabled
67+- Authentication/authorization verified
68+- Rate limiting on all endpoints
69+- Error messages don't leak sensitive data
4570  
46−- Prefer framework auth handlers instead of custom token parsing
47−- Enforce authorization policies at endpoint or handler boundaries
48−- Never log raw tokens, passwords, or PII
71+**Secret management:** NEVER hardcode secrets. Use environment variables or a secret manager. Validate required secrets at startup. Rotate any exposed secrets immediately.
4972  
50−## Error Handling
73+**If security issue found:** STOP → use security-reviewer agent → fix CRITICAL issues → rotate exposed secrets → review codebase for similar issues.
5174  
52−- Return safe client-facing messages
53−- Log detailed exceptions with structured context server-side
54−- Do not expose stack traces, SQL text, or filesystem paths in API responses
75+## Coding Style
5576  
56−## References
77+**Immutability (CRITICAL):** Always create new objects, never mutate. Return new copies with changes applied.
5778  
58−See skill: `security-review` for broader application security review checklists.
79+**File organization:** Many small files over few large ones. 200-400 lines typical, 800 max. Organize by feature/domain, not by type. High cohesion, low coupling.
80+ 
81+**Error handling:** Handle errors at every level. Provide user-friendly messages in UI code. Log detailed context server-side. Never silently swallow errors.
82+ 
83+**Input validation:** Validate all user input at system boundaries. Use schema-based validation. Fail fast with clear messages. Never trust external data.
84+ 
85+**Code quality checklist:**
86+- Functions small (<50 lines), files focused (<800 lines)
87+- No deep nesting (>4 levels)
88+- Proper error handling, no hardcoded values
89+- Readable, well-named identifiers
90+ 
91+## Testing Requirements
92+ 
93+**Minimum coverage: 80%**
94+ 
95+Test types (all required):
96+1. **Unit tests** — Individual functions, utilities, components
97+2. **Integration tests** — API endpoints, database operations
98+3. **E2E tests** — Critical user flows
99+ 
100+**TDD workflow (mandatory):**
101+1. Write test first (RED) — test should FAIL
102+2. Write minimal implementation (GREEN) — test should PASS
103+3. Refactor (IMPROVE) — verify coverage 80%+
104+ 
105+Troubleshoot failures: check test isolation → verify mocks → fix implementation (not tests, unless tests are wrong).
106+ 
107+## Development Workflow
108+ 
109+1. **Plan** — Use planner agent, identify dependencies and risks, break into phases
110+2. **TDD** — Use tdd-guide agent, write tests first, implement, refactor
111+3. **Review** — Use code-reviewer agent immediately, address CRITICAL/HIGH issues
112+4. **Capture knowledge in the right place**
113+ - Personal debugging notes, preferences, and temporary context → auto memory
114+ - Team/project knowledge (architecture decisions, API changes, runbooks) → the project's existing docs structure
115+ - If the current task already produces the relevant docs or code comments, do not duplicate the same information elsewhere
116+ - If there is no obvious project doc location, ask before creating a new top-level file
117+5. **Commit** — Conventional commits format, comprehensive PR summaries
118+ 
119+## Workflow Surface Policy
120+ 
121+- `skills/` is the canonical workflow surface.
122+- New workflow contributions should land in `skills/` first.
123+- `commands/` is a legacy slash-entry compatibility surface and should only be added or updated when a shim is still required for migration or cross-harness parity.
124+ 
125+## Git Workflow
126+ 
127+**Commit format:** `<type>: <description>` — Types: feat, fix, refactor, docs, test, chore, perf, ci
128+ 
129+**PR workflow:** Analyze full commit history → draft comprehensive summary → include test plan → push with `-u` flag.
130+ 
131+## Architecture Patterns
132+ 
133+**API response format:** Consistent envelope with success indicator, data payload, error message, and pagination metadata.
134+ 
135+**Repository pattern:** Encapsulate data access behind standard interface (findAll, findById, create, update, delete). Business logic depends on abstract interface, not storage mechanism.
136+ 
137+**Skeleton projects:** Search for battle-tested templates, evaluate with parallel agents (security, extensibility, relevance), clone best match, iterate within proven structure.
138+ 
139+## Performance
140+ 
141+**Context management:** Avoid last 20% of context window for large refactoring and multi-file features. Lower-sensitivity tasks (single edits, docs, simple fixes) tolerate higher utilization.
142+ 
143+**Build troubleshooting:** Use build-error-resolver agent → analyze errors → fix incrementally → verify after each fix.
144+ 
145+## Project Structure
146+ 
147+```
148+agents/ — 48 specialized subagents
149+skills/ — 183 workflow skills and domain knowledge
150+commands/ — 79 slash commands
151+hooks/ — Trigger-based automations
152+rules/ — Always-follow guidelines (common + per-language)
153+scripts/ — Cross-platform Node.js utilities
154+mcp-configs/ — 14 MCP server configurations
155+tests/ — Test suite
156+```
157+ 
158+`commands/` remains in the repo for compatibility, but the long-term direction is skills-first.
159+ 
160+## Success Metrics
161+ 
162+- All tests pass with 80%+ coverage
163+- No security vulnerabilities
164+- Code is readable and maintainable
165+- Performance is acceptable
166+- User requirements are met
59167  
RuleStack

Built by

Kynth Studio

Directory

Configs
Stacks
Compare formats
Diff two configs
Best AGENTS.md examples

Formats

AGENTS.md
CLAUDE.md
Cursor rules
Copilot instructions

Reference

Read API
Corpus health
Privacy Policy
Terms

RuleStack

RuleStack

Built by

Kynth Studio

Directory

Configs
Stacks
Compare formats
Diff two configs
Best AGENTS.md examples

Formats

AGENTS.md
CLAUDE.md
Cursor rules
Copilot instructions

Reference

Read API
Corpus health
Privacy Policy
Terms

RuleStack

RuleStack

Built by

Kynth Studio

Directory

Configs
Stacks
Compare formats
Diff two configs
Best AGENTS.md examples

Formats

AGENTS.md
CLAUDE.md
Cursor rules
Copilot instructions

Reference

Read API
Corpus health
Privacy Policy
Terms

RuleStack