Vibe Stack banner
vibestackdev vibestackdev

Vibe Stack

AI community

Description

29 .mdc architecture rules that prevent AI coding assistants from hallucinating insecure auth, deprecated imports, and broken Next.js 15 patterns. Built for Cursor Agent and Claude Code.

Installation

This entry records only its repository, not the path inside it, so there is no exact command to give. Open the source below and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

README

⚑ Vibe Stack

Stop fixing AI-generated bugs. Start shipping production apps.

A **Next.js 15 + Supabase boilerplate** with **29 `.mdc` architecture rules** that physically prevent AI coding assistants from hallucinating insecure auth, deprecated packages, and broken patterns.

[![Next.js 15](https://img.shields.io/badge/Next.js-15-black?logo=next.js)](https://nextjs.org/) [![React 19](https://img.shields.io/badge/React-19-blue?logo=react)](https://react.dev/) [![Supabase](https://img.shields.io/badge/Supabase-SSR-3ecf8e?logo=supabase)](https://supabase.com/) [![TypeScript](https://img.shields.io/badge/TypeScript-strict-3178c6?logo=typescript)](https://www.typescriptlang.org/) [![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](LICENSE)

**The problem:** AI models generate code that compiles perfectly but ships critical vulnerabilities β€” `getSession()` instead of `getUser()`, synchronous params that crash in Next.js 15, missing RLS policies that expose your database. These bugs are invisible until production.

**The fix:** Architecture rules that override the AI's training data. When a rule says "NEVER use getSession()", the model is constrained to generate the secure pattern. Every time.


πŸš€ Quick Start

git clone https://github.com/vibestackdev/vibe-stack.git
cd vibe-stack
npm install
cp .env.example .env.local
# Add your Supabase URL + anon key to .env.local
npm run dev

Open in **Cursor** and start building. The rules activate automatically β€” zero configuration.


πŸ†“ What's Free (This Repo)

This open-source repo includes **5 foundational architecture rules** β€” the most critical safeguards for any Next.js 15 + Supabase project:

Free Rule What It Prevents
supabase-auth-security.mdc Bans getSession(), enforces getUser() for JWT verification
nextjs15-params.mdc Prevents synchronous params access (the #1 Next.js 15 breaking change)
supabase-ssr-only.mdc Blocks deprec