principle-type-system-discipline
cursor/plugins
Apply type-system discipline to eliminate impossible states and catch bugs at compile time.
What is principle-type-system-discipline?
A principle for designing types in statically-typed languages to make illegal states unrepresentable and catch errors before runtime. Use sum types, branded primitives, exhaustive matching, and boundary validation to let the compiler prove correctness.
- Model contradictory state combinations as sum types so they cannot compile
- Brand semantic primitives (UserId, OrderId) to prevent accidental type confusion
- Parse external data (JSON, RPC, config) at boundaries into typed models
- Use exhaustive pattern matching so new variants force handling everywhere
- Derive types from authoritative schemas (protobuf, OpenAPI, GraphQL) instead of hand-rolling
- Strengthen types only where partiality appears, keeping functions total
How to install principle-type-system-discipline
npx skills add https://github.com/cursor/plugins --skill principle-type-system-disciplineHow to use principle-type-system-discipline
- 1.Identify loose types: fields that admit contradictory combinations or optional fields that should derive from a single source
- 2.Replace with sum types (discriminated unions, enums with payloads, sealed classes) so illegal states cannot compile
- 3.Brand semantic primitives with newtypes, opaque types, or branded intersections to prevent accidental confusion
- 4.Add parse functions at data boundaries (RPC, JSON, CLI, config, database) to convert unstructured input to typed models
- 5.Use exhaustive pattern matching (never-typed bindings, sealed-class match, -Wincomplete-patterns) so new variants force updates
- 6.Derive types from authoritative schemas instead of hand-rolling parallel definitions
Use cases
- Reviewing a function signature to catch loose types that admit invalid states
- Designing a domain model where field combinations need validation
- Refactoring a codebase with scattered null checks and assertions into typed variants
- Parsing untrusted external data (API responses, config files) safely at entry points
- Adding a new variant to a sum type and finding all places that must handle it
- Backend engineers writing statically-typed code (TypeScript, Rust, Kotlin, Haskell, etc.)
- Code reviewers checking type design and function signatures
- Teams migrating from dynamic languages and learning to leverage type systems
- API and schema designers defining contracts that code can derive from
principle-type-system-discipline FAQ
Use a sum type when field combinations are meaningless. If you can write a comment explaining when a combination is valid, the type is too loose. For example, { completed: boolean; completedAt?: Date } admits completed: true; completedAt: undefined, which is nonsense. Model it as { kind: 'open' } | { kind: 'done'; at: Date } instead.
Branding makes semantically different primitives (UserId vs. OrderId, both strings) incompatible at the type level. Validate once at creation, then trust the type downstream. Use newtypes (Rust), opaque types (Swift), value classes (Kotlin), or branded intersections (TypeScript).
At every boundary where unstructured data enters: RPC payloads, JSON, IPC, CLI args, config files, environment variables, database rows. Write a parse function that converts the raw input into your typed model, and reject invalid data there.
Don't cast or use unsafe coercions—those are latent crashes. Instead, validate the fact (narrow the type, refine the model), or accept that the cast is a hazard and document it. If nothing would otherwise panic, keep the plain type.
Use your language's idiom: never-typed bindings in TypeScript, unannotated match in Rust, -Wincomplete-patterns in Haskell, sealed-class match in Kotlin. The compiler must fail if a new variant is added without a handler.
Full instructions (SKILL.md)
Source of truth, from cursor/plugins.
name: principle-type-system-discipline description: "Apply when designing types, reviewing a function signature, or writing code in any statically-typed language. Make illegal states unrepresentable, brand semantic primitives, parse external data at boundaries, refuse to lie to the compiler, exhaust variants, derive from authoritative schemas." disable-model-invocation: true
Type System Discipline
The type checker is a proof assistant. Use it to eliminate impossible states, mismatched primitives, and unhandled variants at compile time. A case the types let you ignore becomes a runtime failure the compiler could have stopped. Prefer defining errors and special cases out of existence over proliferating handlers. Unrepresentable states, total functions, and interface redesign (the patterns below) are the tools.
Applies to any typed language. Skills like typescript-best-practices ground it in specific syntax.
The patterns:
- Make illegal states unrepresentable. Model variants as sum types: discriminated unions in TypeScript, enums with payloads in Rust/Swift/Kotlin, sealed classes in Scala, ADTs in Haskell/OCaml. Don't model state as a bag of optional fields where contradictory combinations compile. A subtle anti-pattern:
{ completed: boolean; completedAt?: Date }admitscompleted: true; completedAt: undefined, which is meaningless. Derive the boolean from a single source likecompletedAt !== null, or model the variants explicitly as{ kind: 'open' } | { kind: 'done'; at: Date }. If a bug forces the question "wait, can this combination actually happen?", the type is too loose. - Types are constructions, not restrictions. Build the type up from the values you want instead of carving them out of a looser type with checks. The invariant that seems to need a refinement type is usually a construction away. A non-empty list is a head plus a rest, not a list with a length check. A valid time range is a start plus a duration, not two timestamps you must keep ordered. No representation is privileged. A list of pairs is an even-length list if you interpret it that way, so choose the shape that cannot build the illegal value and expose the interface callers need on top.
- Brand semantic primitives.
UserIdandOrderIdare strings underneath but should not be interchangeable. Newtypes in Rust, opaque types in Swift, value classes in Kotlin, phantom types in Haskell, branded intersections in TypeScript. Validate once at creation, trust the type downstream. - External data is untyped until parsed. RPC payloads, JSON, IPC messages, CLI args, config files, environment variables, database rows. Have a parse function at every boundary that turns unstructured input into the typed model. See the boundary-discipline principle skill for where to put validation.
- Don't lie to the type system. Casts, unsafe coercions, and assertion functions that bypass the compiler are latent runtime crashes. If the compiler can't prove a fact, prove it (validate, narrow, refine the model) or accept that the cast is a hazard.
- Exhaustive matching is the compiler's job. When you match on a sum type, the compiler must fail compilation if a new variant is added without handling. Use the idiom your language provides:
never-typed binding in TypeScript, unannotatedmatchin Rust,-Wincomplete-patternsin Haskell, sealed-class match exhaustiveness in Kotlin. - Derive types from authoritative schemas. When a protocol buffer, OpenAPI spec, GraphQL schema, database migration, or design-system token file defines a shape, derive from it instead of hand-rolling a parallel type. See the encode-lessons-in-structure principle skill.
- Strengthen a type only where partiality appears. A runtime assertion, null check, or "this should never happen" throw marks the place a type is too weak. Push that check up into the type. Then stop. The type system's job is to track the cases each use site must handle, not to describe the data as precisely as possible. Prefer total functions.
sumof an empty list is 0, so it takes the plain list.headof an empty list has no answer, so it demands the non-empty one.
The tests:
- "Can I write a comment explaining when this combination of fields is valid?" If yes, the type is too loose. Split it into a sum type.
- "Do two of my function arguments share a primitive type but mean different things?" Brand them.
- "Where did this
any, thisas, thisassertNotNullcome from?" Trace it to the boundary and validate there instead. - "If a new variant is added next month, will the compiler tell the next agent where to add a case?" If no, the match isn't exhaustive.
- "Is this type duplicating a shape another file owns?" Derive instead.
- "Am I strengthening this type to keep an operation total, or just to be more precise?" If nothing would otherwise panic, keep the plain type.
Related skills
More from cursor/plugins and the wider catalog.

recall
Reconstruct your recent working context from chat history and shared records to resume work efficiently.

reflect
Mine conversations for durable learnings and route them into skill edits.

review-and-ship
Review code for bugs and intent fit, run tests, and open or update a PR.

run-smoke-tests
Run Playwright smoke tests, debug failures, and verify fixes

setup-pstack
Agent skill from cursor/plugins.

show-me-your-work
Maintain a reviewable decision log (TSV) for long-running or autonomous work, with one row per decision.