Agent skill

Windsurf Known Pitfalls

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Identify and avoid Devin Desktop (formerly Windsurf) anti-patterns and common mistakes.

MITAuto-check: notesDevelopment

Install Windsurf Known Pitfalls

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill windsurf-known-pitfalls -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace windsurf-known-pitfalls --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/windsurf-known-pitfalls .claude/skills/windsurf-known-pitfalls && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
windsurf-known-pitfalls
GitHub stars
2.8k
Token cost
~2.3k tokens
SKILL.md length
474 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Identify and avoid Devin Desktop (formerly Windsurf) anti-patterns and common mistakes.

  • Works in 10 steps: Avoid Using Cascade for Simple Tasks → Avoid Opening a Monorepo Root → Replace Vague Cascade Prompts → …
  • Onboarding new developers to Windsurf
  • SKILL.md covers Overview, Prerequisites, Tool Use and Instructions, plus 5 more sections
  • Calls git

What it does

Windsurf Known Pitfalls is an agent skill from jeremylongshore/tons-of-skills-marketplace. Identify and avoid Devin Desktop (formerly Windsurf) anti-patterns and common mistakes. Use when onboarding new developers to Windsurf, reviewing AI workflow practices, or auditing Windsurf configuration for issues. Trigger with phrases like "windsurf mistakes", "windsurf anti-patterns", "windsurf pitfalls", "windsurf what not to do", "windsurf gotchas".

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/official-docs.md`). Compatibility notes: Designed for Claude Code

It sits in Development. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Onboarding new developers to Windsurf
  • Reviewing AI workflow practices
  • Auditing Windsurf configuration for issues
  • With phrases like windsurf mistakes

Example prompts

  • “windsurf mistakes”
  • “windsurf anti-patterns”
  • “windsurf pitfalls”
  • “/windsurf-known-pitfalls”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Grep

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Avoid Using Cascade for Simple Tasks
  2. Avoid Opening a Monorepo Root
  3. Replace Vague Cascade Prompts
  4. Review Every Proposed Change
  5. Create a Checkpoint Before Cascade
  6. Isolate Conflicting AI Extensions
  7. Respect Rule Character Limits
  8. Bound Cascade Conversations
  9. Keep Secrets Out of Cascade
  10. Configure Turbo Mode Safely

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.devin.ai
    • windsurf.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Windsurf Known Pitfalls loads about 2.3k tokens when it runs, and up to ~2.4k if it reads all its reference files. Until then it costs about 95 tokens; SKILL.md has 474 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~95
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:188
    etting auth errors with the API key from .env. The error

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 474 words, ~2,297 tokens.

Download SKILL.mdSave it as .claude/skills/windsurf-known-pitfalls/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
windsurf-known-pitfalls
description
Identify and avoid Devin Desktop (formerly Windsurf) anti-patterns and common mistakes. Use when onboarding new developers to Windsurf, reviewing AI workflow practices, or auditing Windsurf configuration for issues. Trigger with phrases like "windsurf mistakes", "windsurf anti-patterns", "windsurf pitfalls", "windsurf what not to do", "windsurf gotchas".
allowed-tools
Read, Grep
compatibility
Designed for Claude Code
argument-hint
[scope or requirements]
version
1.12.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, windsurf, anti-patterns, gotchas, best-practices

Windsurf Known Pitfalls

Overview

Avoid common failure modes involving Cascade, Supercomplete, workspace indexing, Rules, review, checkpoints, secrets, and terminal auto-execution. Verify mutable limits and labels against current first-party documentation.

Prerequisites

  • Windsurf installed and configured
  • Understanding of Cascade vs Supercomplete
  • Awareness of workspace indexing behavior

Tool Use

  • Use Read to inspect only the repository files and configuration needed for the request.
  • Use Grep to locate relevant settings, rules, logs, or code without broad collection.

Instructions

Step 1: Avoid Using Cascade for Simple Tasks

The mistake: Opening Cascade (Cmd+L) to complete a single line of code.

BAD: Opening Cascade to write "add a console.log"
→ Cascade spins up full agent context, reads multiple files = slow and expensive

GOOD: Use Supercomplete (Tab) for inline completions
→ Instant; verify the current model's usage label before assuming no quota charge

RULE OF THUMB:
- Single line / simple completion → Tab (Supercomplete)
- Inline edit of selection → Cmd+I (Command)
- Multi-file task / complex reasoning → Cmd+L (Cascade)
Step 2: Avoid Opening a Monorepo Root

The mistake: Opening a 100K+ file monorepo as a single workspace.

BAD:  windsurf ~/company-monorepo/
→ Cascade indexes everything, slow context, vague suggestions

GOOD: windsurf ~/company-monorepo/services/payments/
→ Focused context, fast indexing, precise suggestions

WHY: Cascade's context window is limited. More files = more noise.
A focused workspace with 5K files gives better suggestions than
a bloated workspace with 100K files.
Step 3: Replace Vague Cascade Prompts

The mistake: Giving Cascade broad, unscoped instructions.

BAD: "Refactor the codebase to use TypeScript"
→ Cascade may try to convert EVERY file at once, breaking everything

BAD: "Add validation to the API"
→ Which API? Which endpoints? What validation rules?

GOOD: "Convert src/utils/api.js to TypeScript. Add proper types for
all function parameters and return values. Don't change other files."

GOOD: "In src/routes/users.ts, add zod validation for the POST /users
endpoint. Validate email format, name length (2-50 chars), and role
must be 'admin' or 'user'. Return 400 with field-level errors."
Step 4: Review Every Proposed Change

The mistake: Accepting all Cascade changes without reading the diffs.

BAD: Cascade modifies 12 files → "Accept All" → broken tests
→ Cascade may have changed shared utilities, removed error handling,
  or introduced dependencies on APIs that don't exist

GOOD:
1. Read Cascade's explanation of what it changed
2. Review each file diff in the Cascade output
3. Check for: removed error handling, new imports, changed signatures
4. Run tests BEFORE committing
5. Use revert button if any file looks wrong
Step 5: Create a Checkpoint Before Cascade

The mistake: Running Cascade on a dirty working tree without a Git checkpoint.

BAD: Uncomitted changes + Cascade edits = impossible to separate
→ Can't tell what was your work vs what Cascade changed
→ Can't revert Cascade changes without losing your work

GOOD: git add -A && git commit -m "checkpoint: before cascade"
→ Clean separation between your work and Cascade's
→ Easy revert: git checkout -- .
Step 6: Isolate Conflicting AI Extensions

The mistake: Running GitHub Copilot alongside Windsurf.

KNOWN CONFLICTS:
- GitHub Copilot — conflicts with Supercomplete
  Symptoms: duplicate suggestions, wrong completions, slow editor

- TabNine — conflicts with Supercomplete
  Symptoms: competing inline suggestions

- Cody (Sourcegraph) — conflicts with Cascade
  Symptoms: multiple AI panels, context confusion

FIX: Disable competing extensions
Settings > Extensions > search "copilot" > Disable
Step 7: Respect Rule Character Limits

The mistake: Writing an oversized .devin/rules/project.md file.

LIMITS:

  • Workspace Rules under .devin/rules/*.md: 12,000 characters each (current documented per-rule limit)
  • Global rules (global_rules.md): 6,000 characters (current documented global limit)

WHAT HAPPENS WHEN EXCEEDED:

  • Oversized rules are outside the documented contract and may not load as intended
  • Re-check the live rules documentation before relying on boundary behavior

FIX: Keep .devin/rules/project.md concise (stack, patterns, don'ts) Move detailed rules to .devin/rules/ with trigger modes

Step 8: Bound Cascade Conversations

The mistake: Using a single Cascade conversation for hours of work.

BAD: 50-message Cascade conversation spanning multiple topics
→ Context window fills up, Cascade "forgets" early context
→ Suggestions become inconsistent or contradictory

GOOD: One task per Cascade session
→ Click + icon to start new conversation for each new task
→ Clean context = better suggestions
→ Use Memories for facts that should persist across sessions
Step 9: Keep Secrets Out of Cascade

The mistake: Sharing API keys or credentials in Cascade chat.

BAD: "My API key is sk-abc123def456, why isn't auth working?"
→ Secret is now in Cascade's context, may appear in suggestions later

GOOD: "I'm getting auth errors with the API key from .env. The error
message is 'Invalid API key'. What should I check?"
→ Cascade can help without seeing the actual secret
Show full SKILL.md (191 more words)Show less
Step 10: Configure Turbo Mode Safely

The mistake: Enabling Turbo mode without configuring deny lists.

BAD: Turbo mode ON + no deny list
→ Cascade auto-runs `rm -rf`, `git push --force`, etc.

GOOD: Turbo mode ON + configured deny list
→ Fast auto-execution for safe commands (npm test, git status)
→ Manual approval for dangerous commands (rm, sudo, push --force)

CONFIGURE:
Settings > cascadeCommandsDenyList > add destructive commands

Output

Return a prioritized audit table with each observed pitfall, evidence location, risk, recommended correction, and verification step. Distinguish current Devin Desktop behavior from legacy Windsurf behavior so teams do not institutionalize obsolete settings.

Error Handling

PitfallSymptomPrevention
Wrong tool for taskSlow response for simple taskTab for completions, Cmd+L for complex
Giant workspaceSlow indexing, vague AIOpen service directory, not root
Vague promptsWrong files modifiedSpecify paths, constraints, expected output
No reviewBroken build after CascadeAlways review diffs, run tests
No checkpointCan't undo Cascade workAlways commit before Cascade
AI conflictsDuplicate/wrong suggestionsDisable competing extensions
Over-limit rulesSilently truncatedCheck char counts, use workspace rules
Long conversationsContext degradationNew session per task
Secrets in chatPotential data exposureNever paste actual credentials
Unsafe TurboDestructive commands auto-runConfigure deny list

Examples

Pre-Cascade Checklist
bash
set -euo pipefail
echo "=== Pre-Cascade Checklist ==="
readonly WORKSPACE_RULE_LIMIT=12000 # Current documented maximum for one workspace rule.
echo "Git clean: $(git status --porcelain | wc -l | xargs) uncommitted files"
echo "On branch: $(git branch --show-current)"
echo "Rules: $(wc -c < .devin/rules/project.md 2>/dev/null || echo 0) chars (max $WORKSPACE_RULE_LIMIT)"
echo "Conflicting exts: $(windsurf --list-extensions 2>/dev/null | grep -ci 'copilot\|tabnine\|cody' || echo 0)"
Common Prompt Templates
Feature: "In [file], add [feature] that [behavior]. Follow the pattern
in @[reference-file]. Include error handling for [edge cases]. Don't
modify [protected files]."

Bug fix: "@[file] The function [name] fails when [condition]. The error
is [error message]. Fix it and add a test for this edge case."

Refactor: "Extract [logic] from [file] into a new [file]. Update all
imports. Run tests after. Don't change public API signatures."

Resources

Start with windsurf-install-auth for a new workstation, or use windsurf-reference-architecture to establish a reviewed team configuration baseline.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/windsurf-known-pitfalls of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/official-docs.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Windsurf Known Pitfalls next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Windsurf Known Pitfalls compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Windsurf Known Pitfalls this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2.3kAutomated safety check: NotesMIT
Vercel Composition Patternssupabase/supabase111k58 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers297k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k4 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 58 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 4 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Windsurf Known Pitfalls

What does Windsurf Known Pitfalls do?

Identify and avoid Devin Desktop (formerly Windsurf) anti-patterns and common mistakes. Windsurf Known Pitfalls is an agent skill from jeremylongshore/tons-of-skills-marketplace. Identify and avoid Devin Desktop (formerly Windsurf) anti-patterns and common mistakes.

When should I use Windsurf Known Pitfalls?

Windsurf Known Pitfalls fits situations like: onboarding new developers to Windsurf; reviewing AI workflow practices; auditing Windsurf configuration for issues; with phrases like windsurf mistakes.

How do I install Windsurf Known Pitfalls in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill windsurf-known-pitfalls -a claude-code`. Or copy the skill folder (skills/.curated/windsurf-known-pitfalls in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/windsurf-known-pitfalls in your project. Claude Code loads it when a task matches its description.

How do I install Windsurf Known Pitfalls in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill windsurf-known-pitfalls -a codex`. Or copy the skill folder (skills/.curated/windsurf-known-pitfalls in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/windsurf-known-pitfalls in your project. Codex loads it when a task matches its description.

Can I use Windsurf Known Pitfalls in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill windsurf-known-pitfalls -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/windsurf-known-pitfalls, .gemini/skills/windsurf-known-pitfalls, .github/skills/windsurf-known-pitfalls and .opencode/skills/windsurf-known-pitfalls in your project.

What does Windsurf Known Pitfalls need to run?

Going by SKILL.md and its folder, Windsurf Known Pitfalls needs the command-line tools its instructions call (git). Its frontmatter pre-approves these tools: Read, Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Windsurf Known Pitfalls access the network?

SKILL.md names 2 domains. As links in the text: docs.devin.ai and windsurf.com. This is read from the text; nothing was executed.

Is Windsurf Known Pitfalls safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Windsurf Known Pitfalls use?

Windsurf Known Pitfalls is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Windsurf Known Pitfalls use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 98 tokens, read only when the agent opens those files.

What are the alternatives to Windsurf Known Pitfalls?

Skills that share tags, products or a category with Windsurf Known Pitfalls: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 297k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Windsurf Known Pitfalls?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.