Hub rules-ai-ml

rules-ai-ml

v5 public Verified

Ai-ml

Community-governed security ruleset for Ai-ml

@sigmashakeinc 0 pulls 7 rules published Apr 10, 2026 synced Sep 27, 2026 sigmashakeinc/rules/rulesets/rules-ai-ml →
Severity
5 error 1 warn 1 info
demo.cast
Community-governed security ruleset for Ai-ml

Rules index

7 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

vector

audit-embedding-model-change info log

AI model for vector embeddings is being changed. This will invalidate all existing vector indices.

Rule source requires an active Pro or Enterprise subscription.
block-hardcoded-vector-api-key error block

Detected potential hardcoded vector database API key (e.g., Pinecone, Weaviate).

Rule source requires an active Pro or Enterprise subscription.
block-mlflow-model-load-untrusted error block

RISK: mlflow.*load_model() deserializes models that may contain pickle payloads, conda environments, or custom Python code executed at load time. Loading a model from an untrusted registry or artifact store is equivalent to running untrusted code. FIX: only load models from registries you control; verify artifact checksums (MLflow >= 2.13 supports artifact signing); prefer safetensors/ONNX export for inference.

Rule source requires an active Pro or Enterprise subscription.
block-torch-load-unsafe error block

RISK: torch.load() without weights_only=True deserializes arbitrary Python objects via pickle (CVE-2025-32434 — PyTorch < 2.6 allows RCE even with weights_only=True on some paths; attacker-controlled model files are a live attack vector on Hugging Face). FIX: upgrade PyTorch >= 2.6 and always call torch.load(path, weights_only=True), or switch to safetensors.load_file() which has no deserialization attack surface.

Rule source requires an active Pro or Enterprise subscription.
block-vector-db-delete error block

Blocked direct deletion of vector database indices or namespaces (Pinecone, Chroma, etc.).

Rule source requires an active Pro or Enterprise subscription.
warn-llm-output-exec error block

RISK: passing LLM response content directly to exec() or eval() is prompt-injection-to-RCE (CWE-95). An adversarially crafted user message or retrieved document can cause the model to return malicious code that executes in your process. FIX: never eval/exec LLM output; parse structured outputs via JSON schema validation or a restricted DSL interpreter.

Rule source requires an active Pro or Enterprise subscription.
warn-vector-db-filter-missing warning log

Detected vector database query without metadata filters. This could lead to cross-tenant data bleed.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 10, 2026
Source commits
0
Synced
Sep 27, 2026
Hash
3be3a932f53aeaccaccca4360656c88df6a195e3c759aea52990725eb96c5d8b
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-ai-ml/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-ai-ml. The published version only bumps when a maintainer resyncs.

No commit history available.