Hub rules-aider

rules-aider

v5 public Verified

Aider

Community-governed security ruleset for Aider

@sigmashakeinc 0 pulls 6 rules published Apr 10, 2026 synced Sep 27, 2026 sigmashakeinc/rules/rulesets/rules-aider →
Severity
3 error 2 warn 1 info
demo.cast
Community-governed security ruleset for Aider

Rules index

6 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

aider

audit-aider-commit-loop info log

Aider is running in an automatic 'edit-commit' loop. This can result in many small, unreviewed commits.

Rule source requires an active Pro or Enterprise subscription.
block-aider-config-edit error block

Blocked Aider from modifying its own configuration or global .aider.conf.yml.

Rule source requires an active Pro or Enterprise subscription.
block-aider-history-in-vcs warning log

RISK: Aider chat and input history files contain your full conversation, including any code snippets, credentials, or internal details shared with the model. Committing them leaks those details into version history. FIX: add .aider.chat.history.md and .aider.input.history to .gitignore.

Rule source requires an active Pro or Enterprise subscription.
block-aider-message-hardcoded-secret error block

RISK: the Aider --message argument contains what looks like a hardcoded secret or API key. Aider sends the full message to the upstream LLM provider and logs it to .aider.chat.history.md, both of which may be stored externally. FIX: never paste secrets into Aider messages; pass them via environment variables and reference the variable name in the message.

Rule source requires an active Pro or Enterprise subscription.
block-aider-no-git-flag error block

RISK: --no-git disables Aider's git-backed undo safety net. Without it, Aider's edits cannot be reverted with /undo and any destructive rewrite is permanent. FIX: always run Aider inside a git-tracked working tree and omit --no-git so each edit is committed and reversible.

Rule source requires an active Pro or Enterprise subscription.
warn-aider-shell-exec warning log

Aider is executing a shell command. This could be triggered by indirect prompt injection in a code file.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 10, 2026
Source commits
0
Synced
Sep 27, 2026
Hash
7ea4b8a6f8dbd490f4e4fe87a0bc2756d5b572cc6f0bfbadc126c15e81329add
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-aider/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-aider. The published version only bumps when a maintainer resyncs.

No commit history available.