Hub rules-angular

rules-angular

v2 public Verified

Angular

Angular is a web development framework for building single-page applications. These rules govern component structure, dependency injection, and best practices for AI-assisted Angular development.

@sigmashakeinc 2 pulls 6 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-angular →
Severity
4 error 2 warn 0 info
demo.cast
Angular is a web development framework for building single-page applications. These rules govern component structure, dependency injection, and best practices for AI-assisted Angular development.

Rules index

6 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

angular

angular-direct-dom-manipulation-innerhtml error block

Direct assignment to `element.innerHTML` bypasses Angular's built-in sanitization and templating mechanisms, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities if the assigned content is not thoroughly sanitized. Angular provides secure data binding (`[innerHTML]`) and `DomSanitizer` for handling trusted HTML. If dynamic HTML is absolutely necessary, ensure it comes from a trusted source or is explicitly sanitized using `DomSanitizer`'s `bypassSecurityTrustHtml` *only after rigorous validation*.

Rule source requires an active Pro or Enterprise subscription.
angular-open-redirect-risk error block

Direct assignment to `window.location.href` or navigation via `router.navigateByUrl()` using untrusted or unvalidated input (e.g., from URL query parameters, user input) can lead to an Open Redirect vulnerability. This allows attackers to redirect users to malicious sites for phishing. Always validate and sanitize redirect URLs against a whitelist of allowed domains or paths before performing navigation.

Rule source requires an active Pro or Enterprise subscription.
angular-style-guide-avoid-var-keyword warning log

The `var` keyword has function-level scope and can lead to unexpected behavior, variable hoisting issues, and make code harder to reason about. The Angular Style Guide and modern JavaScript best practices recommend using `let` for block-scoped mutable variables and `const` for block-scoped immutable variables instead. Replace `var` with `let` or `const` for improved code clarity and reduced potential for bugs.

Rule source requires an active Pro or Enterprise subscription.
angular-tabnabbing-vulnerability warning log

Links with `target="_blank"` can expose the user to a 'tabnabbing' vulnerability, where the newly opened page can manipulate the `window.opener` object of the original page. To prevent this, always include `rel="noopener noreferrer"` (or at least `rel="noopener"`) in the anchor tag. This prevents the new page from accessing the `window.opener` property.

Rule source requires an active Pro or Enterprise subscription.
angular-unsafe-code-execution-eval-function error block

The use of `eval()` or `new Function()` constructs allows arbitrary code execution and is a severe security risk. These functions bypass Angular's security mechanisms and Content Security Policy (CSP) protections, making the application highly vulnerable to injection attacks. There are almost no legitimate use cases for `eval()` or `new Function()` in modern Angular applications. Refactor the code to use Angular's template engine, data binding, or other safe alternatives.

Rule source requires an active Pro or Enterprise subscription.
angular-xss-bypass-security-trust error block

The use of `DomSanitizer.bypassSecurityTrust*` functions (e.g., `bypassSecurityTrustHtml`, `bypassSecurityTrustUrl`) directly exposes the application to Cross-Site Scripting (XSS) vulnerabilities if the input is not thoroughly sanitized beforehand. Angular's built-in sanitization is bypassed, allowing malicious scripts or content to be injected. Ensure all inputs passed to these functions originate from trusted sources or are rigorously sanitized using a robust, context-aware sanitizer before use. Prefer Angular's safe templating and data binding whenever possible.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v2
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
332b5d188cea137f6e6938e59f0cd5db81f33a4448f26e9659b60ed269dd763a
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-angular/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-angular. The published version only bumps when a maintainer resyncs.

No commit history available.