Hub rules-c

rules-c

v5 public Verified

C

C is a general-purpose, procedural computer programming language. These rules govern memory management, pointer usage, and security best practices for AI-assisted C development.

@sigmashakeinc 2 pulls 10 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-c →
Severity
9 error 1 warn 0 info
demo.cast
C is a general-purpose, procedural computer programming language. These rules govern memory management, pointer usage, and security best practices for AI-assisted C development.

Rules index

10 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

c

c-command-injection-system error block

RISK: system() invokes /bin/sh, so any unsanitized user input in the argument leads to shell command injection (CWE-78). FIX: Use execve()/posix_spawn() with an explicit argv[] array (no shell expansion), or avoid spawning subprocesses entirely.

Rule source requires an active Pro or Enterprise subscription.
c-format-string-vulnerability error block

RISK: Using a variable as the format string argument to printf/fprintf/sprintf enables format string attacks (CWE-134) — an attacker who controls the string can read stack memory (%x) or write arbitrary addresses (%n), leading to information disclosure or RCE. FIX: Always pass a literal format string: printf("%s", user_input).

Rule source requires an active Pro or Enterprise subscription.
c-google-style-complex-macro warning log

Complex multi-statement preprocessor macro detected. Consider refactoring into an 'inline' function for better type checking, scope control, and debuggability. The Google C++ Style Guide and general best practice discourage complex macros because they can cause unexpected side effects and are difficult to test.

Rule source requires an active Pro or Enterprise subscription.
c-insecure-random-number-generation error block

RISK: rand()/srand() produce a predictable pseudo-random sequence — they must not be used for keys, nonces, session IDs, or any security-sensitive purpose (CWE-338). FIX: Use getrandom(2) (Linux 3.17+) or read /dev/urandom; on Windows use BCryptGenRandom.

Rule source requires an active Pro or Enterprise subscription.
c-integer-overflow-in-malloc error block

RISK: Multiplying operands inside malloc() without overflow checks (e.g., malloc(n * size)) can wrap around to a small allocation when n is attacker-controlled, causing a heap overflow on write (CWE-190/CWE-122). FIX: Use calloc(n, size) which checks for overflow, or validate that n <= SIZE_MAX / size before calling malloc.

Rule source requires an active Pro or Enterprise subscription.
c-return-address-of-local error block

RISK: Returning a pointer to a local (stack-allocated) variable creates a dangling pointer (CWE-825/CWE-562) — the memory is invalid as soon as the function returns, causing undefined behaviour on use. FIX: Allocate on the heap with malloc() (and document the caller's responsibility to free), or require the caller to pass a buffer.

Rule source requires an active Pro or Enterprise subscription.
c-unsafe-gets error block

RISK: gets() has no length limit — any input longer than the buffer is a guaranteed buffer overflow (CWE-242). It was removed from C11. FIX: Replace with fgets(buf, sizeof(buf), stdin) or getline(), which accept a maximum length.

Rule source requires an active Pro or Enterprise subscription.
c-unsafe-sprintf-fixed-buffer error block

RISK: sprintf() writes into the destination with no length check — a format result longer than the buffer silently overflows (CWE-120). FIX: Replace with snprintf(dst, sizeof(dst), fmt, ...) and check the return value to detect truncation.

Rule source requires an active Pro or Enterprise subscription.
c-unsafe-strcat error block

RISK: strcat() appends without a length limit — when the combined length exceeds the destination buffer, the overflow is silent (CWE-120). FIX: Use strlcat(dst, src, sizeof(dst)) or track remaining capacity manually with strncat(dst, src, sizeof(dst) - strlen(dst) - 1).

Rule source requires an active Pro or Enterprise subscription.
c-unsafe-strcpy error block

RISK: strcpy() performs no bounds check — a source longer than the destination causes a stack/heap buffer overflow (CWE-120), which is exploitable for code execution. FIX: Use strlcpy(dst, src, sizeof(dst)) (BSD/glibc 2.38+), or snprintf(dst, sizeof(dst), "%s", src) for portability.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
514ebaec0ec82fc890c8fb8a17ace83335e1ea5b1531851b78147c3523bb6b40
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-c/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-c. The published version only bumps when a maintainer resyncs.

No commit history available.