Hub rules-capacitor

rules-capacitor

v2 public Verified

Capacitor

Capacitor is an open-source native runtime for building Web Native apps. These rules govern plugin usage, native platform integration, and build processes for AI-assisted Capacitor development.

@sigmashakeinc 2 pulls 7 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-capacitor →
Severity
5 error 2 warn 0 info
demo.cast
Capacitor is an open-source native runtime for building Web Native apps. These rules govern plugin usage, native platform integration, and build processes for AI-assisted Capacitor development.

Rules index

7 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

capacitor

capacitor-filesystem-path-traversal-risk error block

Potential path traversal vulnerability with Capacitor Filesystem plugin. Using untrusted input (e.g., from user input, query parameters, or deep links) directly as a file path without validation can allow attackers to access or modify arbitrary files outside the intended directory. Always sanitize and validate file paths rigorously, or use a fixed, application-controlled path.

Rule source requires an active Pro or Enterprise subscription.
capacitor-google-style-guide-any-type warning log

Violation of type safety best practices (aligned with Google's general TypeScript style tenets). The use of the 'any' type bypasses TypeScript's type checking, reducing code reliability and making it harder to catch errors. Consider defining specific types or interfaces for variables and function parameters/return values to improve code quality and maintainability.

Rule source requires an active Pro or Enterprise subscription.
capacitor-insecure-localstorage-sensitive-data error block

Insecure storage of sensitive data detected. Storing authentication tokens, JWTs, passwords, or other secrets directly in localStorage is vulnerable to XSS attacks. Use the Capacitor Secure Storage plugin (e.g., @capacitor-community/secure-storage) for sensitive data that needs to persist securely on the device.

Rule source requires an active Pro or Enterprise subscription.
capacitor-insecure-window-open warning log

Potential insecure use of window.open(). Opening URLs based on untrusted user input (e.g., from event.url or form fields) can lead to phishing attacks or redirection to malicious sites. Always validate and sanitize URLs before opening them, or use a allow-list of trusted domains.

Rule source requires an active Pro or Enterprise subscription.
capacitor-prohibited-eval-function error block

Use of the 'eval()' function is strictly prohibited. 'eval()' executes arbitrary JavaScript code and is a major security risk, often leading to injection vulnerabilities. Refactor your code to use safer alternatives like JSON.parse() for data parsing, or function constructors for dynamic function creation with controlled input.

Rule source requires an active Pro or Enterprise subscription.
capacitor-weak-csp-unsafe-directives error block

Weak Content Security Policy (CSP) detected. The use of 'unsafe-inline' or 'unsafe-eval' in your CSP significantly reduces the security posture of your Capacitor application, making it vulnerable to XSS. Strive to remove these directives by using nonces, hashes, or refactoring code to avoid inline scripts/styles and eval().

Rule source requires an active Pro or Enterprise subscription.
capacitor-xss-innerhtml-risk error block

Potential Cross-Site Scripting (XSS) vulnerability detected. Assigning untrusted user input (e.g., from event.detail.value) directly to innerHTML can lead to arbitrary code execution in the user's browser. Use element.textContent for displaying user-controlled data, or sanitize input rigorously with a library like DOMPurify before using innerHTML.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v2
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
3f6332364bd670d6a861c92ede8239c63f216866d83d6d1abaeffd1b2b5ea31e
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-capacitor/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-capacitor. The published version only bumps when a maintainer resyncs.

No commit history available.