Hub rules-clojure

rules-clojure

v5 public Verified

Clojure

Clojure is a dynamic, general-purpose functional programming language. These rules govern functional patterns, concurrency, and REPL-driven development for AI-assisted Clojure.

@sigmashakeinc 2 pulls 8 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-clojure →
Severity
6 error 2 warn 0 info
demo.cast
Clojure is a dynamic, general-purpose functional programming language. These rules govern functional patterns, concurrency, and REPL-driven development for AI-assisted Clojure.

Rules index

8 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

clojure

clojure-command-injection-sh-string-concat error block

Potential Command Injection: Detected string concatenation for commands passed to clojure.java.shell/sh. This is highly vulnerable to command injection if user input is involved. Always pass commands and arguments as a vector (e.g., `(sh ["ls" "-l" user-input])`) to prevent shell metacharacter interpretation and ensure arguments are treated as literal values.

Rule source requires an active Pro or Enterprise subscription.
clojure-discourage-legacy-jdbc warning log

Discouraged Legacy Database Library: Detected usage of `clojure.java.jdbc` without `next.jdbc` also being present. While functional, `next.jdbc` is the modern, recommended library for Clojure database access, offering improved performance, better security features (e.g., built-in parameterization), and a more idiomatic API. Consider using `next.jdbc` for new database interactions to leverage these benefits and reduce potential pitfalls associated with older libraries.

Rule source requires an active Pro or Enterprise subscription.
clojure-insecure-clj-http-config warning log

Insecure HTTP Client Configuration: Detected `clj-http.client` call with `:insecure? true`. This disables SSL/TLS certificate validation, making the application vulnerable to Man-in-the-Middle (MITM) attacks by allowing connections to servers with invalid or self-signed certificates. Ensure SSL/TLS verification is enabled for production environments. Remove `:insecure? true` or set it to `false`.

Rule source requires an active Pro or Enterprise subscription.
clojure-java-object-deserialization error block

Unsafe Java deserialization via ObjectInputStream detected (CWE-502). Java object deserialization of untrusted data is a critical RCE vector — CVE-2015-4852 (Apache Commons Collections) and many follow-on gadget chains allow arbitrary code execution. Never deserialize data from untrusted sources with the default Java deserializer. Use JSON/EDN/Transit with explicit schemas, or if Java serialization is unavoidable, apply a serialization filter (ObjectInputFilter, Java 9+) that allowlists expected types.

Rule source requires an active Pro or Enterprise subscription.
clojure-path-traversal-file-string-concat error block

Potential Path Traversal: Detected string concatenation for file paths passed to `java.io.File.` constructor. This can lead to path traversal vulnerabilities if user input is involved, allowing access to arbitrary files on the system. Sanitize and validate all path components, use `java.nio.file.Path` with proper resolution, and canonicalize paths (e.g., `.getCanonicalPath()`) to restrict file access to intended directories.

Rule source requires an active Pro or Enterprise subscription.
clojure-sql-injection-string-concat error block

Potential SQL Injection: Detected string concatenation for SQL queries passed to clojure.java.jdbc/query or next.jdbc/execute!. This is highly vulnerable to SQL injection if user input is involved. Always use parameterized queries (e.g., `(jdbc/query db-spec ["SELECT * FROM users WHERE name = ?" user-input])` or `(next.jdbc/execute! ds ["SELECT * FROM users WHERE name = ?" user-input])`) to prevent malicious input from altering query logic.

Rule source requires an active Pro or Enterprise subscription.
clojure-unsafe-read-string-eval-load-string error block

Critical Code Execution Vulnerability: Detected usage of `read-string`, `eval`, or `load-string`. These functions can execute arbitrary Clojure code and are extremely dangerous if used with untrusted input, leading to Remote Code Execution (RCE). For reading data, use `clojure.edn/read-string` which is a safer alternative for EDN data. Avoid `eval` and `load-string` in production code, especially when processing dynamic or untrusted input.

Rule source requires an active Pro or Enterprise subscription.
clojure-xml-external-entity error block

Potential XML External Entity (XXE) injection (CWE-611). Clojure's `clojure.xml/parse` and bare `DocumentBuilderFactory` instances process external entities by default, allowing attackers to read local files or trigger SSRF. Use data.xml with external entity expansion disabled, or configure the SAX/DOM parser with setFeature("http://xml.org/sax/features/external-general-entities", false). See OWASP XXE Prevention Cheat Sheet.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
13618f2cfbd7bbb0f8e9fd8f9c172ed5919d103830a847861f010bb8c369301c
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-clojure/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-clojure. The published version only bumps when a maintainer resyncs.

No commit history available.