Hub rules-cohere

rules-cohere

v2 public Verified

Cohere

Cohere provides enterprise-grade AI models for natural language processing, embeddings, and reranking. These rules govern the integration of Cohere's API for high-performance text generation and semantic search tasks.

@sigmashakeinc 2 pulls 6 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-cohere →
Severity
3 error 3 warn 0 info
demo.cast
Cohere provides enterprise-grade AI models for natural language processing, embeddings, and reranking. These rules govern the integration of Cohere's API for high-performance text generation and semantic search tasks.

Rules index

6 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

cohere

cohere-deprecated-unsafe-generation-api warning log

Generated code uses the deprecated `cohere.generate_code` API with `safety_filters=False`. This bypasses critical security guardrails. Migrate to `cohere.generate_safe_code()` or ensure `safety_filters=True` is explicitly set and justified. This configuration is highly discouraged for production environments.

Rule source requires an active Pro or Enterprise subscription.
cohere-insecure-filesystem-write-config error block

Generated code configures `cohere.CodeGenerationConfig` to `allow_filesystem_write=True`. This grants the AI model broad write access to the filesystem, posing a significant risk for data corruption or malicious file creation. Restrict filesystem access unless absolutely necessary and implement strict sandboxing. Default to `allow_filesystem_write=False`.

Rule source requires an active Pro or Enterprise subscription.
cohere-insecure-shell-execution error block

Generated Python code uses `subprocess.run` with `shell=True` and potentially user-controlled input (e.g., f-strings, variables). This is a critical command injection vulnerability. Always sanitize inputs and avoid `shell=True` for untrusted commands. Prefer `shell=False` and pass commands as a list of arguments.

Rule source requires an active Pro or Enterprise subscription.
cohere-path-traversal-risk-python warning log

Generated Python code constructs file paths using string concatenation (e.g., f-strings) instead of `os.path.join`. This is a common source of path traversal vulnerabilities. Always use `os.path.join()` to safely construct paths, especially when dealing with user-controlled input.

Rule source requires an active Pro or Enterprise subscription.
cohere-python-wildcard-imports-style-security warning log

Generated Python code uses wildcard imports (`from module import *`). While not strictly a vulnerability, this is discouraged by the Cohere recommended style guide for generated code (aligning with PEP 8). It can lead to namespace pollution, make code harder to read, and obscure the origin of functions, potentially hiding malicious imports. Prefer explicit imports (e.g., `from module import func1, func2`).

Rule source requires an active Pro or Enterprise subscription.
cohere-sensitive-api-key-leakage error block

Generated code appears to embed a Cohere API key directly. This is a severe security risk. API keys should be loaded from environment variables, secure vaults, or configuration management, never hardcoded. Remove the hardcoded key immediately.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v2
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
75411e26fd185357bbf272ecce6421b4a35043a61a2498719f33307b4393e21c
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-cohere/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-cohere. The published version only bumps when a maintainer resyncs.

No commit history available.