Hub rules-compose-multiplatform

rules-compose-multiplatform

v5 public Verified

Compose Multiplatform

Compose Multiplatform is a declarative UI framework for sharing Kotlin-based UI code across Android, iOS, Desktop, and Web. These rules assist AI agents in building consistent, reactive cross-platform user interfaces.

@sigmashakeinc 2 pulls 6 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-compose-multiplatform →
Severity
2 error 4 warn 0 info
demo.cast
Compose Multiplatform is a declarative UI framework for sharing Kotlin-based UI code across Android, iOS, Desktop, and Web. These rules assist AI agents in building consistent, reactive cross-platform user interfaces.

Rules index

6 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

compose-multiplatform

compose-multiplatform-block-unsafe-patterns warning ask

Potentially unsafe pattern detected in compose-multiplatform code: "Modifier.pointerInput". Review the use case — this may indicate a security risk, a deprecated API, or a misconfiguration. Confirm the write is intentional.

Rule source requires an active Pro or Enterprise subscription.
compose-multiplatform-force-updated-api warning log

DesktopMaterialTheme is deprecated in Compose Multiplatform. Migrate to MaterialTheme (from compose.material3 or compose.material) which works across all Compose targets including Desktop.

Rule source requires an active Pro or Enterprise subscription.
no-compose-multiplatform-cleartext-traffic error block

android:usesCleartextTraffic="true" permits unencrypted HTTP traffic. Cleartext HTTP is vulnerable to eavesdropping and MITM attacks. Remove this attribute or create a network_security_config.xml that restricts cleartext to development/localhost only.

Rule source requires an active Pro or Enterprise subscription.
no-compose-multiplatform-hardcoded-secret error block

Hardcoded secret or API key detected in Kotlin source (CWE-798). Credentials embedded in source code are exposed in version control history and compiled binaries. Use BuildConfig fields injected from local.properties, environment variables, or a secrets manager. Never commit real credentials.

Rule source requires an active Pro or Enterprise subscription.
no-compose-multiplatform-http-url warning log

Plain HTTP URL found in Kotlin source. HTTP connections are unencrypted and susceptible to eavesdropping and MITM injection on mobile/desktop networks. Replace with HTTPS. For local development use http://10.0.2.2 only in debug builds guarded by BuildConfig.DEBUG.

Rule source requires an active Pro or Enterprise subscription.
no-compose-multiplatform-webview-js warning log

WebView JavaScript enabled in Compose Multiplatform. If the WebView loads remote URLs, JavaScript + addJavascriptInterface() creates a path to native code execution. Limit WebView to trusted local assets, set loadUrl only to allowed origins, and avoid addJavascriptInterface unless strictly required.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
f4c7f1e34c30146e65094f992d65f95a5c0fa9255a6ff037421c93944ed58e9c
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-compose-multiplatform/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-compose-multiplatform. The published version only bumps when a maintainer resyncs.

No commit history available.