Hub rules-crystal

rules-crystal

v5 public Verified

Crystal

Crystal is a type-safe, compiled language with Ruby-like syntax designed for performance. These rules assist AI agents in type inference, concurrency using fibers, and high-performance systems development.

@sigmashakeinc 2 pulls 8 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-crystal →
Severity
4 error 3 warn 1 info
demo.cast
Crystal is a type-safe, compiled language with Ruby-like syntax designed for performance. These rules assist AI agents in type inference, concurrency using fibers, and high-performance systems development.

Rules index

8 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

crystal

crystal-block-unsafe-patterns warning ask

Pointer(Void) — untyped raw pointer in Crystal. This bypasses the type system and is required only for low-level C FFI. Confirm this is intentional FFI code and document the memory ownership contract.

Rule source requires an active Pro or Enterprise subscription.
crystal-force-updated-api info log

HTTP::Server.new usage detected. Ensure you are using the current Crystal HTTP::Server API (handlers array), as the single-handler constructor form was changed in older versions. Check Crystal release notes for your target version.

Rule source requires an active Pro or Enterprise subscription.
no-crystal-hardcoded-secret error block

Hardcoded secret or API key in Crystal source (CWE-798). Secrets committed to source are exposed via version control. Use ENV["SECRET_KEY"] or a crystal-env / dotenv library. For production, inject secrets via environment variables at deploy time.

Rule source requires an active Pro or Enterprise subscription.
no-crystal-insecure-tls error block

TLS certificate verification disabled in Crystal (CWE-295). Setting verify_mode to NONE allows MITM attacks — the client accepts any certificate including self-signed ones from attackers. Remove this setting or use verify_mode = OpenSSL::SSL::VerifyMode::PEER with a valid CA bundle.

Rule source requires an active Pro or Enterprise subscription.
no-crystal-path-traversal warning log

Path traversal risk in Crystal: File.read/write/open with externally controlled path (CWE-22). User-supplied filenames with '../' sequences can escape the intended directory. Validate paths with File.expand_path and assert they start with the allowed base directory before opening.

Rule source requires an active Pro or Enterprise subscription.
no-crystal-system-command-injection error block

Command injection risk in Crystal: Process.run or backtick interpolation with user-controlled data (CWE-78). Crystal string interpolation in shell commands allows injection of arbitrary shell commands. Use Process.run with an args array (Process.run("cmd", args: [arg1, arg2])) and never pass shell: true with interpolated data.

Rule source requires an active Pro or Enterprise subscription.
no-crystal-unsafe-pointer error block

Raw pointer operation detected in Crystal. Crystal's Pointer(T) and pointerof() bypass the type system and garbage collector — use-after-free and memory corruption are possible. Wrap all FFI operations in safe Crystal abstractions using lib/LibC bindings with explicit lifetime management.

Rule source requires an active Pro or Enterprise subscription.
no-crystal-yaml-load-unsafe warning log

YAML.parse() called with external input. Crystal's YAML.parse returns a recursive Any tree — untrusted YAML with deeply nested/aliased structures (YAML Bomb, CVE-2013-4164-class) can cause excessive memory allocation. Use YAML.parse on trusted data only; deserialize into typed structs with T.from_yaml(input) to fail fast on unexpected shapes.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
3235ae9d7f53e828ba511f90a8a274ee7ecaf7616722a28c24f1f77e8c8c3f92
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-crystal/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-crystal. The published version only bumps when a maintainer resyncs.

No commit history available.