Hub rules-d

rules-d

v5 public Verified

D

D is a systems programming language combining performance with expressive syntax. These rules assist AI agents in memory management, template metaprogramming, and concurrency using D's unique safety and efficiency features.

@sigmashakeinc 2 pulls 5 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-d →
Severity
2 error 3 warn 0 info
demo.cast
D is a systems programming language combining performance with expressive syntax. These rules assist AI agents in memory management, template metaprogramming, and concurrency using D's unique safety and efficiency features.

Rules index

5 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

d

d-command-injection error block

RISK: Shell-based process APIs (spawnShell, executeShell, pipeShell) pass the command through /bin/sh, enabling command injection if any user-controlled value is concatenated (~) into the command string. FIX: Use execute()/spawnProcess() with an explicit string array of arguments, avoiding shell interpretation entirely.

Rule source requires an active Pro or Enterprise subscription.
d-deprecated-c-stdio warning log

std.c.stdio is a deprecated C stdio binding. Use core.stdc.stdio (D runtime's C interface) or D-native std.stdio instead for type-safe I/O.

Rule source requires an active Pro or Enterprise subscription.
d-system-attribute warning log

RISK: @system code disables D's memory-safety checks (bounds checking, null dereference protection) for that scope. FIX: Prefer @safe/@trusted; if @system is required for C FFI, restrict its scope to a minimal wrapper function and document the invariants.

Rule source requires an active Pro or Enterprise subscription.
d-trusted-without-justification warning log

RISK: @trusted signals to the compiler that the function is safe to call from @safe code, but does NOT enforce memory safety itself — the programmer assumes full responsibility. Misuse is a common source of memory bugs in D. FIX: Add a comment documenting exactly why the code is safe; minimize the @trusted scope to the smallest possible function body.

Rule source requires an active Pro or Enterprise subscription.
d-unsafe-void-cast error block

RISK: cast(void*) removes all type information and bypasses D's type system, leading to undefined behaviour on access or reinterpretation. FIX: Use typed pointers or std.bitmanip for controlled bit-level access; restructure to avoid void* entirely.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
02b7c3b4df44d277bb5f132c5c6d555fcbe3ddf56e9d815957f45f07422d1ceb
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-d/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-d. The published version only bumps when a maintainer resyncs.

No commit history available.