Hub rules-dynamodb

rules-dynamodb

v5 public Verified

Dynamodb

AWS DynamoDB is a fully managed NoSQL database service providing fast and predictable performance. These rules guide AI agents in schema design, partition key selection, and efficient querying for serverless applications.

@sigmashakeinc 2 pulls 5 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-dynamodb →
Severity
2 error 3 warn 0 info
demo.cast
AWS DynamoDB is a fully managed NoSQL database service providing fast and predictable performance. These rules guide AI agents in schema design, partition key selection, and efficient querying for serverless applications.

Rules index

5 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

dynamodb

dynamodb-delete-without-condition warning log

RISK: DeleteItem without a ConditionExpression can silently delete an item that has been modified by a concurrent writer — lost-update and TOCTOU vulnerability. FIX: Add a ConditionExpression (e.g. 'attribute_exists(pk)' or a version/etag check) to make the delete conditional and safe under concurrency.

Rule source requires an active Pro or Enterprise subscription.
dynamodb-expression-attribute-injection error block

RISK: Building a DynamoDB FilterExpression or KeyConditionExpression by string concatenation or interpolation can allow injection of malicious expression syntax, bypassing intended data access controls. FIX: Always use ExpressionAttributeValues with named placeholders (:val) — never interpolate user input directly into expression strings.

Rule source requires an active Pro or Enterprise subscription.
dynamodb-full-scan-warning warning log

DynamoDB Scan reads every item in the table, consuming full provisioned read capacity and incurring cost proportional to table size. For production workloads, prefer Query with a known partition key, or a GSI. If Scan is intentional (e.g. data migration), add a FilterExpression to reduce data transfer.

Rule source requires an active Pro or Enterprise subscription.
dynamodb-hardcoded-aws-credentials error block

RISK: Hardcoded AWS credentials grant full DynamoDB (and potentially account-wide) access — exposure via VCS history is a critical secret leak that has caused major data breaches. FIX: Use IAM roles (EC2/ECS/Lambda instance profiles), AWS SSO, or read from environment variables via the AWS SDK credential chain. Revoke the exposed key immediately via IAM.

Rule source requires an active Pro or Enterprise subscription.
dynamodb-unencrypted-table warning log

RISK: DynamoDB tables without SSESpecification use default AWS-managed encryption at rest. For sensitive data, explicitly configure CMK (KMS) encryption to retain control over key rotation and access. FIX: Set SSESpecification: { Enabled: true, SSEType: 'KMS', KMSMasterKeyId: '<key-id>' }.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
c2fec7b755803e91253a97adf445741990c67c4323fde1cd662fb54a3c0838dc
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-dynamodb/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-dynamodb. The published version only bumps when a maintainer resyncs.

No commit history available.