Hub rules-erlang

rules-erlang

v5 public Verified

Erlang

Erlang is a functional language used for massively scalable systems with high availability. These rules guide AI agents in process isolation, message passing, and hot code reloading within the OTP framework.

@sigmashakeinc 2 pulls 7 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-erlang →
Severity
6 error 1 warn 0 info
demo.cast
Erlang is a functional language used for massively scalable systems with high availability. These rules guide AI agents in process isolation, message passing, and hot code reloading within the OTP framework.

Rules index

7 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

erlang

erlang-atom-exhaustion error block

Unchecked list_to_atom/binary_to_atom — CWE-400 (resource exhaustion). Erlang's atom table is limited (~1M atoms by default) and atoms are never garbage-collected. Creating atoms from untrusted input can exhaust the table and crash the VM. Use list_to_existing_atom/binary_to_existing_atom (which fails on unknown atoms) or keep values as binaries.

Rule source requires an active Pro or Enterprise subscription.
erlang-dynamic-code-load error block

Dynamic module loading via code:load_binary/load_file — CWE-829. Loading beam bytecode from a remote or user-controlled source lets an attacker inject arbitrary code into the running VM. Only load modules from trusted, integrity-verified paths.

Rule source requires an active Pro or Enterprise subscription.
erlang-eval-dynamic-code error block

erl_eval evaluates arbitrary Erlang expressions at runtime — CWE-94. If user-controlled input reaches erl_eval, an attacker can execute any Erlang code including spawn, os:cmd, and file operations. Never pass untrusted input to the evaluator; use a restricted DSL or safe data transformations instead.

Rule source requires an active Pro or Enterprise subscription.
erlang-insecure-cookie error block

Hardcoded weak Erlang distribution cookie — CWE-798. The distribution cookie is the only authentication mechanism for EPMD/distributed Erlang; a guessable cookie lets any node on the network connect and execute arbitrary code with full VM access. Set a strong random cookie via environment variable injection or a secrets manager.

Rule source requires an active Pro or Enterprise subscription.
erlang-obsolete-now warning log

erlang:now/0 is deprecated since OTP 18 (returns monotonically adjusted timestamps that can block the runtime). Use os:system_time/1, erlang:monotonic_time/1, or erlang:timestamp/0 depending on whether you need wall-clock time, monotonic time, or Erlang-compatible timestamps.

Rule source requires an active Pro or Enterprise subscription.
erlang-os-cmd-injection error block

os:cmd/1 passes a string to the shell and is vulnerable to command injection — CWE-78. Any unsanitized input passed to os:cmd can execute arbitrary OS commands. Use erlexec or a port with explicit argument lists instead of a shell string. If os:cmd is unavoidable, validate input against a strict allowlist.

Rule source requires an active Pro or Enterprise subscription.
erlang-tls-verify-none error block

TLS peer verification is disabled — CWE-297. '{verify, verify_none}' in ssl:connect/ssl:listen options means the server certificate is never checked, making TLS trivially bypassable by a MITM attacker. Use '{verify, verify_peer}' with a CA certificate bundle.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
597fa92dbd388be08e49e7ad1a584706b8103b5193d112134f1e1538d82784d8
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-erlang/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-erlang. The published version only bumps when a maintainer resyncs.

No commit history available.