Hub rules-plandex

rules-plandex

v2 public Verified

Plandex

Community-governed security ruleset for Plandex

@sigmashakeinc 0 pulls 6 rules published Apr 10, 2026 synced Sep 27, 2026 sigmashakeinc/rules/rulesets/rules-plandex →
Severity
4 error 0 warn 2 info
demo.cast
Community-governed security ruleset for Plandex

Rules index

6 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

plandex

log-plandex-external-docs info log

Plandex fetching external documentation or search results. Content fetched from the web can contain prompt injection payloads that redirect plan generation. Review sourced content before incorporating it into the plan.

Rule source requires an active Pro or Enterprise subscription.
log-plandex-large-refactor info log

Plandex initiating a large-scale refactor touching multiple files. Ensure the diff sandbox is enabled and review each file diff before applying.

Rule source requires an active Pro or Enterprise subscription.
no-plandex-hardcoded-secret-write error log

Plandex generating code with a hardcoded secret. AI-generated multi-file plans frequently embed literal credentials across multiple files simultaneously. Use environment variables; never hardcode credentials in generated source.

Rule source requires an active Pro or Enterprise subscription.
no-plandex-production-path error block

Plandex accessing a production path. Autonomous multi-file agents must not operate directly on production artifacts. Scope plans to a non-production branch or sandbox workspace.

Rule source requires an active Pro or Enterprise subscription.
no-plandex-prompt-injection-plan error block

Prompt injection detected in Plandex plan input (CWE-1428). Instructions containing role-override or instruction-ignore markers attempt to redirect the plan at runtime. Reject and resubmit with a sanitized task description.

Rule source requires an active Pro or Enterprise subscription.
no-plandex-sandbox-bypass error ask

Plandex applying changes with the Diff Review Sandbox disabled. Disabling sandbox removes the human-in-the-loop diff review — all multi-file changes land immediately. Re-enable the sandbox for any non-trivial plan.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v2
Published
Apr 10, 2026
Source commits
0
Synced
Sep 27, 2026
Hash
9e7f2a4e74d3e06f85b69067539fd745a49707f4adfeac6521cf75041c9a364e
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-plandex/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-plandex. The published version only bumps when a maintainer resyncs.

No commit history available.