Hub rules-webgl

rules-webgl

v4 public Verified

Webgl

WebGL is a JavaScript API for rendering high-performance interactive 3D and 2D graphics. These rules govern shader safety and resource management for AI agents.

@sigmashakeinc 2 pulls 6 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-webgl →
Severity
3 error 2 warn 1 info
demo.cast
WebGL is a JavaScript API for rendering high-performance interactive 3D and 2D graphics. These rules govern shader safety and resource management for AI agents.

Rules index

6 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

webgl

webgl-block-unsafe-patterns warning ask

RISK: eval() in WebGL code executes arbitrary JavaScript strings. If the string is derived from shader source, URL params, or remote data it becomes a code-injection vector. FIX: compile shaders from static string literals or template tags and never pass user input to eval().

Rule source requires an active Pro or Enterprise subscription.
webgl-deny-readpixels-data-send error block

RISK: Reading pixel data with gl.readPixels() and immediately sending it to an external endpoint is a canvas fingerprinting or webcam-frame exfiltration pattern. FIX: ensure readPixels is used only for local in-app rendering (e.g. screenshot, color pick) and never wired directly to a network call that sends the buffer off-device.

Rule source requires an active Pro or Enterprise subscription.
webgl-deny-sensitive-extension-query warning log

RISK: WEBGL_debug_renderer_info exposes the GPU vendor and renderer string — a high-entropy fingerprinting signal browsers restrict post-2019 privacy changes. EXT_disjoint_timer_query enables high-resolution GPU timing side-channels used to fingerprint and de-anonymise users. FIX: remove both extensions from production; use performance.now() for profiling in development only.

Rule source requires an active Pro or Enterprise subscription.
webgl-deny-shader-source-from-input error block

RISK: Passing user-controlled strings to gl.shaderSource() and compiling them executes attacker-controlled GPU code — potential driver crashes, DoS, and on some drivers information disclosure via shader side-channels. FIX: keep all GLSL source as static literals or import from .glsl files checked into the repo; never interpolate user data.

Rule source requires an active Pro or Enterprise subscription.
webgl-deny-unsafe-eval-csp error block

RISK: `unsafe-eval` in a Content-Security-Policy allows eval(), new Function(), and inline event handlers in the same page that runs WebGL — it neutralises the XSS defence that CSP provides (CWE-693). FIX: compile shaders at build time and remove unsafe-eval; if a library requires it, consider a compile-time WASM build instead.

Rule source requires an active Pro or Enterprise subscription.
webgl-warn-lost-context-unhandled info log

ADVISORY: WebGL contexts can be lost due to GPU reset or resource pressure. Without a 'webglcontextlost' listener and context-restore path the page silently goes blank. FIX: listen for 'webglcontextlost' (call event.preventDefault()) and 'webglcontextrestored' to reinitialise buffers and programs.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v4
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
c1e7d532d46625657a68ee423bedbc1d0e6ea3081f2560d6772511ae87312a21
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-webgl/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-webgl. The published version only bumps when a maintainer resyncs.

No commit history available.