Hub rules-webrtc

rules-webrtc

v4 public Verified

Webrtc

WebRTC is an open-source project that enables real-time communication in web browsers and mobile applications. These rules govern peer connection safety and media handling for AI agents.

@sigmashakeinc 2 pulls 7 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-webrtc →
Severity
3 error 2 warn 2 info
demo.cast
WebRTC is an open-source project that enables real-time communication in web browsers and mobile applications. These rules govern peer connection safety and media handling for AI agents.

Rules index

7 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

webrtc

webrtc-deny-data-channel-eval error block

RISK: Executing eval() on data received from a WebRTC data channel onmessage handler is remote code execution — the remote peer controls the string. FIX: parse messages as structured data (JSON.parse with try/catch) and dispatch based on a validated 'type' field; never pass the raw string to eval or new Function.

Rule source requires an active Pro or Enterprise subscription.
webrtc-deny-hardcoded-turn-credentials error block

RISK: Hardcoded TURN server credentials in RTCPeerConnection iceServers are committed to version control and ship in the client bundle — anyone can extract them to relay arbitrary traffic through your TURN server, causing bandwidth abuse and cost (CWE-798). FIX: fetch short-lived TURN credentials from your server via an authenticated API call immediately before creating the RTCPeerConnection.

Rule source requires an active Pro or Enterprise subscription.
webrtc-deny-insecure-stun-url warning log

ADVISORY: Plain STUN (stun:) leaks the local network topology (LAN IP, NAT type) to the STUN server operator without encryption. For production, use a self-hosted STUN/TURN server or restrict external STUN use; for privacy-sensitive apps consider using a Cloudflare TURN relay that hides the ICE candidates from peers.

Rule source requires an active Pro or Enterprise subscription.
webrtc-deny-trickle-ice-ignored info log

ADVISORY: Waiting for all ICE candidates (null event) before signalling is the 'vanilla ICE' pattern — it adds 1-3 seconds of latency and discloses all local interfaces at once. FIX: use Trickle ICE (send each candidate as it arrives via onicecandidate, call addIceCandidate on the remote side) for faster and more privacy-preserving connection setup.

Rule source requires an active Pro or Enterprise subscription.
webrtc-deny-unvalidated-remote-sdp error block

RISK: Passing a remote SDP directly from a WebSocket message or HTTP request body to setRemoteDescription() without validation allows a malicious peer to inject crafted SDP that triggers browser bugs or leaks the local ICE candidates beyond the intended peers. FIX: validate the SDP object shape (type must be 'offer'/'answer', sdp must be a string) and reject unexpected fields before calling setRemoteDescription.

Rule source requires an active Pro or Enterprise subscription.
webrtc-warn-create-data-channel info log

ADVISORY: WebRTC data channels transmit arbitrary binary/text data peer-to-peer without a server intermediary — ensure messages are validated and sanitised before acting on them, as the remote peer is not necessarily trusted.

Rule source requires an active Pro or Enterprise subscription.
webrtc-warn-legacy-api warning log

webkitRTCPeerConnection is a vendor-prefixed legacy API removed in all modern browsers. FIX: use RTCPeerConnection (unprefixed), which has been the standard API since Chrome 56 / Firefox 22 / Safari 11.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v4
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
f7d26a1287e912f53eafca9ec1950278d7332973c48d5285a5ea7f99fd3a63dc
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-webrtc/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-webrtc. The published version only bumps when a maintainer resyncs.

No commit history available.