Hub rules-windsurf

rules-windsurf

v3 public Verified

Windsurf

Community-governed security ruleset for Windsurf

@sigmashakeinc 0 pulls 6 rules published Apr 10, 2026 synced Sep 27, 2026 sigmashakeinc/rules/rulesets/rules-windsurf →
Severity
4 error 1 warn 1 info
demo.cast
Community-governed security ruleset for Windsurf

Rules index

6 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

windsurf

audit-cascade-activation info log

Windsurf 'Cascade' persistent agent activated. It will monitor terminal commands and file edits.

Rule source requires an active Pro or Enterprise subscription.
audit-skill-modification warning log

RISK: Agent is attempting to modify Windsurf 'Skills' or config. This could weaken security constraints or expand the agent's permitted capabilities. FIX: review all skill/config changes before approving.

Rule source requires an active Pro or Enterprise subscription.
block-cascade-monitoring-sensitive error block

RISK: Blocked 'Cascade' from monitoring sensitive directories like .ssh or .env. Monitoring these paths could expose SSH keys or credentials to the agent context. FIX: restrict watch paths to project source directories only.

Rule source requires an active Pro or Enterprise subscription.
deny-cascade-memory-secret-write error block

RISK: Windsurf Memories files persist across sessions — writing a secret into a memory file commits it to long-term Cascade context storage where it may be logged, synced, or surfaced in unrelated conversations. FIX: never store secrets in .windsurf/memories; reference secrets only via environment variables or a secrets manager at runtime.

Rule source requires an active Pro or Enterprise subscription.
deny-cascade-tool-override error block

RISK: Enabling allowDangerousCommands / disableToolChecks / skipApproval in the Windsurf config removes the human-in-the-loop approval step for file writes and shell commands — the agent can execute destructive operations without confirmation. FIX: keep all approval gates enabled; use scoped allow-lists for specific safe commands rather than a blanket bypass.

Rule source requires an active Pro or Enterprise subscription.
deny-windsurfrules-prompt-injection error block

RISK: The .windsurfrules file contains prompt-injection language ('ignore previous instructions', 'act as', 'you are now') that attempts to override Cascade's system constraints from within a project file. FIX: .windsurfrules must contain only legitimate coding guidelines; remove injected persona or override directives.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v3
Published
Apr 10, 2026
Source commits
0
Synced
Sep 27, 2026
Hash
caed75476024fab6f0c3fbad6be8c995a387610ad1a3cdf3754c83458bb83dd5
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-windsurf/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-windsurf. The published version only bumps when a maintainer resyncs.

No commit history available.