Hub rules-xamarin

rules-xamarin

v4 public Verified

Xamarin

Xamarin is an open-source platform for building modern and performant applications for iOS, Android, and Windows with .NET. These rules govern native interop and application security for AI agents.

@sigmashakeinc 2 pulls 8 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-xamarin →
Severity
6 error 2 warn 0 info
demo.cast
Xamarin is an open-source platform for building modern and performant applications for iOS, Android, and Windows with .NET. These rules govern native interop and application security for AI agents.

Rules index

8 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

xamarin

xamarin-block-unsafe-patterns warning ask

RISK: Java.Interop bypasses Xamarin.Android's managed memory model — incorrect JNI references can cause native crashes or memory corruption. FIX: prefer Xamarin.Android's typed binding classes over raw JNI; if JNI is required, document the globalref/localref lifecycle carefully.

Rule source requires an active Pro or Enterprise subscription.
xamarin-deny-allow-all-certificates error block

RISK: Accepting all TLS certificates disables server identity verification — any self-signed or expired certificate passes, enabling man-in-the-middle attacks on every HTTPS call from the app (CWE-295). FIX: implement proper certificate pinning via ServicePointManager or use a custom X509Chain validator that checks against a pinned leaf/CA hash.

Rule source requires an active Pro or Enterprise subscription.
xamarin-deny-cleartext-traffic error block

RISK: Enabling cleartext (HTTP) traffic in the Android network security config transmits all data unencrypted — credentials, session tokens, and PII are visible on the network (CWE-319). FIX: disable cleartext globally; if a specific legacy endpoint requires HTTP, list only that domain in <domain-config> with an expiry plan to migrate to HTTPS.

Rule source requires an active Pro or Enterprise subscription.
xamarin-deny-debuggable-release error block

RISK: android:debuggable=true in the Android manifest enables USB debugging on release builds — attackers with physical or ADB access can attach a debugger, dump memory, and extract credentials at runtime (CWE-489). FIX: remove the attribute from the manifest; the Xamarin/MAUI Debug configuration sets it automatically for debug builds only.

Rule source requires an active Pro or Enterprise subscription.
xamarin-deny-hardcoded-secret error block

RISK: Hardcoded credentials in Xamarin C#/XAML source are committed to version control and embedded in the compiled APK/IPA — they can be extracted by decompiling the app with dotPeek or jadx (CWE-798). FIX: read secrets from secure platform storage (Android Keystore / iOS Keychain via Xamarin.Essentials SecureStorage), not from code.

Rule source requires an active Pro or Enterprise subscription.
xamarin-deny-insecure-local-storage error block

RISK: Storing sensitive values (passwords, tokens, API keys) in Xamarin.Essentials Preferences or Application.Current.Properties writes them to SharedPreferences (Android) or NSUserDefaults (iOS) — both are accessible to other apps on rooted/jailbroken devices and backed up by default. FIX: use SecureStorage.SetAsync() which stores values in the platform secure enclave (Android Keystore / iOS Keychain).

Rule source requires an active Pro or Enterprise subscription.
xamarin-deny-sqlite-string-concat error block

RISK: Constructing SQLite queries by string concatenation ("SELECT * FROM t WHERE id = " + userId) is SQL injection (CWE-89) — any user-controlled value can terminate the query and append arbitrary SQL. FIX: use parameterized queries with SQLiteCommand.Parameters.AddWithValue('@id', userId) or the SQLite-net ORM's LINQ queries.

Rule source requires an active Pro or Enterprise subscription.
xamarin-warn-deprecated-forms-init warning log

Xamarin.Forms.Init() is the Xamarin.Forms 2/3/4/5 bootstrapper. Xamarin.Forms reached end-of-life in May 2024. FIX: migrate to .NET MAUI (MauiApp.CreateBuilder / MAUI handlers) which receives ongoing security updates.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v4
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
0e04299a1eebfa68de14d02b8b9ee39bfe744aa55fcfa3484b0cc8a8aabf1088
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-xamarin/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-xamarin. The published version only bumps when a maintainer resyncs.

No commit history available.