Hub rules-xgboost

rules-xgboost

v4 public Verified

Xgboost

XGBoost is an optimized distributed gradient boosting library designed to be highly efficient, flexible and portable. These rules govern model parameter safety and data handling for AI agents.

@sigmashakeinc 2 pulls 5 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-xgboost →
Severity
2 error 3 warn 0 info
demo.cast
XGBoost is an optimized distributed gradient boosting library designed to be highly efficient, flexible and portable. These rules govern model parameter safety and data handling for AI agents.

Rules index

5 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

xgboost

xgboost-no-eval-custom-objective warning log

Passing an eval()/exec() expression as a custom XGBoost objective or metric function is a code-injection risk (CWE-95). Define the objective/metric as a proper Python function and pass the function reference directly.

Rule source requires an active Pro or Enterprise subscription.
xgboost-no-joblib-load error block

joblib.load() deserialises Python objects and is equivalent to pickle — it can execute arbitrary code when loading an untrusted XGBoost model (CWE-502). Use bst.load_model('model.ubj') for safe binary-JSON deserialisation.

Rule source requires an active Pro or Enterprise subscription.
xgboost-no-nthread-minus-one warning log

nthread=-1 tells XGBoost to use ALL logical CPU cores. On shared or power-capped machines this saturates the CPU, starves other processes, and (on some PSU-limited workstations) risks an overcurrent trip. Set nthread to an explicit positive value appropriate for the environment.

Rule source requires an active Pro or Enterprise subscription.
xgboost-no-pickle-load error block

pickle.load() on an XGBoost model (or any model artefact) is an RCE vector — a crafted pickle executes arbitrary Python on load (CWE-502). Replace with bst.load_model('model.ubj') (binary JSON, safe) or bst.load_model('model.json'). Never load untrusted pickle files.

Rule source requires an active Pro or Enterprise subscription.
xgboost-warn-load-model-path warning log

XGBoost load_model() detected. Verify the model path is from a trusted, integrity-verified source. Loading a model from an attacker-controlled path or a tampered artefact can corrupt predictions or, with native-lib callbacks, escalate to code execution. Prefer storing model SHA-256 alongside the artefact and verifying before load.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v4
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
82fd3d4b6fbcd59ac663d2c04b68fe860fe5fbed92d4f496c9d65781804a54f5
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-xgboost/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-xgboost. The published version only bumps when a maintainer resyncs.

No commit history available.