[
  {
    "id": "SEC001",
    "name": "Hardcoded API Key",
    "type": "hardcoded_secret",
    "pattern": "['\"](?:sk-|sk_(?:live|test)_|pk-|pk_(?:live|test)_|xox[pboa]-|AKIA|ghp_|gho_|github_pat_)[a-zA-Z0-9_-]{10,}['\"]|['\"][a-zA-Z0-9]{32,}['\"]",
    "flags": "",
    "severity": "critical",
    "message": "Possible hardcoded API key or secret detected",
    "context": "(api[_-]?key|apikey|secret[_\\s]*key|token|credential|bearer)",
    "contextFlags": "i",
    "skipIfSafe": true,
    "owasp": "A02:2021 Cryptographic Failures",
    "cwe": "CWE-798"
  },
  {
    "id": "SEC001B",
    "name": "Hardcoded API Key (bare)",
    "type": "hardcoded_secret",
    "pattern": "['\"](?:sk-|sk_(?:live|test)_|pk-|pk_(?:live|test)_|xox[pboa]-|AKIA|ghp_|gho_|github_pat_)[a-zA-Z0-9_-]{10,}['\"]",
    "flags": "",
    "severity": "critical",
    "message": "Possible hardcoded API key or secret detected",
    "skipIfSafe": true,
    "owasp": "A02:2021 Cryptographic Failures",
    "cwe": "CWE-798"
  },
  {
    "id": "SEC002",
    "name": "Hardcoded Password",
    "type": "hardcoded_secret",
    "pattern": "password\\s*[:=]\\s*['\"][^'\"]+['\"]",
    "flags": "i",
    "severity": "critical",
    "message": "Hardcoded password detected",
    "skipIfSafe": true,
    "skipInTests": true,
    "owasp": "A02:2021 Cryptographic Failures",
    "cwe": "CWE-798"
  },
  {
    "id": "SEC002B",
    "name": "Hardcoded Password (JSON key)",
    "type": "hardcoded_secret",
    "pattern": "[\"']password[\"']\\s*:\\s*[\"'][^\"']+[\"']",
    "flags": "i",
    "severity": "critical",
    "message": "Hardcoded password detected",
    "skipIfSafe": true,
    "skipInTests": true,
    "owasp": "A02:2021 Cryptographic Failures",
    "cwe": "CWE-798"
  },
  {
    "id": "SEC003",
    "name": "SQL Injection Risk",
    "type": "sql_injection",
    "pattern": "\\b(?:SELECT|INSERT\\s+INTO|UPDATE|DELETE\\s+FROM|WHERE)\\b.*(\\$\\{|#\\{|\\+\\s*['\"]|\\+\\s*\\w+|f['\"].*\\{|%s|%d)",
    "flags": "i",
    "severity": "error",
    "message": "Potential SQL injection - use parameterized queries",
    "owasp": "A03:2021 Injection",
    "cwe": "CWE-89"
  },
  {
    "id": "SEC004",
    "name": "eval() Usage",
    "type": "eval_abuse",
    "pattern": "\\beval\\s*\\(\\s*[^\\s)]",
    "flags": "",
    "severity": "error",
    "message": "eval() is dangerous and should be avoided",
    "owasp": "A03:2021 Injection",
    "cwe": "CWE-95"
  },
  {
    "id": "SEC004B",
    "name": "eval() Usage (unicode-escaped)",
    "type": "eval_abuse",
    "pattern": "\\\\u0065\\\\u0076\\\\u0061\\\\u006[cC]",
    "flags": "",
    "severity": "error",
    "message": "Obfuscated eval() usage (unicode escapes) is dangerous and should be avoided",
    "owasp": "A03:2021 Injection",
    "cwe": "CWE-95"
  },
  {
    "id": "SEC005",
    "name": "innerHTML/document.write Assignment",
    "type": "xss",
    "pattern": "\\.innerHTML\\s*=|\\bdocument\\.write\\s*\\(",
    "flags": "",
    "severity": "warning",
    "message": "innerHTML/document.write can cause XSS - consider using textContent or sanitization",
    "owasp": "A03:2021 Injection",
    "cwe": "CWE-79"
  },
  {
    "id": "SEC006",
    "name": "Disabled Security",
    "type": "insecure_config",
    "pattern": "rejectUnauthorized\\s*:\\s*false|verify\\s*=\\s*False|InsecureSkipVerify\\s*:\\s*true",
    "flags": "",
    "severity": "error",
    "message": "SSL certificate validation disabled",
    "owasp": "A02:2021 Cryptographic Failures",
    "cwe": "CWE-295"
  },
  {
    "id": "SEC007",
    "name": "Exposed .env Reference",
    "type": "insecure_config",
    "pattern": "\\.env['\"]",
    "flags": "",
    "severity": "warning",
    "message": "Direct .env file manipulation - ensure not exposed",
    "context": "fs\\.(read|write)|path\\.join|open\\s*\\(|os\\.Open",
    "contextFlags": "i",
    "owasp": "A05:2021 Security Misconfiguration",
    "cwe": "CWE-538"
  },
  {
    "id": "SEC008",
    "name": "Unsafe Block (Rust)",
    "type": "memory_safety",
    "pattern": "\\bunsafe\\s*\\{",
    "flags": "",
    "severity": "warning",
    "message": "Rust unsafe block - verify memory safety guarantees",
    "owasp": "A06:2021 Vulnerable and Outdated Components",
    "cwe": "CWE-787"
  },
  {
    "id": "SEC009",
    "name": "Shell Execution (PHP/Ruby/Python)",
    "type": "command_injection",
    "pattern": "\\bshell_exec\\s*\\(|\\bpassthru\\s*\\(|\\bos\\.system\\s*\\(|\\bos\\.popen\\s*\\(|\\bsubprocess\\.(?:call|run|Popen|check_output)\\s*\\([^)]*shell\\s*=\\s*True|\\bexec\\s*\\(\\s*[\"']|\\bsystem\\s*\\(\\s*[\"']",
    "flags": "",
    "severity": "error",
    "message": "Shell/OS execution function — command injection risk if input unsanitized",
    "excludeExtensions": [".js", ".ts", ".jsx", ".tsx", ".mjs", ".cjs"],
    "owasp": "A03:2021 Injection",
    "cwe": "CWE-78"
  },
  {
    "id": "SEC010",
    "name": "Prototype Pollution",
    "type": "prototype_pollution",
    "pattern": "\\[\\s*['\"]__proto__['\"]\\s*\\]|\\.__proto__\\s*(=|\\[)|constructor\\s*\\[\\s*['\"]prototype['\"]\\s*\\]|constructor\\.prototype\\s*(=|\\[)|['\"]__proto__['\"]\\s*:",
    "flags": "",
    "severity": "error",
    "message": "Possible prototype pollution via __proto__/constructor.prototype",
    "owasp": "A03:2021 Injection",
    "cwe": "CWE-1321"
  },
  {
    "id": "SEC011",
    "name": "PHP SQL Injection (dot concatenation)",
    "type": "sql_injection",
    "pattern": "\"SELECT[^\"]*WHERE[^\"]*\"\\s*\\.\\s*\\$[a-zA-Z_]|\"UPDATE[^\"]*SET[^\"]*\"\\s*\\.\\s*\\$[a-zA-Z_]|\"DELETE[^\"]*WHERE[^\"]*\"\\s*\\.\\s*\\$[a-zA-Z_]|\\$(?:query|sql|qry)\\s*\\.=\\s*\\$(?:_GET|_POST|_REQUEST|_COOKIE)",
    "flags": "i",
    "severity": "critical",
    "message": "PHP SQL injection: user input concatenated into SQL query with dot operator — use PDO prepared statements",
    "owasp": "A03:2021 Injection",
    "cwe": "CWE-89"
  },
  {
    "id": "SEC012",
    "name": "PHP XSS (echo with user input)",
    "type": "xss",
    "pattern": "echo\\s+(?!htmlspecialchars|htmlentities|strip_tags|esc_html).*\\$(?:_GET|_POST|_REQUEST|_COOKIE)|echo\\s+[\"'][^\"']*[\"']\\s*\\.\\s*\\$(?:_GET|_POST|_REQUEST|_COOKIE)|print\\s+\\$(?:_GET|_POST|_REQUEST|_COOKIE)",
    "flags": "i",
    "severity": "error",
    "message": "PHP XSS: unescaped user input echoed to page — use htmlspecialchars()",
    "owasp": "A03:2021 Injection",
    "cwe": "CWE-79"
  },
  {
    "id": "SEC013",
    "name": "Hardcoded JWT Token",
    "type": "hardcoded_secret",
    "pattern": "['\"]eyJ[A-Za-z0-9_-]{20,}\\.[A-Za-z0-9_-]{20,}\\.[A-Za-z0-9_-]{20,}['\"]",
    "flags": "",
    "severity": "critical",
    "message": "Hardcoded JWT token detected — rotate immediately and use environment variables",
    "skipIfSafe": true,
    "skipInTests": true,
    "owasp": "A02:2021 Cryptographic Failures",
    "cwe": "CWE-798"
  },
  {
    "id": "SEC014",
    "name": "Hardcoded PEM Private Key",
    "type": "hardcoded_secret",
    "pattern": "-----BEGIN (?:RSA |EC )?PRIVATE KEY-----",
    "flags": "",
    "severity": "critical",
    "message": "Private key embedded in source code — move to secure key store or environment variable",
    "owasp": "A02:2021 Cryptographic Failures",
    "cwe": "CWE-321"
  },
  {
    "id": "SEC015",
    "name": "Hardcoded AWS Secret Access Key",
    "type": "hardcoded_secret",
    "pattern": "(?:aws_secret_access_key|AWS_SECRET_ACCESS_KEY|SecretAccessKey)\\s*[:=]\\s*['\"][A-Za-z0-9/+=]{40}['\"]",
    "flags": "",
    "severity": "critical",
    "message": "AWS Secret Access Key hardcoded — use IAM roles or environment variables",
    "skipIfSafe": true,
    "owasp": "A02:2021 Cryptographic Failures",
    "cwe": "CWE-798"
  },
  {
    "id": "SEC016",
    "name": "Rust Hardcoded Secret (const &str)",
    "type": "hardcoded_secret",
    "pattern": "const\\s+(?:PASSWORD|SECRET|API_KEY|TOKEN|PRIVATE_KEY|DB_PASS)\\s*:\\s*&str\\s*=\\s*\"[^\"]+\"",
    "flags": "i",
    "severity": "critical",
    "message": "Hardcoded secret in Rust const — use environment variables at runtime",
    "skipInTests": true,
    "owasp": "A02:2021 Cryptographic Failures",
    "cwe": "CWE-798"
  },
  {
    "id": "SEC017",
    "name": "Rust format! SQL Injection",
    "type": "sql_injection",
    "pattern": "format!\\s*\\(\\s*\"(?:SELECT|INSERT|UPDATE|DELETE|WHERE)[^\"]*\\{",
    "flags": "i",
    "severity": "error",
    "message": "SQL query built with format!() macro — use parameterized queries (sqlx::query! or bind)",
    "owasp": "A03:2021 Injection",
    "cwe": "CWE-89"
  },
  {
    "id": "SEC018",
    "name": "Ruby String Interpolation XSS/Injection",
    "type": "xss",
    "pattern": "[\"'](?:SELECT|INSERT|UPDATE|DELETE|WHERE|<)[^\"']*#\\{[^}]*(?:params|request|input|user|cookies|session)[^}]*\\}",
    "flags": "i",
    "severity": "error",
    "message": "User input interpolated via Ruby #{} into SQL/HTML — use parameterized queries or sanitize",
    "owasp": "A03:2021 Injection",
    "cwe": "CWE-89"
  },
  {
    "id": "SEC019",
    "name": "Go format SQL Injection",
    "type": "sql_injection",
    "pattern": "fmt\\.Sprintf\\s*\\(\\s*\"(?:SELECT|INSERT|UPDATE|DELETE|WHERE)[^\"]*%[sv]",
    "flags": "i",
    "severity": "error",
    "message": "SQL query built with fmt.Sprintf — use parameterized queries (db.Query with $1/? placeholders)",
    "owasp": "A03:2021 Injection",
    "cwe": "CWE-89"
  },
  {
    "id": "RUST001",
    "name": "Rust Deprecated API (mem::uninitialized)",
    "type": "deprecated_api",
    "pattern": "mem::uninitialized\\s*\\(|MaybeUninit::uninit\\(\\)\\.assume_init\\(\\)",
    "flags": "",
    "severity": "error",
    "message": "mem::uninitialized is UB since Rust 1.39 — use MaybeUninit::zeroed() or MaybeUninit with proper init",
    "owasp": "A06:2021 Vulnerable and Outdated Components",
    "cwe": "CWE-908"
  },
  {
    "id": "RUST002",
    "name": "Rust Deprecated trim_left/trim_right",
    "type": "deprecated_api",
    "pattern": "\\.trim_left\\(\\)|\\.trim_right\\(\\)|\\.trim_left_matches\\(|\\.trim_right_matches\\(",
    "flags": "",
    "severity": "warning",
    "message": "trim_left/trim_right deprecated since Rust 1.33 — use trim_start/trim_end",
    "owasp": "A06:2021 Vulnerable and Outdated Components",
    "cwe": "CWE-477"
  },
  {
    "id": "SEC020",
    "name": "C# String Interpolation SQL Injection",
    "type": "sql_injection",
    "pattern": "\\$\"[^\"]*(?:SELECT|INSERT|UPDATE|DELETE|WHERE)[^\"]*\\{",
    "flags": "i",
    "severity": "error",
    "message": "SQL query built with C# string interpolation — use parameterized queries (SqlCommand.Parameters)",
    "owasp": "A03:2021 Injection",
    "cwe": "CWE-89"
  },
  {
    "id": "SEC021",
    "name": "PHP Variable Interpolation SQL Injection",
    "type": "sql_injection",
    "pattern": "\"(?:SELECT|INSERT|UPDATE|DELETE|WHERE)[^\"]*\\$[a-zA-Z_][a-zA-Z0-9_]*[^\"]*\"",
    "flags": "i",
    "severity": "critical",
    "message": "SQL query built with PHP variable interpolation — use PDO prepared statements",
    "excludeExtensions": [".kt", ".kts"],
    "owasp": "A03:2021 Injection",
    "cwe": "CWE-89"
  },
  {
    "id": "SEC022",
    "name": "Rust Shell Command Injection (Command::new)",
    "type": "command_injection",
    "pattern": "Command::new\\s*\\(\\s*[\"'](?:/bin/)?(?:sh|bash|zsh)[\"']\\s*\\)",
    "flags": "",
    "severity": "critical",
    "message": "Command::new spawns a shell (sh/bash) — arguments built with format!()/user input risk command injection; avoid shell invocation, pass args directly to Command",
    "owasp": "A03:2021 Injection",
    "cwe": "CWE-78"
  },
  {
    "id": "SEC023",
    "name": "Rust push_str(format!()) SQL Injection",
    "type": "sql_injection",
    "pattern": "(?:sql|query|qry|stmt)[a-zA-Z0-9_]*\\.push_str\\s*\\(\\s*&?format!\\s*\\(\\s*[\"'][^\"']*\\{",
    "flags": "i",
    "severity": "error",
    "message": "SQL query built by push_str(format!()) — interpolated value inserted directly into the query string; use parameterized queries (sqlx::query! or bind) instead",
    "owasp": "A03:2021 Injection",
    "cwe": "CWE-89"
  },
  {
    "id": "SEC024",
    "name": "Rust push_str Variable SQL Injection",
    "type": "sql_injection",
    "pattern": "(?:sql|query|qry|stmt)[a-zA-Z0-9_]*\\.push_str\\s*\\(\\s*&?[a-zA-Z_][a-zA-Z0-9_]*\\s*\\)",
    "flags": "i",
    "severity": "error",
    "message": "SQL query string built with push_str() from a variable — likely unsanitized input concatenated into the query; use parameterized queries (sqlx::query! or bind) instead",
    "owasp": "A03:2021 Injection",
    "cwe": "CWE-89"
  },
  {
    "id": "SEC025",
    "name": "Rust String Addition SQL Injection",
    "type": "sql_injection",
    "pattern": "\"(?:SELECT|INSERT|UPDATE|DELETE|WHERE)\\b[^\"]{0,80}\"\\s*\\+",
    "flags": "i",
    "severity": "error",
    "message": "SQL query built with string concatenation (+) — use parameterized queries (sqlx::query! or bind) instead",
    "includeExtensions": [".rs"],
    "owasp": "A03:2021 Injection",
    "cwe": "CWE-89"
  },
  {
    "id": "SEC025B",
    "name": "JavaScript/TypeScript String Concatenation SQL Injection",
    "type": "sql_injection",
    "pattern": "\"(?:SELECT|INSERT|UPDATE|DELETE|WHERE)\\b[^\"]{0,80}\"\\s*\\+",
    "flags": "i",
    "severity": "error",
    "message": "SQL query built with string concatenation (+) — use parameterized queries (e.g. db.query('SELECT ...', [param])) instead",
    "includeExtensions": [".js", ".jsx", ".ts", ".tsx", ".mjs", ".cjs"],
    "owasp": "A03:2021 Injection",
    "cwe": "CWE-89"
  },
  {
    "id": "SEC025C",
    "name": "Python String Concatenation SQL Injection",
    "type": "sql_injection",
    "pattern": "\"(?:SELECT|INSERT|UPDATE|DELETE|WHERE)\\b[^\"]{0,80}\"\\s*\\+",
    "flags": "i",
    "severity": "error",
    "message": "SQL query built with string concatenation (+) — use parameterized queries (e.g. cursor.execute('SELECT ...', (param,))) instead",
    "includeExtensions": [".py"],
    "owasp": "A03:2021 Injection",
    "cwe": "CWE-89"
  },
  {
    "id": "SEC025D",
    "name": "Java String Concatenation SQL Injection",
    "type": "sql_injection",
    "pattern": "\"(?:SELECT|INSERT|UPDATE|DELETE|WHERE)\\b[^\"]{0,80}\"\\s*\\+",
    "flags": "i",
    "severity": "error",
    "message": "SQL query built with string concatenation (+) — use PreparedStatement with parameterized queries instead",
    "includeExtensions": [".java"],
    "owasp": "A03:2021 Injection",
    "cwe": "CWE-89"
  },
  {
    "id": "SEC025E",
    "name": "C# String Concatenation SQL Injection",
    "type": "sql_injection",
    "pattern": "\"(?:SELECT|INSERT|UPDATE|DELETE|WHERE)\\b[^\"]{0,80}\"\\s*\\+",
    "flags": "i",
    "severity": "error",
    "message": "SQL query built with string concatenation (+) — use SqlCommand.Parameters or Dapper parameterized queries instead",
    "includeExtensions": [".cs"],
    "owasp": "A03:2021 Injection",
    "cwe": "CWE-89"
  },
  {
    "id": "SEC025F",
    "name": "Kotlin String Concatenation SQL Injection",
    "type": "sql_injection",
    "pattern": "\"(?:SELECT|INSERT|UPDATE|DELETE|WHERE)\\b[^\"]{0,80}\"\\s*\\+",
    "flags": "i",
    "severity": "error",
    "message": "SQL query built with string concatenation (+) — use PreparedStatement with parameterized queries instead",
    "includeExtensions": [".kt", ".kts"],
    "owasp": "A03:2021 Injection",
    "cwe": "CWE-89"
  },
  {
    "id": "SEC025G",
    "name": "Kotlin String Template SQL Injection",
    "type": "sql_injection",
    "pattern": "\"(?:SELECT|INSERT|UPDATE|DELETE|WHERE)[^\"]*\\$[a-zA-Z_][a-zA-Z0-9_]*[^\"]*\"",
    "flags": "i",
    "severity": "critical",
    "message": "SQL query built with Kotlin string template interpolation — use PreparedStatement with parameterized queries instead",
    "includeExtensions": [".kt", ".kts"],
    "owasp": "A03:2021 Injection",
    "cwe": "CWE-89"
  }
]
