rules: - id: lua-os-execute pattern-either: - pattern: os.execute($CMD) - pattern: io.popen($CMD) message: >- Shell command executed via os.execute/io.popen. If $CMD includes any externally-influenced data (arguments, env vars, network/file input), this is command injection. Verify the command is a fixed literal or properly escaped/allowlisted. languages: [lua] severity: WARNING metadata: cwe: ["CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"] category: security - id: lua-dynamic-code-load pattern-either: - pattern: load($CODE) - pattern: loadstring($CODE) message: >- Dynamic code loaded via load/loadstring. If $CODE is derived from external input, this allows arbitrary code execution. Verify the source is trusted and not attacker-influenced. languages: [lua] severity: WARNING metadata: cwe: ["CWE-94: Improper Control of Generation of Code ('Code Injection')"] category: security