My comment on RSPEC-2385 is also relevant here, I would limit the scope of this rule to some known and widely used mutable objects. Moreover I would not activate this rule by default and would use the tag 'security'. Looks like we could link this rule to: