How do I install Ironheights?
Run it once with npx
npx ironheights scan ./path/to/skill
npx downloads the package and runs it. Nothing else is set up, and the files you scan are read as data, never executed.
Install the command
npm install -g ironheights
ironheights --version
ironheights and ih are the same command. The current version is 0.3.0. It runs on macOS, Linux and Windows; Windows support is new in 0.2.0 and is tested in CI on Node.js 20.0.0 and 24.
A 60-second first run
npx ironheights doctor
npx ironheights scan ~/.openclaw/workspace/skills/some-skill
npx ironheights baseline create
npx ironheights verify
doctor prints which OpenClaw directories it found and whether your Node.js version fits the range OpenClaw itself requires (OpenClaw has stricter requirements than Ironheights). scan prints findings grouped by skill and a verdict. baseline create records your skills and agent files, and verify later reports what changed. The docs list every command, flag, exit code and config key. To check a ClawHub skill before it reaches your machine, use npx ironheights safe-install <owner>/<slug>, which installs only when the scan is clean. See the features page.
Only from official sources
Fake security tools are a documented lure. Public reports describe a malicious skill that posed as a skill security checker, and a security-auditing skill that carried an encoded download command. Install Ironheights only from:
- the ironheights package on npm, published with a provenance signature;
- the GitHub releases of Frank-Masciopinto/ironheights;
- links on ironheights.dev.
Optional: the advisory OpenClaw skill
An optional skill tells your agent to run ironheights scan <path> --json before it installs or updates a skill, summarize the findings, and stop on a block verdict until you confirm. It asks for no network access and no secrets, and it expects the ironheights command to be installed already. It is advisory: it runs inside the agent, and a hostile skill can try to talk the agent out of it, so the CLI you run yourself is the trusted path. We explain why in this post.
Do not want to install anything?
The browser scanner runs the same content rules on a pasted SKILL.md in your browser. Integrity checks need the CLI.
If something does not work
Run ironheights --version; it should print 0.3.0. If the command is not found after a global install, check that npm's global bin directory is on your PATH, or keep using npx ironheights. If doctor reports that your Node.js version is outside OpenClaw's range, that affects OpenClaw, not Ironheights, which only needs Node.js 20 or newer. Version 0.1.0 printed nothing when started through npx or the installed command; that was fixed in 0.1.1 and every later release, so make sure you are not pinned to the older release. Report anything else as a GitHub issue.
Limits
Installing a scanner does not make skills safe. No findings means no rule matched; read the limitations before relying on a result.
Sources
- Ironheights README: Install, GitHub.
- ironheights on npm, npm.
- Ironheights advisory skill, GitHub.
- openclaw/clawhub issue #110 and issue #135, GitHub.