Using IronheightsUpdated

Is Ironheights free and open source?

Short answer

Yes. The Ironheights command-line scanner, its detection rules, the benchmark harness and the advisory OpenClaw skill are free and open source under the Apache-2.0 license, with the source on GitHub. Paid Pro, Team, Threat Intel API and Enterprise tiers are planned, but their prices are hypotheses and nothing paid is on sale yet.

What is free

The Community edition is everything that exists today:

There is no account, no sign-up, and no usage limit in the CLI.

The license

Ironheights is licensed under Apache-2.0. You can use it commercially, modify it, and redistribute it under the license terms, including in CI pipelines for clients. It is provided without warranty, as the license and our terms state. The full source, issues and releases are in the GitHub repository.

Why open source matters for a security tool

You should not have to trust a security tool's marketing. Because the rules are published, you can read exactly what each one matches, test it against your own skills, and see where it misfires. Our benchmark publishes the method, the per-sample results and the limits, including the fact that our first corpus is small, synthetic and written by us, so it is a regression check rather than a detection rate.

What is planned, and what is not promised

The pricing page lists Pro, Team, a Threat Intel API and Enterprise tiers. Those are plans, and the prices shown are early hypotheses. Features such as a sandbox, a credential broker and a team console are on the roadmap, not in version 0.3.0. We do not sell anything today, and the free CLI does not depend on a paid service.

How to contribute or report a problem

Bug reports, false positives and missed patterns are most useful as GitHub issues with a minimal, harmless example that reproduces them. Please never attach a real malicious skill; describe the technique instead. Security vulnerabilities in Ironheights itself should go through a private GitHub security advisory, as described on the security page. Rule changes are checked against the published rule reference, the synthetic test corpus and the scanner's parity tests before release, so a contribution comes with a test that shows what it matches and what it does not.

Limits

Free does not mean complete. Ironheights is a static, rules-only scanner (the guard plugin only logs by default): it cannot see payloads on linked websites, runtime behavior, or novel techniques its rules do not describe. See what Ironheights does not detect and the limitations page.

Sources

  • Install Ironheights with npx ironheights or npm install -g ironheights. Needs Node.js 20+. Official sources, a first scan, a baseline, and the advisory skill.
  • The Ironheights CLI has no telemetry and a scan makes no network call. Commands you choose, such as fetch, use the network. What the website records, with consent.
  • Ironheights misses payloads on linked sites, files over 1 MiB by default, runtime behavior, money-moving instructions and novel attacks. What to do about each.

All answers

Check the next skill before your agent reads it

Ironheights is a free, open-source, local-first scanner and integrity monitor for OpenClaw skills. It reports what its rules match; it cannot prove a skill is safe.