What does Ironheights not detect?
The blind spots, with examples
| Blind spot | Public example | What Ironheights reports |
|---|---|---|
| Payload on a linked website or paste site | About 40 skills that only linked to a lookalike site | The link, as a review finding (IH-NET-001) |
| Archive hosted on GitHub | Windows steps in several campaigns | Nothing: GitHub is on the allowlist |
| File larger than 1 MiB | A README padded to about 22 MB | Nothing inside the file with default settings; the scan is reported as incomplete (exit code 3) |
| Runtime and remote behavior | A skill that fetched affiliate links on every use | The remote host, not the behavior |
| Instructions to move money | A scheme to pool cryptocurrency into the operator's wallet | Nothing |
| Novel or heavily obfuscated phrasing | Not measurable in advance | Only what matches a rule |
| Compromised host | An attacker who can write your home directory | verify trusts a baseline that can be rewritten |
Each public example is a sourced entry in our malicious skill tracker, which marks whether the reported pattern is covered, partly covered, or not covered.
Why these gaps exist
Ironheights is a static, rules-only scanner. It reads files as text and never runs them, never fetches URLs while scanning, does not extract archives, and does not decide verdicts with a language model. An optional model review can add advisory notes (off by default, you choose the server); it never changes a verdict. Those choices keep it local, fast and predictable, and they define what it can see.
What to do about each
- Linked payloads and archives: treat any unexplained link or archive in a setup step as a stop.
- Large files: the CLI names every skipped file and directory (
.gitandnode_modulesare not entered unless you acknowledge them with a reason inignoreDirs) and reports the verdictincompletewith exit code 3, so a padded file no longer reads as clean. Raiselimits.maxFileBytesin your config to have the file scanned, and treat--allow-skippedas accepting the risk. The browser scanner shows "Incomplete scan" when it skips a file. - Runtime behavior and money: read what the skill tells the agent to do, run new skills without production keys or funded wallets, and require approval for transfers.
- Novel attacks: read the skill yourself and consider a second tool with a different method.
- Host compromise: keep the baseline somewhere harder to write, and investigate the machine itself.
Why we publish this list
A scanner that hides its blind spots invites false confidence, which is worse than no scanner. Every rule page on this site has its own "what it cannot catch" section, and we add to this list when we find a new gap.
How we measure it
Our benchmark is a small synthetic corpus written by us: a regression check, not a real-world detection rate. The full list is on the limitations page, and What our scanner cannot catch goes through each case in depth.
Sources
- Ironheights README: What Ironheights cannot detect, GitHub.
- Malicious ClawHub Skills Use External Websites to Hide in Plain Sight, OpenSourceMalware.
- Anatomy of a Deception: the 'omnicogg' Dropper, JFrog Security Research.
- OpenClaw's Skill Marketplace and the Emerging AI Supply Chain Threat, Palo Alto Networks Unit 42.