Ironheights vs Cisco skill-scanner
Short answer: Cisco's skill-scanner is the more capable detector when you run it with its LLM judge, and it publishes held-out accuracy we cannot match yet. Ironheights is smaller and rules-only, built around OpenClaw, and adds integrity checks for installed skills and agent files.
At a glance
| Cisco skill-scanner | Ironheights | |
|---|---|---|
| License and maker | Open source, Apache-2.0, from Cisco AI Defense[1] | Open source, Apache-2.0, independent project |
| Install | Python (CPython 3.11–3.14) via uv, pip, or Homebrew; version 2.2.2 at the time of checking[1][3] | Node.js 20 or newer, one npx command (docs) |
| Skill formats | Agent Skills specification (Codex and Cursor skill formats), plus non-standard formats with --lenient[1] | OpenClaw skills, with OpenClaw paths built in and a doctor command for your install |
| How it detects | YAML and YARA-X patterns, AST and dataflow analysis, an optional LLM judge, and a CEL decision layer[1] | 35 published rules (text, MCP config, advisory and integrity) whose severities add up to a review or block verdict and an A to F grade (how it works) |
| Reads intent | Yes, with the LLM judge, which Cisco runs in every recommended setup. It can use a local model so nothing leaves the machine[2] | No. Fixed patterns decide the verdict. An optional model second opinion is off by default, runs against a server you choose, and only adds advisory notes |
| Published accuracy | On 1,384 held-out records: rules alone catch 8.0% of malicious skills at MEDIUM+ (4.2% false positives). With the judge, 66.7% reach review at a 15.4% false-positive rate[2] | A synthetic 20-skill regression check only. No real-world rate yet[4] |
| CI and automation | SARIF, a reusable GitHub Actions workflow, a pre-commit hook, a Python API, and a REST API[1][2] | JSON, SARIF, Markdown and HTML reports, --fail-on, --since-baseline, documented exit codes, a GitHub Action and a pre-commit hook |
| After install | Not covered in the documentation we reviewed | Signed baselines and verify for installed skills and agent files, quarantine that moves a skill aside instead of deleting it, and an optional guard plugin that logs risky OpenClaw tool calls. The guard is not a sandbox |
Where each one is stronger
On our benchmark
On our 20-skill synthetic corpus, Ironheights (version 0.1.0, the version the benchmark ran on) sent 10/10 malicious samples to review and Cisco's rules sent 4/10, with no benign sample flagged by either. That comparison favors us and is not fair to Cisco: we wrote the corpus to match our own rules, and we ran Cisco without the LLM judge it recommends. It is a regression check, not evidence that Ironheights detects more in the real world. The full method and every sample are on the benchmark page[4].
Using both
The two do not conflict. A reasonable setup for a team that installs third-party skills:
- Scan new skills with Cisco's scanner and its judge in CI, and send MEDIUM and above to a reviewer, as Cisco recommends.
- Scan with Ironheights before installing on an OpenClaw machine, and record a baseline after.
- Run verify on a schedule so a changed skill or agent file is noticed.
Sources
- cisco-ai-defense/skill-scanner README, GitHub.
- Recommended Settings, Cisco Skill Scanner documentation.
- cisco-ai-skill-scanner 2.2.2, PyPI.
- Ironheights benchmark #1, Ironheights, 9 October 2026.
All sources last checked on 9 October 2026.