{
  "name": "Ironheights facts",
  "url": "https://ironheights.dev/facts/",
  "lastUpdated": "2026-10-11",
  "note": "Generated from the same data as the website on every build. Each fact has a stable anchor at url#id.",
  "product": {
    "name": "Ironheights",
    "definition": "Ironheights is a free, open-source, local-first security scanner and integrity monitor for OpenClaw agent skills. It reads skill files as data, flags risky patterns with published rules, and reports changes to installed skills and agent files against a baseline saved on your machine.",
    "maker": "Ironheights",
    "repository": "https://github.com/Frank-Masciopinto/ironheights",
    "license": "Apache-2.0",
    "version": "0.3.0",
    "package": "ironheights",
    "commands": [
      "ironheights",
      "ih"
    ],
    "install": {
      "npx": "npx ironheights scan ./path/to/skill",
      "global": "npm install -g ironheights"
    },
    "node": {
      "minimum": 20,
      "requirement": "Node.js 20 or newer"
    },
    "platforms": [
      "macOS",
      "Linux",
      "Windows"
    ],
    "windowsNote": "Windows support is new in 0.2.0 and is tested in CI on Node.js 20.0.0 and 24.",
    "website": "https://ironheights.dev/",
    "domain": "ironheights.dev"
  },
  "detection": {
    "totalRules": 35,
    "contentRules": 17,
    "integrityRules": 4,
    "mcpRules": 3,
    "advisoryRules": 1,
    "configRules": 9,
    "modelNoteRules": 1,
    "bySeverity": {
      "critical": 5,
      "high": 19,
      "medium": 9,
      "low": 1,
      "info": 1
    },
    "thresholds": {
      "block": 80,
      "review": 15
    },
    "rules": [
      {
        "id": "IH-EXEC-001",
        "title": "Remote content piped into an interpreter",
        "severity": "critical",
        "url": "https://ironheights.dev/rules/ih-exec-001/"
      },
      {
        "id": "IH-EXEC-002",
        "title": "Prerequisite install from an external URL",
        "severity": "high",
        "url": "https://ironheights.dev/rules/ih-exec-002/"
      },
      {
        "id": "IH-EXEC-003",
        "title": "Dynamic code execution",
        "severity": "high",
        "url": "https://ironheights.dev/rules/ih-exec-003/"
      },
      {
        "id": "IH-NET-001",
        "title": "Undeclared network destination",
        "severity": "medium",
        "url": "https://ironheights.dev/rules/ih-net-001/"
      },
      {
        "id": "IH-NET-002",
        "title": "Possible exfiltration",
        "severity": "high",
        "url": "https://ironheights.dev/rules/ih-net-002/"
      },
      {
        "id": "IH-CRED-001",
        "title": "Access to a sensitive path",
        "severity": "high",
        "url": "https://ironheights.dev/rules/ih-cred-001/"
      },
      {
        "id": "IH-CRED-002",
        "title": "Hard-coded secret",
        "severity": "high",
        "url": "https://ironheights.dev/rules/ih-cred-002/"
      },
      {
        "id": "IH-CRED-003",
        "title": "Secret asked for in chat or memory",
        "severity": "medium",
        "url": "https://ironheights.dev/rules/ih-cred-003/"
      },
      {
        "id": "IH-INJ-001",
        "title": "Instruction override",
        "severity": "high",
        "url": "https://ironheights.dev/rules/ih-inj-001/"
      },
      {
        "id": "IH-INJ-002",
        "title": "Hidden content",
        "severity": "high",
        "url": "https://ironheights.dev/rules/ih-inj-002/"
      },
      {
        "id": "IH-INJ-003",
        "title": "Weaken agent safeguards",
        "severity": "high",
        "url": "https://ironheights.dev/rules/ih-inj-003/"
      },
      {
        "id": "IH-OBF-001",
        "title": "Obfuscated code",
        "severity": "medium",
        "url": "https://ironheights.dev/rules/ih-obf-001/"
      },
      {
        "id": "IH-PERSIST-001",
        "title": "Persistence mechanism",
        "severity": "high",
        "url": "https://ironheights.dev/rules/ih-persist-001/"
      },
      {
        "id": "IH-PRIV-001",
        "title": "Privilege or OS protection bypass",
        "severity": "high",
        "url": "https://ironheights.dev/rules/ih-priv-001/"
      },
      {
        "id": "IH-BIN-001",
        "title": "Bundled executable or archive",
        "severity": "high",
        "url": "https://ironheights.dev/rules/ih-bin-001/"
      },
      {
        "id": "IH-FS-001",
        "title": "Suspicious filesystem access",
        "severity": "medium",
        "url": "https://ironheights.dev/rules/ih-fs-001/"
      },
      {
        "id": "IH-META-001",
        "title": "Skill metadata problem",
        "severity": "low",
        "url": "https://ironheights.dev/rules/ih-meta-001/"
      },
      {
        "id": "IH-MCP-001",
        "title": "MCP server launched from a remote command",
        "severity": "high",
        "url": "https://ironheights.dev/rules/ih-mcp-001/"
      },
      {
        "id": "IH-MCP-002",
        "title": "Secret in an MCP server environment",
        "severity": "high",
        "url": "https://ironheights.dev/rules/ih-mcp-002/"
      },
      {
        "id": "IH-MCP-003",
        "title": "MCP server given a broad filesystem root",
        "severity": "medium",
        "url": "https://ironheights.dev/rules/ih-mcp-003/"
      },
      {
        "id": "IH-INT-001",
        "title": "Skill file modified",
        "severity": "high",
        "url": "https://ironheights.dev/rules/ih-int-001/"
      },
      {
        "id": "IH-INT-002",
        "title": "New skill file",
        "severity": "medium",
        "url": "https://ironheights.dev/rules/ih-int-002/"
      },
      {
        "id": "IH-INT-003",
        "title": "Skill file removed",
        "severity": "medium",
        "url": "https://ironheights.dev/rules/ih-int-003/"
      },
      {
        "id": "IH-INT-004",
        "title": "Watched agent file changed",
        "severity": "high",
        "url": "https://ironheights.dev/rules/ih-int-004/"
      },
      {
        "id": "IH-ADV-001",
        "title": "Advisory feed match",
        "severity": "critical",
        "url": "https://ironheights.dev/rules/ih-adv-001/"
      },
      {
        "id": "IH-CFG-001",
        "title": "Gateway bind is not loopback",
        "severity": "high",
        "url": "https://ironheights.dev/rules/ih-cfg-001/"
      },
      {
        "id": "IH-CFG-002",
        "title": "Gateway auth is missing or a placeholder",
        "severity": "critical",
        "url": "https://ironheights.dev/rules/ih-cfg-002/"
      },
      {
        "id": "IH-CFG-003",
        "title": "DM policy is open",
        "severity": "critical",
        "url": "https://ironheights.dev/rules/ih-cfg-003/"
      },
      {
        "id": "IH-CFG-004",
        "title": "Group policy is open",
        "severity": "high",
        "url": "https://ironheights.dev/rules/ih-cfg-004/"
      },
      {
        "id": "IH-CFG-005",
        "title": "Plaintext secret in OpenClaw config",
        "severity": "high",
        "url": "https://ironheights.dev/rules/ih-cfg-005/"
      },
      {
        "id": "IH-CFG-006",
        "title": "OpenClaw config permissions",
        "severity": "critical",
        "url": "https://ironheights.dev/rules/ih-cfg-006/"
      },
      {
        "id": "IH-CFG-007",
        "title": "Dangerous tool permissions",
        "severity": "high",
        "url": "https://ironheights.dev/rules/ih-cfg-007/"
      },
      {
        "id": "IH-CFG-008",
        "title": "Skills load from an extra directory",
        "severity": "medium",
        "url": "https://ironheights.dev/rules/ih-cfg-008/"
      },
      {
        "id": "IH-CFG-009",
        "title": "Sandbox disabled while tools can act",
        "severity": "medium",
        "url": "https://ironheights.dev/rules/ih-cfg-009/"
      },
      {
        "id": "IH-LLM-001",
        "title": "Advisory model review",
        "severity": "info",
        "url": "https://ironheights.dev/rules/ih-llm-001/"
      }
    ]
  },
  "features": [
    {
      "id": "coexist",
      "title": "Works next to your other security tools",
      "summary": "ironheights coexist (alias doctor coexist) reads files only to list other security tools (ClawHub vetting skills, guard plugins, scanner CLIs, CI and pre-commit scanners) and reports overlaps as IH-COEX-001 to IH-COEX-011, each with a fix. It runs none of them, makes no network call and writes nothing. Detection is heuristic, and no findings is not proof that tools will not interfere.",
      "limit": "Detection is heuristic. It reads files and names, so a tool that is not on its list, was renamed, or is only loaded in a running Gateway can be missed, and anyone can copy a name. No findings is not proof that two tools will not interfere.",
      "url": "https://ironheights.dev/features/#coexist"
    },
    {
      "id": "guard-priority",
      "title": "A guard that shares the hook",
      "summary": "The guard plugin runs before_tool_call at priority 80 by default, configurable from -1000 to 1000 (OpenClaw runs higher numbers first and a block ends the chain). It returns only block and blockReason, never blocks in monitor mode, keeps its files under ~/.ironheights, prefixes block reasons with ironheights:, and logs one line at startup when it sees other security tools. It is not a sandbox.",
      "limit": "Priority sets the order, not who is right. When two guards enforce, the higher one blocks first and the other never sees that call, so its log is missing it. The hook still runs inside the agent and is not a sandbox. Hook order follows OpenClaw's plugin docs as checked on 11 October 2026 and can change.",
      "url": "https://ironheights.dev/features/#guard-priority"
    },
    {
      "id": "known-security-tools",
      "title": "Security tools are not trusted by name",
      "summary": "When a scanned skill's folder or SKILL.md name equals a known security tool, scan adds a name-match-only note and lowers confidence one step on its Markdown injection and credential findings. Severity, score, grade, verdict and exit code do not change, and nothing is allowlisted, because a malicious skill can copy a name.",
      "limit": "A name match proves nothing about the files. The note helps you read findings. It is not a clearance, and a malicious skill that borrows a familiar name gets the same verdict as any other.",
      "url": "https://ironheights.dev/features/#known-security-tools"
    },
    {
      "id": "safe-install",
      "title": "Fetch and safe-install",
      "summary": "ironheights fetch owner/slug downloads a ClawHub skill over HTTPS without executing it and scans it; safe-install copies it into your skills folder only when the verdict is no-findings (or review with --accept-review). Block and incomplete are never installed.",
      "limit": "A clean verdict means no rule matched, not that the skill is safe. This is one of the few commands that uses the network, and only when you run it.",
      "url": "https://ironheights.dev/features/#safe-install"
    },
    {
      "id": "advisory-feed",
      "title": "Signed advisory feed support",
      "summary": "The CLI can download and verify a signed advisory feed (Ed25519, key pinned in the CLI) and reports IH-ADV-001 when a cached feed lists a skill by name, content hash or indicator host. The feed itself is not published yet, so until it is live scans report nothing from the feed.",
      "limit": "The feed is not published yet. Until it is, advisories update has nothing to download and scans report nothing from the feed. A skill missing from a feed is not evidence that it is harmless.",
      "url": "https://ironheights.dev/features/#advisory-feed"
    },
    {
      "id": "signed-baselines",
      "title": "Signed baselines",
      "summary": "baseline create --key and verify --key sign and check baseline.json with an HMAC-SHA256 or Ed25519 key file you keep. A signature mismatch is reported as a tampered baseline (critical IH-INT-001, exit code 2).",
      "limit": "An attacker who can write your home directory and also has the key can sign a new baseline. Keep the key file private, and a copy of it off the machine if you can.",
      "url": "https://ironheights.dev/features/#signed-baselines"
    },
    {
      "id": "guard",
      "title": "Guard plugin for agent tool calls",
      "summary": "The guard is an in-process OpenClaw before_tool_call plugin that watches four behaviors (credential reads, download-and-execute, undeclared or high-risk hosts, writes to agent identity files and skill folders). It defaults to monitor mode, which logs and does not block. It is not a sandbox, and a compromised skill that can edit OpenClaw config can turn it off.",
      "limit": "The guard is not a sandbox. It runs inside the OpenClaw process, so a compromised skill that can edit your OpenClaw config or the policy file can switch it off. It sees only the tool name and parameters OpenClaw passes in. A quiet log is not proof that nothing happened.",
      "url": "https://ironheights.dev/features/#guard"
    },
    {
      "id": "trust-grade",
      "title": "A to F trust grade",
      "summary": "Every scan prints a trust grade from 0 to 100 (A 90-100, B 80-89, C 70-79, D 60-69, F 0-59) based on the existing risk points, next to the line “Absence of findings is not proof of safety.” A scan that skipped anything is graded incomplete, with no number.",
      "limit": "An A means the rules found little to add up. It does not mean the skill is safe. A scan that skipped anything is graded incomplete, with no number.",
      "url": "https://ironheights.dev/features/#trust-grade"
    },
    {
      "id": "incomplete-scans",
      "title": "Honest incomplete verdicts",
      "summary": "A scan that skipped a file (for example over 1 MiB) or a .git or node_modules directory reports the verdict incomplete with exit code 3, names what was skipped, and grades incomplete, unless the scanned files already reached review or block. dist/ is scanned.",
      "limit": "Incomplete means part of the skill was not checked at all. --allow-skipped and ignoreDirs let you accept that. They do not scan what was skipped.",
      "url": "https://ironheights.dev/features/#incomplete-scans"
    },
    {
      "id": "piped-json",
      "title": "Piped JSON that stays whole",
      "summary": "Fixed in 0.2.0: piped scan --json and --format html output is no longer cut off at 64 KiB; the process waits for the pipe to accept the whole report.",
      "limit": "This is a bug fix, not a new detection. It does not change what a scan finds.",
      "url": "https://ironheights.dev/features/#piped-json"
    },
    {
      "id": "config-audit",
      "title": "OpenClaw config audit",
      "summary": "ironheights audit-config reads the local OpenClaw config and reports risky settings as IH-CFG-001 to IH-CFG-009. It is offline and read-only, and it does not replace openclaw security audit.",
      "limit": "It reads the file, not the running system. Settings that come from environment variables are not seen.",
      "url": "https://ironheights.dev/features/#config-audit"
    },
    {
      "id": "mcp-rules",
      "title": "MCP configuration rules",
      "summary": "scan reports IH-MCP-001, IH-MCP-002 and IH-MCP-003 for risky MCP server commands, literal secrets in a server environment, and broad filesystem roots. The in-browser scanner does not run these.",
      "limit": "CLI only: the in-browser scanner does not run these rules. A pinned package can still be malicious.",
      "url": "https://ironheights.dev/features/#mcp-rules"
    },
    {
      "id": "since-baseline",
      "title": "Only what is new",
      "summary": "scan --since-baseline reports only findings that are new compared with an integrity baseline or a previous JSON result, and counts and lists the omitted ones.",
      "limit": "A finding you already accepted is hidden from the list, not made safe.",
      "url": "https://ironheights.dev/features/#since-baseline"
    },
    {
      "id": "text-scan",
      "title": "Scan a piece of text",
      "summary": "scan --stdin and scan --text run the content rules on one piece of text and label the result as a limited text scan; the text is not executed.",
      "limit": "A text scan has no skill folder, so it cannot check files, hashes or the baseline.",
      "url": "https://ironheights.dev/features/#text-scan"
    },
    {
      "id": "suppressions",
      "title": "Suppressions that need a reason",
      "summary": "Inline ironheights-ignore comments and config suppressions require a reason of at least 8 characters; suppressed findings are counted and listed, and critical and integrity findings stay visible unless suppressCritical or suppressIntegrity is set.",
      "limit": "A suppression records your decision. It does not make the line safe.",
      "url": "https://ironheights.dev/features/#suppressions"
    },
    {
      "id": "ci",
      "title": "CI action, pre-commit hook and Windows",
      "summary": "The 0.2.0 release added a composite GitHub Action (action.yml, pinned to an exact version), a pre-commit hook, and Windows CI on Node.js 20.0.0 and 24.",
      "limit": "Windows support is new in 0.2.0 and is checked in CI, not yet as widely used as macOS and Linux.",
      "url": "https://ironheights.dev/features/#ci"
    },
    {
      "id": "model-review",
      "title": "Optional model second opinion",
      "summary": "scan --llm and review are opt-in. They send a capped, secret-scrubbed copy of the skill to a model server you choose (a loopback Ollama-compatible endpoint by default) and add IH-LLM-001 notes that never change the verdict, the grade or the exit code.",
      "limit": "Models can be wrong, and the scrub can miss a secret. A silent model is not a clearance.",
      "url": "https://ironheights.dev/features/#model-review"
    }
  ],
  "limitations": {
    "notProof": "No findings means the rules did not match; it is not proof of safety.",
    "cannotCatch": [
      "Novel attacks, and attacks obfuscated in a way the current rules do not describe.",
      "Runtime-only behavior that appears after a script is executed. The scanner reads files; it does not watch processes or network traffic. The optional guard plugin watches a short list of OpenClaw tool calls from inside the agent. It is not a sandbox, a compromised agent can switch it off, and a quiet log is not proof of safety.",
      "A host that is already compromised, including a baseline an attacker can rewrite. Anyone who can write your home directory can edit the baseline file, unless you sign the baseline with a key kept somewhere they cannot reach, and even a signed baseline does not help against an attacker who also has the key.",
      "Social engineering that never lands in a file the scanner reads.",
      "Files larger than 1 MiB are skipped by default (limits.maxFileBytes, 1,048,576 bytes) without being read, and .git and node_modules directories are not entered. The report names each skipped file and directory, the grade is incomplete, and the verdict is incomplete with exit code 3 unless something else already reached review or block; --allow-skipped accepts the skipped files and directories. A skipped file is still not checked."
    ]
  },
  "benchmark": {
    "url": "https://ironheights.dev/benchmark/",
    "measured": "2026-10-09",
    "version": "0.1.0",
    "corpus": {
      "total": 20,
      "malicious": 10,
      "benign": 10,
      "synthetic": true,
      "selfWritten": true
    },
    "ironheights": {
      "review": "10/10",
      "block": "4/10",
      "benignFlagged": "0/10"
    },
    "cisco": {
      "setup": "Rules only (balanced and strict gave identical results); LLM judge off",
      "review": "4/10",
      "benignFlagged": "0/10"
    },
    "virustotal": {
      "flagged": "0/10",
      "benignFlagged": "0/10",
      "codeInsight": "not measured"
    },
    "headline": "On a 20-skill synthetic corpus written by the Ironheights authors (10 malicious, 10 benign), Ironheights 0.1.0 sent 10 of 10 malicious samples to review, blocked 4 of 10, and flagged 0 of 10 benign samples.",
    "caveat": "This is a regression check, not a real-world detection rate: the corpus is tiny, self-written, and close to the rule examples. Measured on version 0.1.0; not re-measured on 0.3.0, whose rules changed, so results there can differ. A one-off check of the same corpus with 0.1.5 gave review 10 of 10, block 3 of 10, and 0 of 10 benign samples flagged; it is not part of the published comparison."
  },
  "privacy": {
    "statement": "The Ironheights CLI has no telemetry. The in-browser scanner never sends your skill’s content anywhere; it runs in your browser. With your consent, the site records only the scan verdict (no content) through Google Analytics.",
    "websiteAnalytics": "The ironheights.dev website loads Google Analytics 4 only after a visitor chooses Accept analytics in the consent banner. Ad features are off, and it never receives skill text or anything a visitor types.",
    "details": "https://ironheights.dev/privacy/"
  },
  "officialSources": [
    "https://www.npmjs.com/package/ironheights",
    "https://github.com/Frank-Masciopinto/ironheights/releases",
    "https://ironheights.dev/"
  ],
  "pricing": {
    "community": "free",
    "paidTiers": "hypotheses, not for sale",
    "statement": "The Community edition is free under Apache-2.0. Pro, Team, a Threat Intel API, and Enterprise are planned; their prices are hypotheses and nothing paid is on sale yet."
  },
  "contact": {
    "securityAdvisory": "https://github.com/Frank-Masciopinto/ironheights/security/advisories/new",
    "issues": "https://github.com/Frank-Masciopinto/ironheights/issues"
  },
  "tools": [
    {
      "name": "Skill scanner",
      "url": "https://ironheights.dev/tools/scanner/",
      "description": "Paste a SKILL.md and get a local risk read in your browser."
    },
    {
      "name": "Malicious skill tracker",
      "url": "https://ironheights.dev/tracker/",
      "description": "Publicly reported malicious ClawHub skills, with sources."
    },
    {
      "name": "Rules reference",
      "url": "https://ironheights.dev/rules/",
      "description": "One page per detection rule, in plain language."
    },
    {
      "name": "Skill safety checklist",
      "url": "https://ironheights.dev/tools/checklist/",
      "description": "A 10-minute vetting checklist and risk quiz for any skill."
    },
    {
      "name": "Benchmark",
      "url": "https://ironheights.dev/benchmark/",
      "description": "How the rules perform, with method and misses."
    },
    {
      "name": "Compare",
      "url": "https://ironheights.dev/compare/",
      "description": "Ironheights next to other skill scanners, written fairly."
    }
  ],
  "tracker": {
    "entries": 22,
    "reports": 19,
    "studies": 3,
    "sources": 25,
    "lastUpdated": "2026-10-10",
    "feed": "https://ironheights.dev/tracker/feed.json",
    "pages": [
      {
        "name": "ClawHavoc",
        "url": "https://ironheights.dev/tracker/clawhavoc/"
      },
      {
        "name": "Malicious ClawHub skills targeting crypto and trading users",
        "url": "https://ironheights.dev/tracker/osm-first-wave/"
      },
      {
        "name": "Fake “ClawHub CLI” skills by zaycv (clawhub, clawdhub1)",
        "url": "https://ironheights.dev/tracker/zaycv-clawhub-cli/"
      },
      {
        "name": "More skills by zaycv: linkedin-job-application, autoupdater, deepresearch",
        "url": "https://ironheights.dev/tracker/zaycv-more/"
      },
      {
        "name": "WhatsApp and security-check lookalikes by moonshine-100rze",
        "url": "https://ironheights.dev/tracker/moonshine-100rze/"
      },
      {
        "name": "x-trends-nvdfx (bundled Windows executable)",
        "url": "https://ironheights.dev/tracker/x-trends-nvdfx/"
      },
      {
        "name": "security-check (security-audit) and nanopdf",
        "url": "https://ironheights.dev/tracker/security-check-nanopdf/"
      },
      {
        "name": "Polymarket skills with a hidden reverse shell",
        "url": "https://ironheights.dev/tracker/polymarket-backdoor/"
      },
      {
        "name": "rankaj (credential exfiltration)",
        "url": "https://ironheights.dev/tracker/rankaj/"
      },
      {
        "name": "“AuthTool” trading skills",
        "url": "https://ironheights.dev/tracker/authtool/"
      },
      {
        "name": "copywritings and airbnb by StveenLi",
        "url": "https://ironheights.dev/tracker/stveenli-openclawcli-forum/"
      },
      {
        "name": "Fake “OpenClawCLI” website lure (thiagoruss0, stveenli)",
        "url": "https://ironheights.dev/tracker/openclawcli-vercel/"
      },
      {
        "name": "Skills distributing an Atomic macOS Stealer variant",
        "url": "https://ironheights.dev/tracker/trendmicro-amos-openclawcli/"
      },
      {
        "name": "google-qx4 (fake openclaw-core requirement)",
        "url": "https://ironheights.dev/tracker/google-qx4/"
      },
      {
        "name": "omnicogg (22 MB padded README)",
        "url": "https://ironheights.dev/tracker/omnicogg/"
      },
      {
        "name": "TradingView assistant skills delivering the cluw stealer",
        "url": "https://ironheights.dev/tracker/tradingview-cluw/"
      },
      {
        "name": "money-radar (runtime affiliate injection)",
        "url": "https://ironheights.dev/tracker/money-radar/"
      },
      {
        "name": "letssendit (agentic front-running)",
        "url": "https://ironheights.dev/tracker/letssendit/"
      },
      {
        "name": "soroban-trader-skill and burhanclaw-soroban-trader",
        "url": "https://ironheights.dev/tracker/soroban-trader/"
      },
      {
        "name": "ToxicSkills study",
        "url": "https://ironheights.dev/tracker/snyk-toxicskills/"
      },
      {
        "name": "Bitdefender Labs analysis of OpenClaw skills",
        "url": "https://ironheights.dev/tracker/bitdefender-17pct/"
      },
      {
        "name": "VirusTotal Code Insight findings on OpenClaw skills",
        "url": "https://ironheights.dev/tracker/virustotal-code-insight/"
      }
    ]
  },
  "answers": {
    "count": 13,
    "url": "https://ironheights.dev/answers/",
    "items": [
      {
        "question": "Is a ClawHub skill safe to install?",
        "answer": "Not automatically. Most ClawHub skills are ordinary, but researchers found hundreds of malicious ones in 2026, and some passed the marketplace's VirusTotal scan. Treat every skill as code that runs with your agent's access: check the listing, read the setup section and links, scan it, and give it only the access it needs.",
        "url": "https://ironheights.dev/answers/is-a-clawhub-skill-safe-to-install/",
        "updated": "2026-10-09"
      },
      {
        "question": "What is a malicious ClawHub skill?",
        "answer": "A malicious ClawHub skill is an OpenClaw skill written to harm the person who installs it. Its SKILL.md instructions get the agent, or you, to run a hidden installer, send credentials or files to an attacker, weaken the agent's safeguards, or move money. Most reported cases hid malware behind a fake setup step.",
        "url": "https://ironheights.dev/answers/what-is-a-malicious-clawhub-skill/",
        "updated": "2026-10-09"
      },
      {
        "question": "What is prompt injection in an agent skill?",
        "answer": "Prompt injection in an agent skill is text in the skill's files that tries to take control of the agent: telling it to ignore earlier rules, hide actions from you, turn off confirmations, or edit its own instruction files. It works because the agent cannot reliably tell trusted instructions from text supplied by the skill's author.",
        "url": "https://ironheights.dev/answers/what-is-prompt-injection-in-an-agent-skill/",
        "updated": "2026-10-09"
      },
      {
        "question": "What is OpenClaw skill supply-chain risk?",
        "answer": "OpenClaw skill supply-chain risk is the risk you take on by running instructions written by someone else. A third-party skill, a later update to it, or a website or file it depends on can turn harmful, and it acts with your agent's access to files, accounts and keys. It is the agent version of a malicious package.",
        "url": "https://ironheights.dev/answers/what-is-openclaw-skill-supply-chain-risk/",
        "updated": "2026-10-09"
      },
      {
        "question": "Does VirusTotal scan ClawHub skills?",
        "answer": "Yes. Since 7 February 2026, every skill published to ClawHub is scanned with VirusTotal, including Code Insight, an LLM review of SKILL.md and the files it references. Benign skills are approved, suspicious ones get a warning, malicious ones are blocked from download, and active skills are re-scanned daily. OpenClaw calls it helpful but not a silver bullet.",
        "url": "https://ironheights.dev/answers/does-virustotal-scan-clawhub-skills/",
        "updated": "2026-10-09"
      },
      {
        "question": "How do I scan an OpenClaw skill for malware?",
        "answer": "Run npx ironheights scan with the path to the skill folder, or paste its SKILL.md into the free browser scanner on this site. Both read the files as text, never run them, and report each risky pattern with a rule id, line and evidence. Then read every finding: no findings means no rule matched, not that the skill is safe.",
        "url": "https://ironheights.dev/answers/how-do-i-scan-an-openclaw-skill-for-malware/",
        "updated": "2026-10-11"
      },
      {
        "question": "How do I verify a skill from ClawHub?",
        "answer": "Confirm you are on the skill's real ClawHub listing and the name and publisher are what you expect, read its VirusTotal status, then read the raw SKILL.md setup section, commands and links yourself. Scan the downloaded folder with a local scanner, install only if everything fits the skill's job, and record a baseline right after.",
        "url": "https://ironheights.dev/answers/how-do-i-verify-a-skill-from-clawhub/",
        "updated": "2026-10-11"
      },
      {
        "question": "How do I check if a skill changed after install?",
        "answer": "Record a baseline right after you install and review the skill: npx ironheights baseline create stores a hash, size and mode for every watched file. Later, npx ironheights verify compares the current files with that record and lists every file that was added, modified, removed or had its permissions changed, with a rule id for each.",
        "url": "https://ironheights.dev/answers/how-do-i-check-if-a-skill-changed-after-install/",
        "updated": "2026-10-11"
      },
      {
        "question": "How do I install Ironheights?",
        "answer": "You need Node.js 20 or newer. Run npx ironheights scan with the path to a skill to use it without installing, or install the command globally with npm install -g ironheights; ih is a shorter alias for the same command. Get it only from the ironheights package on npm, the project's GitHub releases, or this site.",
        "url": "https://ironheights.dev/answers/how-do-i-install-ironheights/",
        "updated": "2026-10-11"
      },
      {
        "question": "Is Ironheights free and open source?",
        "answer": "Yes. The Ironheights command-line scanner, its detection rules, the benchmark harness and the advisory OpenClaw skill are free and open source under the Apache-2.0 license, with the source on GitHub. Paid Pro, Team, Threat Intel API and Enterprise tiers are planned, but their prices are hypotheses and nothing paid is on sale yet.",
        "url": "https://ironheights.dev/answers/is-ironheights-free-and-open-source/",
        "updated": "2026-10-11"
      },
      {
        "question": "Does Ironheights send my data anywhere?",
        "answer": "The CLI has no telemetry, and a scan makes no network call. Only commands you run on purpose use the network, such as fetch or the optional model review. The in-browser scanner never sends your skill's content anywhere. The website uses Google Analytics only after you accept it, and then records only the scan verdict.",
        "url": "https://ironheights.dev/answers/does-ironheights-send-my-data-anywhere/",
        "updated": "2026-10-11"
      },
      {
        "question": "Can I run Ironheights alongside other security scanners?",
        "answer": "Yes. Ironheights reads files and never runs another tool, and its guard stays in monitor mode unless you change it, so it can sit beside other scanners. Run ironheights coexist to list the other security tools it can see and where they overlap, with a fix for each. The check is heuristic, and a clean report is not proof.",
        "url": "https://ironheights.dev/answers/can-i-run-ironheights-alongside-other-security-scanners/",
        "updated": "2026-10-11"
      },
      {
        "question": "What does Ironheights not detect?",
        "answer": "Ironheights only sees patterns its rules describe in the files it reads. It misses payloads hosted on a linked website or paste site, files over 1 MiB by default, behavior that appears only at runtime, instructions to move money, novel or heavily obfuscated attacks, and tampering by someone who can rewrite its baseline. No findings is not proof of safety.",
        "url": "https://ironheights.dev/answers/what-does-ironheights-not-detect/",
        "updated": "2026-10-11"
      }
    ]
  },
  "blog": {
    "count": 8,
    "url": "https://ironheights.dev/blog/",
    "posts": [
      {
        "title": "Ironheights 0.3.0: running next to the security tools you already have",
        "description": "Ironheights 0.3.0 adds ironheights coexist, which finds other scanners and guards on your agent and reports overlaps. How it works, and where it stops.",
        "url": "https://ironheights.dev/blog/ironheights-0-3-0-run-next-to-other-security-tools/",
        "published": "2026-10-11"
      },
      {
        "title": "Ironheights 0.2.0: protection beyond scanning, and where it stops",
        "description": "Ironheights 0.2.0 adds fetch and safe-install, signed baselines, a guard plugin for agent tool calls, an A to F grade and advisory feed support. Plain language.",
        "url": "https://ironheights.dev/blog/ironheights-0-2-0-protection-beyond-scanning/",
        "published": "2026-10-11"
      },
      {
        "title": "What our scanner cannot catch (and what to do about it)",
        "description": "What Ironheights misses: payloads on linked sites, files over 1 MiB, runtime behavior, money-moving instructions and a compromised host, with a fix for each.",
        "url": "https://ironheights.dev/blog/what-ironheights-cannot-catch/",
        "published": "2026-10-09"
      },
      {
        "title": "Baselines for agent files: detecting silent tampering",
        "description": "How to record a known-good baseline of OpenClaw skills and agent files like AGENTS.md, SOUL.md and MEMORY.md, and verify later what was added, modified or removed.",
        "url": "https://ironheights.dev/blog/agent-file-baselines-detect-silent-tampering/",
        "published": "2026-10-09"
      },
      {
        "title": "Where your agent leaks credentials without you noticing",
        "description": "The quiet places an OpenClaw agent exposes API keys, SSH keys and wallets: chat, memory, .env files, skill files and outbound requests. How to check each.",
        "url": "https://ironheights.dev/blog/where-openclaw-agents-leak-credentials/",
        "published": "2026-10-09"
      },
      {
        "title": "Why a security skill that runs inside the agent can be bypassed",
        "description": "A security skill shares the agent's context with the skills it checks, so a hostile skill can talk the agent out of it. Where the real trust boundary is.",
        "url": "https://ironheights.dev/blog/why-in-agent-security-skills-can-be-bypassed/",
        "published": "2026-10-09"
      },
      {
        "title": "A 10-minute checklist for vetting an OpenClaw skill",
        "description": "A 10-minute routine to vet an OpenClaw or ClawHub skill before install: where it comes from, what to read in SKILL.md, what it can reach, what to record.",
        "url": "https://ironheights.dev/blog/vet-openclaw-skill-10-minute-checklist/",
        "published": "2026-10-09"
      },
      {
        "title": "How malicious skills trick agents: anatomy of a prerequisite attack",
        "description": "How fake 'Prerequisites' sections in ClawHub skills get agents and people to run malware, the variants seen in 2026, and what a file scanner can and cannot see.",
        "url": "https://ironheights.dev/blog/malicious-skill-prerequisite-attack-anatomy/",
        "published": "2026-10-09"
      }
    ]
  },
  "citation": {
    "text": "Ironheights. “Ironheights facts.” ironheights.dev, last updated 11 October 2026. https://ironheights.dev/facts/",
    "bibtex": "@misc{ironheights_facts_2026,\n  author       = {{Ironheights}},\n  title        = {Ironheights facts},\n  year         = {2026},\n  url          = {https://ironheights.dev/facts/},\n  urldate      = {2026-10-11},\n  note         = {Last updated 2026-10-11}\n}"
  },
  "facts": [
    {
      "id": "definition",
      "section": "what-it-is",
      "label": "Definition",
      "text": "Ironheights is a free, open-source, local-first security scanner and integrity monitor for OpenClaw agent skills. It reads skill files as data, flags risky patterns with published rules, and reports changes to installed skills and agent files against a baseline saved on your machine.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#definition"
    },
    {
      "id": "maker",
      "section": "what-it-is",
      "label": "Who makes it",
      "text": "Ironheights is an open-source project by Ironheights, developed in public on GitHub at Frank-Masciopinto/ironheights.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#maker"
    },
    {
      "id": "license",
      "section": "what-it-is",
      "label": "License",
      "text": "The Ironheights CLI is free and open source under the Apache-2.0 license.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#license"
    },
    {
      "id": "version",
      "section": "what-it-is",
      "label": "Current version",
      "text": "The current release is 0.3.0, published on npm as the ironheights package with a provenance signature. The GitHub release lists SHA256 checksums.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#version"
    },
    {
      "id": "platforms",
      "section": "what-it-is",
      "label": "Platforms",
      "text": "Ironheights is a command-line tool for macOS, Linux and Windows. Windows support is new in 0.2.0 and is tested in CI on Node.js 20.0.0 and 24. A browser version of its content rules runs on any modern browser.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#platforms"
    },
    {
      "id": "install-npx",
      "section": "install",
      "label": "Run without installing",
      "text": "Run `npx ironheights scan ./path/to/skill` to scan one skill folder.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#install-npx"
    },
    {
      "id": "install-global",
      "section": "install",
      "label": "Install the command",
      "text": "Run `npm install -g ironheights`. The commands `ironheights` and `ih` are the same program.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#install-global"
    },
    {
      "id": "node",
      "section": "install",
      "label": "Supported Node.js",
      "text": "Ironheights needs Node.js 20 or newer. OpenClaw itself has stricter requirements; `ironheights doctor` reports whether your runtime fits.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#node"
    },
    {
      "id": "exit-codes",
      "section": "install",
      "label": "Exit codes",
      "text": "0 means no findings, 1 review, 2 block, 3 incomplete (a file or directory was skipped), 64 a usage or config error, and 70 an internal error, a failed network request or a rejected signature. --allow-skipped accepts skipped files and directories and returns the finding verdict instead of 3. Reports are available as JSON, SARIF 2.1.0, Markdown and HTML for CI.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#exit-codes"
    },
    {
      "id": "rule-count",
      "section": "detection",
      "label": "Rules",
      "text": "Ironheights 0.3.0 ships 35 rules: 17 content rules that read skill files during scan (these also run in the browser scanner), 3 MCP configuration rules and 1 advisory feed rule that scan reports in the CLI, 4 integrity rules that compare installed skills and agent files with a saved baseline during verify, 9 OpenClaw config rules for audit-config, and 1 optional model note.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#rule-count"
    },
    {
      "id": "severities",
      "section": "detection",
      "label": "Severities",
      "text": "By severity: 5 critical, 19 high, 9 medium, 1 low, 1 info.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#severities"
    },
    {
      "id": "verdicts",
      "section": "detection",
      "label": "Verdicts",
      "text": "Each skill gets one of four verdicts: no-findings; review when the score reaches 15 or any finding is high or medium; block when the score reaches 80 or any finding is critical; incomplete when a file or directory was skipped and nothing else reached review or block.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#verdicts"
    },
    {
      "id": "rules-list",
      "section": "detection",
      "label": "Every rule",
      "text": "All 35 rule ids, with one page each:",
      "items": [
        {
          "text": "IH-EXEC-001: Remote content piped into an interpreter (critical)",
          "url": "https://ironheights.dev/rules/ih-exec-001/"
        },
        {
          "text": "IH-EXEC-002: Prerequisite install from an external URL (high)",
          "url": "https://ironheights.dev/rules/ih-exec-002/"
        },
        {
          "text": "IH-EXEC-003: Dynamic code execution (high)",
          "url": "https://ironheights.dev/rules/ih-exec-003/"
        },
        {
          "text": "IH-NET-001: Undeclared network destination (medium)",
          "url": "https://ironheights.dev/rules/ih-net-001/"
        },
        {
          "text": "IH-NET-002: Possible exfiltration (high)",
          "url": "https://ironheights.dev/rules/ih-net-002/"
        },
        {
          "text": "IH-CRED-001: Access to a sensitive path (high)",
          "url": "https://ironheights.dev/rules/ih-cred-001/"
        },
        {
          "text": "IH-CRED-002: Hard-coded secret (high)",
          "url": "https://ironheights.dev/rules/ih-cred-002/"
        },
        {
          "text": "IH-CRED-003: Secret asked for in chat or memory (medium)",
          "url": "https://ironheights.dev/rules/ih-cred-003/"
        },
        {
          "text": "IH-INJ-001: Instruction override (high)",
          "url": "https://ironheights.dev/rules/ih-inj-001/"
        },
        {
          "text": "IH-INJ-002: Hidden content (high)",
          "url": "https://ironheights.dev/rules/ih-inj-002/"
        },
        {
          "text": "IH-INJ-003: Weaken agent safeguards (high)",
          "url": "https://ironheights.dev/rules/ih-inj-003/"
        },
        {
          "text": "IH-OBF-001: Obfuscated code (medium)",
          "url": "https://ironheights.dev/rules/ih-obf-001/"
        },
        {
          "text": "IH-PERSIST-001: Persistence mechanism (high)",
          "url": "https://ironheights.dev/rules/ih-persist-001/"
        },
        {
          "text": "IH-PRIV-001: Privilege or OS protection bypass (high)",
          "url": "https://ironheights.dev/rules/ih-priv-001/"
        },
        {
          "text": "IH-BIN-001: Bundled executable or archive (high)",
          "url": "https://ironheights.dev/rules/ih-bin-001/"
        },
        {
          "text": "IH-FS-001: Suspicious filesystem access (medium)",
          "url": "https://ironheights.dev/rules/ih-fs-001/"
        },
        {
          "text": "IH-META-001: Skill metadata problem (low)",
          "url": "https://ironheights.dev/rules/ih-meta-001/"
        },
        {
          "text": "IH-MCP-001: MCP server launched from a remote command (high)",
          "url": "https://ironheights.dev/rules/ih-mcp-001/"
        },
        {
          "text": "IH-MCP-002: Secret in an MCP server environment (high)",
          "url": "https://ironheights.dev/rules/ih-mcp-002/"
        },
        {
          "text": "IH-MCP-003: MCP server given a broad filesystem root (medium)",
          "url": "https://ironheights.dev/rules/ih-mcp-003/"
        },
        {
          "text": "IH-INT-001: Skill file modified (high)",
          "url": "https://ironheights.dev/rules/ih-int-001/"
        },
        {
          "text": "IH-INT-002: New skill file (medium)",
          "url": "https://ironheights.dev/rules/ih-int-002/"
        },
        {
          "text": "IH-INT-003: Skill file removed (medium)",
          "url": "https://ironheights.dev/rules/ih-int-003/"
        },
        {
          "text": "IH-INT-004: Watched agent file changed (high)",
          "url": "https://ironheights.dev/rules/ih-int-004/"
        },
        {
          "text": "IH-ADV-001: Advisory feed match (critical)",
          "url": "https://ironheights.dev/rules/ih-adv-001/"
        },
        {
          "text": "IH-CFG-001: Gateway bind is not loopback (high)",
          "url": "https://ironheights.dev/rules/ih-cfg-001/"
        },
        {
          "text": "IH-CFG-002: Gateway auth is missing or a placeholder (critical)",
          "url": "https://ironheights.dev/rules/ih-cfg-002/"
        },
        {
          "text": "IH-CFG-003: DM policy is open (critical)",
          "url": "https://ironheights.dev/rules/ih-cfg-003/"
        },
        {
          "text": "IH-CFG-004: Group policy is open (high)",
          "url": "https://ironheights.dev/rules/ih-cfg-004/"
        },
        {
          "text": "IH-CFG-005: Plaintext secret in OpenClaw config (high)",
          "url": "https://ironheights.dev/rules/ih-cfg-005/"
        },
        {
          "text": "IH-CFG-006: OpenClaw config permissions (critical)",
          "url": "https://ironheights.dev/rules/ih-cfg-006/"
        },
        {
          "text": "IH-CFG-007: Dangerous tool permissions (high)",
          "url": "https://ironheights.dev/rules/ih-cfg-007/"
        },
        {
          "text": "IH-CFG-008: Skills load from an extra directory (medium)",
          "url": "https://ironheights.dev/rules/ih-cfg-008/"
        },
        {
          "text": "IH-CFG-009: Sandbox disabled while tools can act (medium)",
          "url": "https://ironheights.dev/rules/ih-cfg-009/"
        },
        {
          "text": "IH-LLM-001: Advisory model review (info)",
          "url": "https://ironheights.dev/rules/ih-llm-001/"
        }
      ],
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#rules-list"
    },
    {
      "id": "new-coexist",
      "section": "whats-new",
      "label": "Works next to your other security tools",
      "text": "ironheights coexist (alias doctor coexist) reads files only to list other security tools (ClawHub vetting skills, guard plugins, scanner CLIs, CI and pre-commit scanners) and reports overlaps as IH-COEX-001 to IH-COEX-011, each with a fix. It runs none of them, makes no network call and writes nothing. Detection is heuristic, and no findings is not proof that tools will not interfere.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#new-coexist"
    },
    {
      "id": "new-guard-priority",
      "section": "whats-new",
      "label": "A guard that shares the hook",
      "text": "The guard plugin runs before_tool_call at priority 80 by default, configurable from -1000 to 1000 (OpenClaw runs higher numbers first and a block ends the chain). It returns only block and blockReason, never blocks in monitor mode, keeps its files under ~/.ironheights, prefixes block reasons with ironheights:, and logs one line at startup when it sees other security tools. It is not a sandbox.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#new-guard-priority"
    },
    {
      "id": "new-known-security-tools",
      "section": "whats-new",
      "label": "Security tools are not trusted by name",
      "text": "When a scanned skill's folder or SKILL.md name equals a known security tool, scan adds a name-match-only note and lowers confidence one step on its Markdown injection and credential findings. Severity, score, grade, verdict and exit code do not change, and nothing is allowlisted, because a malicious skill can copy a name.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#new-known-security-tools"
    },
    {
      "id": "new-safe-install",
      "section": "whats-new",
      "label": "Fetch and safe-install",
      "text": "ironheights fetch owner/slug downloads a ClawHub skill over HTTPS without executing it and scans it; safe-install copies it into your skills folder only when the verdict is no-findings (or review with --accept-review). Block and incomplete are never installed.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#new-safe-install"
    },
    {
      "id": "new-advisory-feed",
      "section": "whats-new",
      "label": "Signed advisory feed support",
      "text": "The CLI can download and verify a signed advisory feed (Ed25519, key pinned in the CLI) and reports IH-ADV-001 when a cached feed lists a skill by name, content hash or indicator host. The feed itself is not published yet, so until it is live scans report nothing from the feed.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#new-advisory-feed"
    },
    {
      "id": "new-signed-baselines",
      "section": "whats-new",
      "label": "Signed baselines",
      "text": "baseline create --key and verify --key sign and check baseline.json with an HMAC-SHA256 or Ed25519 key file you keep. A signature mismatch is reported as a tampered baseline (critical IH-INT-001, exit code 2).",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#new-signed-baselines"
    },
    {
      "id": "new-guard",
      "section": "whats-new",
      "label": "Guard plugin for agent tool calls",
      "text": "The guard is an in-process OpenClaw before_tool_call plugin that watches four behaviors (credential reads, download-and-execute, undeclared or high-risk hosts, writes to agent identity files and skill folders). It defaults to monitor mode, which logs and does not block. It is not a sandbox, and a compromised skill that can edit OpenClaw config can turn it off.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#new-guard"
    },
    {
      "id": "new-trust-grade",
      "section": "whats-new",
      "label": "A to F trust grade",
      "text": "Every scan prints a trust grade from 0 to 100 (A 90-100, B 80-89, C 70-79, D 60-69, F 0-59) based on the existing risk points, next to the line “Absence of findings is not proof of safety.” A scan that skipped anything is graded incomplete, with no number.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#new-trust-grade"
    },
    {
      "id": "new-incomplete-scans",
      "section": "whats-new",
      "label": "Honest incomplete verdicts",
      "text": "A scan that skipped a file (for example over 1 MiB) or a .git or node_modules directory reports the verdict incomplete with exit code 3, names what was skipped, and grades incomplete, unless the scanned files already reached review or block. dist/ is scanned.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#new-incomplete-scans"
    },
    {
      "id": "new-piped-json",
      "section": "whats-new",
      "label": "Piped JSON that stays whole",
      "text": "Fixed in 0.2.0: piped scan --json and --format html output is no longer cut off at 64 KiB; the process waits for the pipe to accept the whole report.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#new-piped-json"
    },
    {
      "id": "new-config-audit",
      "section": "whats-new",
      "label": "OpenClaw config audit",
      "text": "ironheights audit-config reads the local OpenClaw config and reports risky settings as IH-CFG-001 to IH-CFG-009. It is offline and read-only, and it does not replace openclaw security audit.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#new-config-audit"
    },
    {
      "id": "new-mcp-rules",
      "section": "whats-new",
      "label": "MCP configuration rules",
      "text": "scan reports IH-MCP-001, IH-MCP-002 and IH-MCP-003 for risky MCP server commands, literal secrets in a server environment, and broad filesystem roots. The in-browser scanner does not run these.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#new-mcp-rules"
    },
    {
      "id": "new-since-baseline",
      "section": "whats-new",
      "label": "Only what is new",
      "text": "scan --since-baseline reports only findings that are new compared with an integrity baseline or a previous JSON result, and counts and lists the omitted ones.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#new-since-baseline"
    },
    {
      "id": "new-text-scan",
      "section": "whats-new",
      "label": "Scan a piece of text",
      "text": "scan --stdin and scan --text run the content rules on one piece of text and label the result as a limited text scan; the text is not executed.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#new-text-scan"
    },
    {
      "id": "new-suppressions",
      "section": "whats-new",
      "label": "Suppressions that need a reason",
      "text": "Inline ironheights-ignore comments and config suppressions require a reason of at least 8 characters; suppressed findings are counted and listed, and critical and integrity findings stay visible unless suppressCritical or suppressIntegrity is set.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#new-suppressions"
    },
    {
      "id": "new-ci",
      "section": "whats-new",
      "label": "CI action, pre-commit hook and Windows",
      "text": "The 0.2.0 release added a composite GitHub Action (action.yml, pinned to an exact version), a pre-commit hook, and Windows CI on Node.js 20.0.0 and 24.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#new-ci"
    },
    {
      "id": "new-model-review",
      "section": "whats-new",
      "label": "Optional model second opinion",
      "text": "scan --llm and review are opt-in. They send a capped, secret-scrubbed copy of the skill to a model server you choose (a loopback Ollama-compatible endpoint by default) and add IH-LLM-001 notes that never change the verdict, the grade or the exit code.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#new-model-review"
    },
    {
      "id": "not-proof",
      "section": "limits",
      "label": "A clean result",
      "text": "No findings means the rules did not match; it is not proof of safety.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#not-proof"
    },
    {
      "id": "cannot-catch",
      "section": "limits",
      "label": "Out of reach",
      "text": "Ironheights is a static, rules-based scanner. It cannot catch:",
      "items": [
        {
          "text": "Novel attacks, and attacks obfuscated in a way the current rules do not describe."
        },
        {
          "text": "Runtime-only behavior that appears after a script is executed. The scanner reads files; it does not watch processes or network traffic. The optional guard plugin watches a short list of OpenClaw tool calls from inside the agent. It is not a sandbox, a compromised agent can switch it off, and a quiet log is not proof of safety."
        },
        {
          "text": "A host that is already compromised, including a baseline an attacker can rewrite. Anyone who can write your home directory can edit the baseline file, unless you sign the baseline with a key kept somewhere they cannot reach, and even a signed baseline does not help against an attacker who also has the key."
        },
        {
          "text": "Social engineering that never lands in a file the scanner reads."
        },
        {
          "text": "Files larger than 1 MiB are skipped by default (limits.maxFileBytes, 1,048,576 bytes) without being read, and .git and node_modules directories are not entered. The report names each skipped file and directory, the grade is incomplete, and the verdict is incomplete with exit code 3 unless something else already reached review or block; --allow-skipped accepts the skipped files and directories. A skipped file is still not checked."
        }
      ],
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#cannot-catch"
    },
    {
      "id": "in-agent-skill",
      "section": "limits",
      "label": "The advisory skill",
      "text": "The OpenClaw advisory skill runs inside the agent, so a hostile skill can try to talk the agent out of it. The CLI you run yourself is the trusted path.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#in-agent-skill"
    },
    {
      "id": "benchmark-headline",
      "section": "benchmark",
      "label": "Headline, in counts",
      "text": "On a 20-skill synthetic corpus written by the Ironheights authors (10 malicious, 10 benign), Ironheights 0.1.0 sent 10 of 10 malicious samples to review, blocked 4 of 10, and flagged 0 of 10 benign samples.",
      "updated": "2026-10-09",
      "url": "https://ironheights.dev/facts/#benchmark-headline"
    },
    {
      "id": "benchmark-caveats",
      "section": "benchmark",
      "label": "Caveats",
      "text": "This is a regression check, not a real-world detection rate: the corpus is tiny, self-written, and close to the rule examples. Measured on version 0.1.0; not re-measured on 0.3.0, whose rules changed, so results there can differ. A one-off check of the same corpus with 0.1.5 gave review 10 of 10, block 3 of 10, and 0 of 10 benign samples flagged; it is not part of the published comparison.",
      "updated": "2026-10-09",
      "url": "https://ironheights.dev/facts/#benchmark-caveats"
    },
    {
      "id": "benchmark-others",
      "section": "benchmark",
      "label": "Other tools on the same corpus",
      "text": "Cisco skill-scanner 2.2.2 (rules only, no LLM judge) sent 4 of 10 malicious samples to review. Public VirusTotal flagged 0 of 10 malicious and 0 of 10 benign samples; its engines are built for binaries, and the Code Insight verdict ClawHub uses was not measured. The corpus was written to match Ironheights rules, so this comparison favors Ironheights.",
      "updated": "2026-10-09",
      "url": "https://ironheights.dev/facts/#benchmark-others"
    },
    {
      "id": "privacy-statement",
      "section": "privacy",
      "label": "Privacy statement",
      "text": "The Ironheights CLI has no telemetry. The in-browser scanner never sends your skill’s content anywhere; it runs in your browser. With your consent, the site records only the scan verdict (no content) through Google Analytics.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#privacy-statement"
    },
    {
      "id": "website-analytics",
      "section": "privacy",
      "label": "Website analytics",
      "text": "The ironheights.dev website loads Google Analytics 4 only after a visitor chooses Accept analytics in the consent banner. Ad features are off, and it never receives skill text or anything a visitor types.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#website-analytics"
    },
    {
      "id": "network-use",
      "section": "privacy",
      "label": "When the CLI uses the network",
      "text": "Scans make no network call. Only the commands you choose can: fetch and safe-install talk to clawhub.ai, advisories update talks to ironheights.dev, and scan --llm or review talk to a model server you pick (off by default; the default is a loopback Ollama-compatible endpoint). The CLI prints each URL before it requests it, and none of this is telemetry.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#network-use"
    },
    {
      "id": "no-execution",
      "section": "privacy",
      "label": "Scanned files",
      "text": "Skill files are read as data. Scripts are never executed and archives are flagged, not extracted.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#no-execution"
    },
    {
      "id": "sources",
      "section": "official-sources",
      "label": "Where to get it",
      "text": "Get Ironheights only from these three places. Do not trust builds or skills named Ironheights from anywhere else; fake security skills are a known lure.",
      "items": [
        {
          "text": "npm: the ironheights package",
          "url": "https://www.npmjs.com/package/ironheights"
        },
        {
          "text": "GitHub releases of Frank-Masciopinto/ironheights",
          "url": "https://github.com/Frank-Masciopinto/ironheights/releases"
        },
        {
          "text": "This website, ironheights.dev",
          "url": "https://ironheights.dev/"
        }
      ],
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#sources"
    },
    {
      "id": "pricing-status",
      "section": "pricing",
      "label": "Pricing status",
      "text": "The Community edition is free under Apache-2.0. Pro, Team, a Threat Intel API, and Enterprise are planned; their prices are hypotheses and nothing paid is on sale yet.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#pricing-status"
    },
    {
      "id": "free-tools",
      "section": "tools",
      "label": "Tools",
      "text": "6 free tools, all usable without an account:",
      "items": [
        {
          "text": "Skill scanner: Paste a SKILL.md and get a local risk read in your browser.",
          "url": "https://ironheights.dev/tools/scanner/"
        },
        {
          "text": "Malicious skill tracker: Publicly reported malicious ClawHub skills, with sources.",
          "url": "https://ironheights.dev/tracker/"
        },
        {
          "text": "Rules reference: One page per detection rule, in plain language.",
          "url": "https://ironheights.dev/rules/"
        },
        {
          "text": "Skill safety checklist: A 10-minute vetting checklist and risk quiz for any skill.",
          "url": "https://ironheights.dev/tools/checklist/"
        },
        {
          "text": "Benchmark: How the rules perform, with method and misses.",
          "url": "https://ironheights.dev/benchmark/"
        },
        {
          "text": "Compare: Ironheights next to other skill scanners, written fairly.",
          "url": "https://ironheights.dev/compare/"
        }
      ],
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#free-tools"
    },
    {
      "id": "tracker-size",
      "section": "tools",
      "label": "Malicious skill tracker",
      "text": "The tracker lists 22 entries (19 reported skills and campaigns, 3 studies) with 25 cited sources, each with its own page. It is not a complete list of malicious skills.",
      "updated": "2026-10-10",
      "url": "https://ironheights.dev/facts/#tracker-size"
    },
    {
      "id": "answers-count",
      "section": "guides",
      "label": "Short answers",
      "text": "13 short, sourced answers to common questions about OpenClaw and ClawHub skill security, each opening with a 40–60 word direct answer.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#answers-count"
    },
    {
      "id": "blog-count",
      "section": "guides",
      "label": "Blog posts",
      "text": "8 long-form guides and teardowns, each with its sources and what Ironheights cannot catch.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#blog-count"
    },
    {
      "id": "security-disclosure",
      "section": "contact",
      "label": "Report a vulnerability",
      "text": "Report a vulnerability through a private security advisory on the GitHub repository. There is no bug bounty.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#security-disclosure"
    },
    {
      "id": "contact-issues",
      "section": "contact",
      "label": "Everything else",
      "text": "Questions, false positives, and missing tracker entries go to GitHub issues.",
      "updated": "2026-10-11",
      "url": "https://ironheights.dev/facts/#contact-issues"
    }
  ],
  "quickAnswers": [
    {
      "url": "https://ironheights.dev/",
      "question": "What is Ironheights?",
      "answer": "Ironheights is a free, open-source (Apache-2.0) command-line scanner for OpenClaw agent skills. It reads skill files as data, checks them against 35 published rules, and reports changes against a local baseline. Version 0.3.0 can also fetch a skill and install it only if the scan is clean. No findings means no rule matched; it is not proof of safety.",
      "updated": "2026-10-11"
    },
    {
      "url": "https://ironheights.dev/tools/scanner/",
      "question": "How do I check a SKILL.md in my browser?",
      "answer": "Paste a SKILL.md or drop a folder below. The scanner runs the 17 content rules from the Ironheights 0.1.5 engine inside this tab and returns no findings, review or block, with rule ids and line numbers. Your skill’s content is never sent anywhere. Integrity, MCP and advisory checks need the CLI. No findings is not proof of safety.",
      "updated": "2026-10-11"
    },
    {
      "url": "https://ironheights.dev/rules/",
      "question": "What do the Ironheights rules check?",
      "answer": "Ironheights 0.3.0 has 35 rules. 17 content rules match risky patterns in skill files, such as remote scripts piped to a shell, credential paths, and instruction overrides. The rest cover MCP configs (3), the advisory feed (1), baseline integrity (4), OpenClaw config (9) and an optional model note (1).",
      "updated": "2026-10-11"
    },
    {
      "url": "https://ironheights.dev/tracker/",
      "question": "Which ClawHub skills have been reported as malicious?",
      "answer": "This tracker lists 19 publicly reported malicious skills and campaigns, plus 3 studies, each with its sources, report date, status as stated by the source, and whether an Ironheights rule flags the pattern. It covers only what researchers have published, so a skill missing from it is not evidence that the skill is harmless.",
      "updated": "2026-10-10"
    },
    {
      "url": "https://ironheights.dev/benchmark/",
      "question": "How well does Ironheights detect malicious skills?",
      "answer": "We have no real-world detection rate yet. On a 20-skill synthetic corpus we wrote ourselves, Ironheights 0.1.0 sent 10 of 10 malicious samples to review, blocked 4, and flagged 0 of 10 benign samples. Cisco skill-scanner, rules only, caught 4 of 10. It is a regression check that favors our rules.",
      "updated": "2026-10-09"
    },
    {
      "url": "https://ironheights.dev/compare/",
      "question": "How does Ironheights compare with VirusTotal and Cisco skill-scanner?",
      "answer": "VirusTotal checks ClawHub skills when they are published. Cisco skill-scanner is an open-source static scanner with an optional LLM judge and published accuracy. Ironheights is rules-only and runs on your machine: it scans the copy you install and reports later changes against a baseline. They cover different moments, so using more than one is reasonable.",
      "updated": "2026-10-09"
    },
    {
      "url": "https://ironheights.dev/tools/checklist/",
      "question": "How do I vet an OpenClaw skill before installing it?",
      "answer": "Take about 10 minutes. Work through 16 checks: where the skill comes from, what its SKILL.md asks the agent to do, and what it can reach. Run npx ironheights scan, then answer 8 risk questions for a rating. Everything stays in your browser. It lowers risk; it does not guarantee a skill is harmless.",
      "updated": "2026-10-11"
    },
    {
      "url": "https://ironheights.dev/how-it-works/",
      "question": "How does Ironheights work?",
      "answer": "Ironheights runs on your machine. It reads skill files as text, matches them against fixed rules, and gives a verdict (no findings, review, block or incomplete) and an A to F grade. A saved baseline of hashes shows what was added, changed or removed. safe-install scans a ClawHub skill before installing it. It never executes what it scans.",
      "updated": "2026-10-11"
    },
    {
      "url": "https://ironheights.dev/facts/",
      "question": "What are the key facts about Ironheights?",
      "answer": "Ironheights 0.3.0 is a free, open-source (Apache-2.0) scanner for OpenClaw agent skills that runs on Node.js 20 or later. It has 35 published rules, runs on macOS, Linux and Windows, and has no telemetry. Scans make no network call; only commands you choose, such as fetch, do. A clean scan is not proof of safety.",
      "updated": "2026-10-11"
    },
    {
      "url": "https://ironheights.dev/features/",
      "question": "What is new in Ironheights 0.3.0?",
      "answer": "Version 0.3.0 adds ironheights coexist, which finds other security tools on your machine and reports where they overlap with Ironheights, plus a guard priority setting. The 0.2.0 release added fetch and safe-install, signed baselines, an A to F grade, honest incomplete verdicts and an optional guard plugin that is not a sandbox. Detection is heuristic.",
      "updated": "2026-10-11"
    },
    {
      "url": "https://ironheights.dev/limitations/",
      "question": "What can Ironheights not detect?",
      "answer": "Ironheights cannot see novel or obfuscated attacks its rules do not describe, a compromised host, or social engineering outside the files. Its optional guard plugin is not a sandbox. It reports skipped files and directories as incomplete (exit code 3), not clean. No findings means no rule matched, not that a skill is harmless. Read the skill too.",
      "updated": "2026-10-11"
    }
  ]
}
