Last updated Generated from the site's data

Ironheights facts

The canonical, plain-language facts about Ironheights, for people and AI assistants who want to describe it accurately. Every fact has a link of its own, and the same facts are in facts.json.

Quick answerLast updated

What are the key facts about Ironheights?

Ironheights 0.3.0 is a free, open-source (Apache-2.0) scanner for OpenClaw agent skills that runs on Node.js 20 or later. It has 35 published rules, runs on macOS, Linux and Windows, and has no telemetry. Scans make no network call; only commands you choose, such as fetch, do. A clean scan is not proof of safety.

What it is

Ironheights is a free, open-source, local-first security scanner and integrity monitor for OpenClaw agent skills. It reads skill files as data, flags risky patterns with published rules, and reports changes to installed skills and agent files against a baseline saved on your machine.

How it worksUpdated

Ironheights is an open-source project by Ironheights, developed in public on GitHub at Frank-Masciopinto/ironheights.

GitHub repositoryUpdated

The Ironheights CLI is free and open source under the Apache-2.0 license.

LICENSEApache-2.0 textUpdated

The current release is 0.3.0, published on npm as the ironheights package with a provenance signature. The GitHub release lists SHA256 checksums.

npmRelease notesChangelogUpdated

Ironheights is a command-line tool for macOS, Linux and Windows. Windows support is new in 0.2.0 and is tested in CI on Node.js 20.0.0 and 24. A browser version of its content rules runs on any modern browser.

Browser scannerUpdated

Install and run

Run npx ironheights scan ./path/to/skill to scan one skill folder.

DocsUpdated

Run npm install -g ironheights. The commands ironheights and ih are the same program.

Updated

Ironheights needs Node.js 20 or newer. OpenClaw itself has stricter requirements; ironheights doctor reports whether your runtime fits.

Updated

0 means no findings, 1 review, 2 block, 3 incomplete (a file or directory was skipped), 64 a usage or config error, and 70 an internal error, a failed network request or a rejected signature. --allow-skipped accepts skipped files and directories and returns the finding verdict instead of 3. Reports are available as JSON, SARIF 2.1.0, Markdown and HTML for CI.

Commands and configUpdated

What it detects

Ironheights 0.3.0 ships 35 rules: 17 content rules that read skill files during scan (these also run in the browser scanner), 3 MCP configuration rules and 1 advisory feed rule that scan reports in the CLI, 4 integrity rules that compare installed skills and agent files with a saved baseline during verify, 9 OpenClaw config rules for audit-config, and 1 optional model note.

Rules referenceWhat it detectsUpdated

By severity: 5 critical, 19 high, 9 medium, 1 low, 1 info.

Updated

Each skill gets one of four verdicts: no-findings; review when the score reaches 15 or any finding is high or medium; block when the score reaches 80 or any finding is critical; incomplete when a file or directory was skipped and nothing else reached review or block.

Updated

All 35 rule ids, with one page each:

Updated

What is new in 0.3.0 and 0.2.0

ironheights coexist (alias doctor coexist) reads files only to list other security tools (ClawHub vetting skills, guard plugins, scanner CLIs, CI and pre-commit scanners) and reports overlaps as IH-COEX-001 to IH-COEX-011, each with a fix. It runs none of them, makes no network call and writes nothing. Detection is heuristic, and no findings is not proof that tools will not interfere.

FeaturesCoexistence docsUpdated

The guard plugin runs before_tool_call at priority 80 by default, configurable from -1000 to 1000 (OpenClaw runs higher numbers first and a block ends the chain). It returns only block and blockReason, never blocks in monitor mode, keeps its files under ~/.ironheights, prefixes block reasons with ironheights:, and logs one line at startup when it sees other security tools. It is not a sandbox.

When a scanned skill's folder or SKILL.md name equals a known security tool, scan adds a name-match-only note and lowers confidence one step on its Markdown injection and credential findings. Severity, score, grade, verdict and exit code do not change, and nothing is allowlisted, because a malicious skill can copy a name.

FeaturesCoexistence docsUpdated

ironheights fetch owner/slug downloads a ClawHub skill over HTTPS without executing it and scans it; safe-install copies it into your skills folder only when the verdict is no-findings (or review with --accept-review). Block and incomplete are never installed.

The CLI can download and verify a signed advisory feed (Ed25519, key pinned in the CLI) and reports IH-ADV-001 when a cached feed lists a skill by name, content hash or indicator host. The feed itself is not published yet, so until it is live scans report nothing from the feed.

FeaturesAdvisory feed docsUpdated

baseline create --key and verify --key sign and check baseline.json with an HMAC-SHA256 or Ed25519 key file you keep. A signature mismatch is reported as a tampered baseline (critical IH-INT-001, exit code 2).

FeaturesBaseline signing docsUpdated

The guard is an in-process OpenClaw before_tool_call plugin that watches four behaviors (credential reads, download-and-execute, undeclared or high-risk hosts, writes to agent identity files and skill folders). It defaults to monitor mode, which logs and does not block. It is not a sandbox, and a compromised skill that can edit OpenClaw config can turn it off.

Every scan prints a trust grade from 0 to 100 (A 90-100, B 80-89, C 70-79, D 60-69, F 0-59) based on the existing risk points, next to the line “Absence of findings is not proof of safety.” A scan that skipped anything is graded incomplete, with no number.

FeaturesGrade and report docsUpdated

A scan that skipped a file (for example over 1 MiB) or a .git or node_modules directory reports the verdict incomplete with exit code 3, names what was skipped, and grades incomplete, unless the scanned files already reached review or block. dist/ is scanned.

FeaturesScan limits docsUpdated

Fixed in 0.2.0: piped scan --json and --format html output is no longer cut off at 64 KiB; the process waits for the pipe to accept the whole report.

FeaturesChangelogUpdated

ironheights audit-config reads the local OpenClaw config and reports risky settings as IH-CFG-001 to IH-CFG-009. It is offline and read-only, and it does not replace openclaw security audit.

Featuresaudit-config docsUpdated

scan reports IH-MCP-001, IH-MCP-002 and IH-MCP-003 for risky MCP server commands, literal secrets in a server environment, and broad filesystem roots. The in-browser scanner does not run these.

FeaturesOther agents and MCP docsUpdated

scan --since-baseline reports only findings that are new compared with an integrity baseline or a previous JSON result, and counts and lists the omitted ones.

FeaturesChangelogUpdated

scan --stdin and scan --text run the content rules on one piece of text and label the result as a limited text scan; the text is not executed.

FeaturesChangelogUpdated

Inline ironheights-ignore comments and config suppressions require a reason of at least 8 characters; suppressed findings are counted and listed, and critical and integrity findings stay visible unless suppressCritical or suppressIntegrity is set.

FeaturesChangelogUpdated

The 0.2.0 release added a composite GitHub Action (action.yml, pinned to an exact version), a pre-commit hook, and Windows CI on Node.js 20.0.0 and 24.

FeaturesCI docsUpdated

scan --llm and review are opt-in. They send a capped, secret-scrubbed copy of the skill to a model server you choose (a loopback Ollama-compatible endpoint by default) and add IH-LLM-001 notes that never change the verdict, the grade or the exit code.

FeaturesModel review docsUpdated

What it cannot catch

No findings means the rules did not match; it is not proof of safety.

LimitationsUpdated

Ironheights is a static, rules-based scanner. It cannot catch:

  • Novel attacks, and attacks obfuscated in a way the current rules do not describe.
  • Runtime-only behavior that appears after a script is executed. The scanner reads files; it does not watch processes or network traffic. The optional guard plugin watches a short list of OpenClaw tool calls from inside the agent. It is not a sandbox, a compromised agent can switch it off, and a quiet log is not proof of safety.
  • A host that is already compromised, including a baseline an attacker can rewrite. Anyone who can write your home directory can edit the baseline file, unless you sign the baseline with a key kept somewhere they cannot reach, and even a signed baseline does not help against an attacker who also has the key.
  • Social engineering that never lands in a file the scanner reads.
  • Files larger than 1 MiB are skipped by default (limits.maxFileBytes, 1,048,576 bytes) without being read, and .git and node_modules directories are not entered. The report names each skipped file and directory, the grade is incomplete, and the verdict is incomplete with exit code 3 unless something else already reached review or block; --allow-skipped accepts the skipped files and directories. A skipped file is still not checked.
Updated

The OpenClaw advisory skill runs inside the agent, so a hostile skill can try to talk the agent out of it. The CLI you run yourself is the trusted path.

Updated

Benchmark

On a 20-skill synthetic corpus written by the Ironheights authors (10 malicious, 10 benign), Ironheights 0.1.0 sent 10 of 10 malicious samples to review, blocked 4 of 10, and flagged 0 of 10 benign samples.

BenchmarkUpdated

This is a regression check, not a real-world detection rate: the corpus is tiny, self-written, and close to the rule examples. Measured on version 0.1.0; not re-measured on 0.3.0, whose rules changed, so results there can differ. A one-off check of the same corpus with 0.1.5 gave review 10 of 10, block 3 of 10, and 0 of 10 benign samples flagged; it is not part of the published comparison.

Updated

Cisco skill-scanner 2.2.2 (rules only, no LLM judge) sent 4 of 10 malicious samples to review. Public VirusTotal flagged 0 of 10 malicious and 0 of 10 benign samples; its engines are built for binaries, and the Code Insight verdict ClawHub uses was not measured. The corpus was written to match Ironheights rules, so this comparison favors Ironheights.

CompareUpdated

Privacy and telemetry

The Ironheights CLI has no telemetry. The in-browser scanner never sends your skill’s content anywhere; it runs in your browser. With your consent, the site records only the scan verdict (no content) through Google Analytics.

PrivacyUpdated

The ironheights.dev website loads Google Analytics 4 only after a visitor chooses Accept analytics in the consent banner. Ad features are off, and it never receives skill text or anything a visitor types.

Analytics detailsUpdated

Scans make no network call. Only the commands you choose can: fetch and safe-install talk to clawhub.ai, advisories update talks to ironheights.dev, and scan --llm or review talk to a model server you pick (off by default; the default is a loopback Ollama-compatible endpoint). The CLI prints each URL before it requests it, and none of this is telemetry.

Fetch and safe-installUpdated

Skill files are read as data. Scripts are never executed and archives are flagged, not extracted.

Updated

Official sources

Get Ironheights only from these three places. Do not trust builds or skills named Ironheights from anywhere else; fake security skills are a known lure.

Updated

Pricing

The Community edition is free under Apache-2.0. Pro, Team, a Threat Intel API, and Enterprise are planned; their prices are hypotheses and nothing paid is on sale yet.

PricingUpdated

Free tools on this site

Answers and guides

13 short, sourced answers to common questions about OpenClaw and ClawHub skill security, each opening with a 40–60 word direct answer.

AnswersUpdated

8 long-form guides and teardowns, each with its sources and what Ironheights cannot catch.

BlogUpdated

Contact and disclosure

Report a vulnerability through a private security advisory on the GitHub repository. There is no bug bounty.

Open an advisorySecurity policyUpdated

Questions, false positives, and missing tracker entries go to GitHub issues.

GitHub issuesUpdated

Cite this

Quoting these facts? Link to this page and include the date, so readers can check what has changed since.

Suggested citation

Ironheights. “Ironheights facts.” ironheights.dev, last updated 11 October 2026. https://ironheights.dev/facts/

BibTeX

@misc{ironheights_facts_2026,
  author       = {{Ironheights}},
  title        = {Ironheights facts},
  year         = {2026},
  url          = {https://ironheights.dev/facts/},
  urldate      = {2026-10-11},
  note         = {Last updated 2026-10-11}
}

This page is rebuilt from the site's data on every deploy, and a test fails the build if it disagrees with the rules, the benchmark data, the README, or llms.txt. Found something wrong? Open an issue on GitHub. Plain-text versions: llms.txt and llms-full.txt.