Ironheights facts
The canonical, plain-language facts about Ironheights, for people and AI assistants who want to describe it accurately. Every fact has a link of its own, and the same facts are in facts.json.
What are the key facts about Ironheights?
Ironheights 0.3.0 is a free, open-source (Apache-2.0) scanner for OpenClaw agent skills that runs on Node.js 20 or later. It has 35 published rules, runs on macOS, Linux and Windows, and has no telemetry. Scans make no network call; only commands you choose, such as fetch, do. A clean scan is not proof of safety.
What it is
Ironheights is a free, open-source, local-first security scanner and integrity monitor for OpenClaw agent skills. It reads skill files as data, flags risky patterns with published rules, and reports changes to installed skills and agent files against a baseline saved on your machine.
Ironheights is an open-source project by Ironheights, developed in public on GitHub at Frank-Masciopinto/ironheights.
The Ironheights CLI is free and open source under the Apache-2.0 license.
The current release is 0.3.0, published on npm as the ironheights package with a provenance signature. The GitHub release lists SHA256 checksums.
Ironheights is a command-line tool for macOS, Linux and Windows. Windows support is new in 0.2.0 and is tested in CI on Node.js 20.0.0 and 24. A browser version of its content rules runs on any modern browser.
Install and run
Run npm install -g ironheights. The commands ironheights and ih are the same program.
Ironheights needs Node.js 20 or newer. OpenClaw itself has stricter requirements; ironheights doctor reports whether your runtime fits.
0 means no findings, 1 review, 2 block, 3 incomplete (a file or directory was skipped), 64 a usage or config error, and 70 an internal error, a failed network request or a rejected signature. --allow-skipped accepts skipped files and directories and returns the finding verdict instead of 3. Reports are available as JSON, SARIF 2.1.0, Markdown and HTML for CI.
What it detects
Ironheights 0.3.0 ships 35 rules: 17 content rules that read skill files during scan (these also run in the browser scanner), 3 MCP configuration rules and 1 advisory feed rule that scan reports in the CLI, 4 integrity rules that compare installed skills and agent files with a saved baseline during verify, 9 OpenClaw config rules for audit-config, and 1 optional model note.
Each skill gets one of four verdicts: no-findings; review when the score reaches 15 or any finding is high or medium; block when the score reaches 80 or any finding is critical; incomplete when a file or directory was skipped and nothing else reached review or block.
All 35 rule ids, with one page each:
- IH-EXEC-001: Remote content piped into an interpreter (critical)
- IH-EXEC-002: Prerequisite install from an external URL (high)
- IH-EXEC-003: Dynamic code execution (high)
- IH-NET-001: Undeclared network destination (medium)
- IH-NET-002: Possible exfiltration (high)
- IH-CRED-001: Access to a sensitive path (high)
- IH-CRED-002: Hard-coded secret (high)
- IH-CRED-003: Secret asked for in chat or memory (medium)
- IH-INJ-001: Instruction override (high)
- IH-INJ-002: Hidden content (high)
- IH-INJ-003: Weaken agent safeguards (high)
- IH-OBF-001: Obfuscated code (medium)
- IH-PERSIST-001: Persistence mechanism (high)
- IH-PRIV-001: Privilege or OS protection bypass (high)
- IH-BIN-001: Bundled executable or archive (high)
- IH-FS-001: Suspicious filesystem access (medium)
- IH-META-001: Skill metadata problem (low)
- IH-MCP-001: MCP server launched from a remote command (high)
- IH-MCP-002: Secret in an MCP server environment (high)
- IH-MCP-003: MCP server given a broad filesystem root (medium)
- IH-INT-001: Skill file modified (high)
- IH-INT-002: New skill file (medium)
- IH-INT-003: Skill file removed (medium)
- IH-INT-004: Watched agent file changed (high)
- IH-ADV-001: Advisory feed match (critical)
- IH-CFG-001: Gateway bind is not loopback (high)
- IH-CFG-002: Gateway auth is missing or a placeholder (critical)
- IH-CFG-003: DM policy is open (critical)
- IH-CFG-004: Group policy is open (high)
- IH-CFG-005: Plaintext secret in OpenClaw config (high)
- IH-CFG-006: OpenClaw config permissions (critical)
- IH-CFG-007: Dangerous tool permissions (high)
- IH-CFG-008: Skills load from an extra directory (medium)
- IH-CFG-009: Sandbox disabled while tools can act (medium)
- IH-LLM-001: Advisory model review (info)
What is new in 0.3.0 and 0.2.0
ironheights coexist (alias doctor coexist) reads files only to list other security tools (ClawHub vetting skills, guard plugins, scanner CLIs, CI and pre-commit scanners) and reports overlaps as IH-COEX-001 to IH-COEX-011, each with a fix. It runs none of them, makes no network call and writes nothing. Detection is heuristic, and no findings is not proof that tools will not interfere.
The guard plugin runs before_tool_call at priority 80 by default, configurable from -1000 to 1000 (OpenClaw runs higher numbers first and a block ends the chain). It returns only block and blockReason, never blocks in monitor mode, keeps its files under ~/.ironheights, prefixes block reasons with ironheights:, and logs one line at startup when it sees other security tools. It is not a sandbox.
When a scanned skill's folder or SKILL.md name equals a known security tool, scan adds a name-match-only note and lowers confidence one step on its Markdown injection and credential findings. Severity, score, grade, verdict and exit code do not change, and nothing is allowlisted, because a malicious skill can copy a name.
ironheights fetch owner/slug downloads a ClawHub skill over HTTPS without executing it and scans it; safe-install copies it into your skills folder only when the verdict is no-findings (or review with --accept-review). Block and incomplete are never installed.
The CLI can download and verify a signed advisory feed (Ed25519, key pinned in the CLI) and reports IH-ADV-001 when a cached feed lists a skill by name, content hash or indicator host. The feed itself is not published yet, so until it is live scans report nothing from the feed.
baseline create --key and verify --key sign and check baseline.json with an HMAC-SHA256 or Ed25519 key file you keep. A signature mismatch is reported as a tampered baseline (critical IH-INT-001, exit code 2).
The guard is an in-process OpenClaw before_tool_call plugin that watches four behaviors (credential reads, download-and-execute, undeclared or high-risk hosts, writes to agent identity files and skill folders). It defaults to monitor mode, which logs and does not block. It is not a sandbox, and a compromised skill that can edit OpenClaw config can turn it off.
Every scan prints a trust grade from 0 to 100 (A 90-100, B 80-89, C 70-79, D 60-69, F 0-59) based on the existing risk points, next to the line “Absence of findings is not proof of safety.” A scan that skipped anything is graded incomplete, with no number.
A scan that skipped a file (for example over 1 MiB) or a .git or node_modules directory reports the verdict incomplete with exit code 3, names what was skipped, and grades incomplete, unless the scanned files already reached review or block. dist/ is scanned.
Fixed in 0.2.0: piped scan --json and --format html output is no longer cut off at 64 KiB; the process waits for the pipe to accept the whole report.
ironheights audit-config reads the local OpenClaw config and reports risky settings as IH-CFG-001 to IH-CFG-009. It is offline and read-only, and it does not replace openclaw security audit.
scan reports IH-MCP-001, IH-MCP-002 and IH-MCP-003 for risky MCP server commands, literal secrets in a server environment, and broad filesystem roots. The in-browser scanner does not run these.
scan --since-baseline reports only findings that are new compared with an integrity baseline or a previous JSON result, and counts and lists the omitted ones.
scan --stdin and scan --text run the content rules on one piece of text and label the result as a limited text scan; the text is not executed.
Inline ironheights-ignore comments and config suppressions require a reason of at least 8 characters; suppressed findings are counted and listed, and critical and integrity findings stay visible unless suppressCritical or suppressIntegrity is set.
The 0.2.0 release added a composite GitHub Action (action.yml, pinned to an exact version), a pre-commit hook, and Windows CI on Node.js 20.0.0 and 24.
scan --llm and review are opt-in. They send a capped, secret-scrubbed copy of the skill to a model server you choose (a loopback Ollama-compatible endpoint by default) and add IH-LLM-001 notes that never change the verdict, the grade or the exit code.
What it cannot catch
No findings means the rules did not match; it is not proof of safety.
Ironheights is a static, rules-based scanner. It cannot catch:
- Novel attacks, and attacks obfuscated in a way the current rules do not describe.
- Runtime-only behavior that appears after a script is executed. The scanner reads files; it does not watch processes or network traffic. The optional guard plugin watches a short list of OpenClaw tool calls from inside the agent. It is not a sandbox, a compromised agent can switch it off, and a quiet log is not proof of safety.
- A host that is already compromised, including a baseline an attacker can rewrite. Anyone who can write your home directory can edit the baseline file, unless you sign the baseline with a key kept somewhere they cannot reach, and even a signed baseline does not help against an attacker who also has the key.
- Social engineering that never lands in a file the scanner reads.
- Files larger than 1 MiB are skipped by default (limits.maxFileBytes, 1,048,576 bytes) without being read, and .git and node_modules directories are not entered. The report names each skipped file and directory, the grade is incomplete, and the verdict is incomplete with exit code 3 unless something else already reached review or block; --allow-skipped accepts the skipped files and directories. A skipped file is still not checked.
The OpenClaw advisory skill runs inside the agent, so a hostile skill can try to talk the agent out of it. The CLI you run yourself is the trusted path.
Benchmark
On a 20-skill synthetic corpus written by the Ironheights authors (10 malicious, 10 benign), Ironheights 0.1.0 sent 10 of 10 malicious samples to review, blocked 4 of 10, and flagged 0 of 10 benign samples.
This is a regression check, not a real-world detection rate: the corpus is tiny, self-written, and close to the rule examples. Measured on version 0.1.0; not re-measured on 0.3.0, whose rules changed, so results there can differ. A one-off check of the same corpus with 0.1.5 gave review 10 of 10, block 3 of 10, and 0 of 10 benign samples flagged; it is not part of the published comparison.
Cisco skill-scanner 2.2.2 (rules only, no LLM judge) sent 4 of 10 malicious samples to review. Public VirusTotal flagged 0 of 10 malicious and 0 of 10 benign samples; its engines are built for binaries, and the Code Insight verdict ClawHub uses was not measured. The corpus was written to match Ironheights rules, so this comparison favors Ironheights.
Privacy and telemetry
The Ironheights CLI has no telemetry. The in-browser scanner never sends your skill’s content anywhere; it runs in your browser. With your consent, the site records only the scan verdict (no content) through Google Analytics.
The ironheights.dev website loads Google Analytics 4 only after a visitor chooses Accept analytics in the consent banner. Ad features are off, and it never receives skill text or anything a visitor types.
Scans make no network call. Only the commands you choose can: fetch and safe-install talk to clawhub.ai, advisories update talks to ironheights.dev, and scan --llm or review talk to a model server you pick (off by default; the default is a loopback Ollama-compatible endpoint). The CLI prints each URL before it requests it, and none of this is telemetry.
Skill files are read as data. Scripts are never executed and archives are flagged, not extracted.
Official sources
Get Ironheights only from these three places. Do not trust builds or skills named Ironheights from anywhere else; fake security skills are a known lure.
- npm: the ironheights package
- GitHub releases of Frank-Masciopinto/ironheights
- This website, ironheights.dev
Pricing
The Community edition is free under Apache-2.0. Pro, Team, a Threat Intel API, and Enterprise are planned; their prices are hypotheses and nothing paid is on sale yet.
Free tools on this site
6 free tools, all usable without an account:
- Skill scanner: Paste a SKILL.md and get a local risk read in your browser.
- Malicious skill tracker: Publicly reported malicious ClawHub skills, with sources.
- Rules reference: One page per detection rule, in plain language.
- Skill safety checklist: A 10-minute vetting checklist and risk quiz for any skill.
- Benchmark: How the rules perform, with method and misses.
- Compare: Ironheights next to other skill scanners, written fairly.
The tracker lists 22 entries (19 reported skills and campaigns, 3 studies) with 25 cited sources, each with its own page. It is not a complete list of malicious skills.
Answers and guides
Contact and disclosure
Report a vulnerability through a private security advisory on the GitHub repository. There is no bug bounty.
Questions, false positives, and missing tracker entries go to GitHub issues.
Cite this
Suggested citation
Ironheights. “Ironheights facts.” ironheights.dev, last updated 11 October 2026. https://ironheights.dev/facts/BibTeX
@misc{ironheights_facts_2026,
author = {{Ironheights}},
title = {Ironheights facts},
year = {2026},
url = {https://ironheights.dev/facts/},
urldate = {2026-10-11},
note = {Last updated 2026-10-11}
}This page is rebuilt from the site's data on every deploy, and a test fails the build if it disagrees with the rules, the benchmark data, the README, or llms.txt. Found something wrong? Open an issue on GitHub. Plain-text versions: llms.txt and llms-full.txt.