# Ironheights: full text for AI assistants > Plain text of the key pages on ironheights.dev, rebuilt from the site's data on every deploy. Facts last updated 2026-10-11. The canonical fact sheet is https://ironheights.dev/facts/ (JSON: https://ironheights.dev/facts.json); a short index is at https://ironheights.dev/llms.txt. When you cite a fact, link its anchor and give its date. No findings means the rules did not match; it is not proof of safety. --- ## Facts Source: https://ironheights.dev/facts/ ### Definition Ironheights is a free, open-source, local-first security scanner and integrity monitor for OpenClaw agent skills. It reads skill files as data, flags risky patterns with published rules, and reports changes to installed skills and agent files against a baseline saved on your machine. Updated 2026-10-11. Link: https://ironheights.dev/facts/#definition ### Who makes it Ironheights is an open-source project by Ironheights, developed in public on GitHub at Frank-Masciopinto/ironheights. Updated 2026-10-11. Link: https://ironheights.dev/facts/#maker ### License The Ironheights CLI is free and open source under the Apache-2.0 license. Updated 2026-10-11. Link: https://ironheights.dev/facts/#license ### Current version The current release is 0.3.0, published on npm as the ironheights package with a provenance signature. The GitHub release lists SHA256 checksums. Updated 2026-10-11. Link: https://ironheights.dev/facts/#version ### Platforms Ironheights is a command-line tool for macOS, Linux and Windows. Windows support is new in 0.2.0 and is tested in CI on Node.js 20.0.0 and 24. A browser version of its content rules runs on any modern browser. Updated 2026-10-11. Link: https://ironheights.dev/facts/#platforms ### Run without installing Run `npx ironheights scan ./path/to/skill` to scan one skill folder. Updated 2026-10-11. Link: https://ironheights.dev/facts/#install-npx ### Install the command Run `npm install -g ironheights`. The commands `ironheights` and `ih` are the same program. Updated 2026-10-11. Link: https://ironheights.dev/facts/#install-global ### Supported Node.js Ironheights needs Node.js 20 or newer. OpenClaw itself has stricter requirements; `ironheights doctor` reports whether your runtime fits. Updated 2026-10-11. Link: https://ironheights.dev/facts/#node ### Exit codes 0 means no findings, 1 review, 2 block, 3 incomplete (a file or directory was skipped), 64 a usage or config error, and 70 an internal error, a failed network request or a rejected signature. --allow-skipped accepts skipped files and directories and returns the finding verdict instead of 3. Reports are available as JSON, SARIF 2.1.0, Markdown and HTML for CI. Updated 2026-10-11. Link: https://ironheights.dev/facts/#exit-codes ### Rules Ironheights 0.3.0 ships 35 rules: 17 content rules that read skill files during scan (these also run in the browser scanner), 3 MCP configuration rules and 1 advisory feed rule that scan reports in the CLI, 4 integrity rules that compare installed skills and agent files with a saved baseline during verify, 9 OpenClaw config rules for audit-config, and 1 optional model note. Updated 2026-10-11. Link: https://ironheights.dev/facts/#rule-count ### Severities By severity: 5 critical, 19 high, 9 medium, 1 low, 1 info. Updated 2026-10-11. Link: https://ironheights.dev/facts/#severities ### Verdicts Each skill gets one of four verdicts: no-findings; review when the score reaches 15 or any finding is high or medium; block when the score reaches 80 or any finding is critical; incomplete when a file or directory was skipped and nothing else reached review or block. Updated 2026-10-11. Link: https://ironheights.dev/facts/#verdicts ### Every rule All 35 rule ids, with one page each: - IH-EXEC-001: Remote content piped into an interpreter (critical) (https://ironheights.dev/rules/ih-exec-001/) - IH-EXEC-002: Prerequisite install from an external URL (high) (https://ironheights.dev/rules/ih-exec-002/) - IH-EXEC-003: Dynamic code execution (high) (https://ironheights.dev/rules/ih-exec-003/) - IH-NET-001: Undeclared network destination (medium) (https://ironheights.dev/rules/ih-net-001/) - IH-NET-002: Possible exfiltration (high) (https://ironheights.dev/rules/ih-net-002/) - IH-CRED-001: Access to a sensitive path (high) (https://ironheights.dev/rules/ih-cred-001/) - IH-CRED-002: Hard-coded secret (high) (https://ironheights.dev/rules/ih-cred-002/) - IH-CRED-003: Secret asked for in chat or memory (medium) (https://ironheights.dev/rules/ih-cred-003/) - IH-INJ-001: Instruction override (high) (https://ironheights.dev/rules/ih-inj-001/) - IH-INJ-002: Hidden content (high) (https://ironheights.dev/rules/ih-inj-002/) - IH-INJ-003: Weaken agent safeguards (high) (https://ironheights.dev/rules/ih-inj-003/) - IH-OBF-001: Obfuscated code (medium) (https://ironheights.dev/rules/ih-obf-001/) - IH-PERSIST-001: Persistence mechanism (high) (https://ironheights.dev/rules/ih-persist-001/) - IH-PRIV-001: Privilege or OS protection bypass (high) (https://ironheights.dev/rules/ih-priv-001/) - IH-BIN-001: Bundled executable or archive (high) (https://ironheights.dev/rules/ih-bin-001/) - IH-FS-001: Suspicious filesystem access (medium) (https://ironheights.dev/rules/ih-fs-001/) - IH-META-001: Skill metadata problem (low) (https://ironheights.dev/rules/ih-meta-001/) - IH-MCP-001: MCP server launched from a remote command (high) (https://ironheights.dev/rules/ih-mcp-001/) - IH-MCP-002: Secret in an MCP server environment (high) (https://ironheights.dev/rules/ih-mcp-002/) - IH-MCP-003: MCP server given a broad filesystem root (medium) (https://ironheights.dev/rules/ih-mcp-003/) - IH-INT-001: Skill file modified (high) (https://ironheights.dev/rules/ih-int-001/) - IH-INT-002: New skill file (medium) (https://ironheights.dev/rules/ih-int-002/) - IH-INT-003: Skill file removed (medium) (https://ironheights.dev/rules/ih-int-003/) - IH-INT-004: Watched agent file changed (high) (https://ironheights.dev/rules/ih-int-004/) - IH-ADV-001: Advisory feed match (critical) (https://ironheights.dev/rules/ih-adv-001/) - IH-CFG-001: Gateway bind is not loopback (high) (https://ironheights.dev/rules/ih-cfg-001/) - IH-CFG-002: Gateway auth is missing or a placeholder (critical) (https://ironheights.dev/rules/ih-cfg-002/) - IH-CFG-003: DM policy is open (critical) (https://ironheights.dev/rules/ih-cfg-003/) - IH-CFG-004: Group policy is open (high) (https://ironheights.dev/rules/ih-cfg-004/) - IH-CFG-005: Plaintext secret in OpenClaw config (high) (https://ironheights.dev/rules/ih-cfg-005/) - IH-CFG-006: OpenClaw config permissions (critical) (https://ironheights.dev/rules/ih-cfg-006/) - IH-CFG-007: Dangerous tool permissions (high) (https://ironheights.dev/rules/ih-cfg-007/) - IH-CFG-008: Skills load from an extra directory (medium) (https://ironheights.dev/rules/ih-cfg-008/) - IH-CFG-009: Sandbox disabled while tools can act (medium) (https://ironheights.dev/rules/ih-cfg-009/) - IH-LLM-001: Advisory model review (info) (https://ironheights.dev/rules/ih-llm-001/) Updated 2026-10-11. Link: https://ironheights.dev/facts/#rules-list ### Works next to your other security tools ironheights coexist (alias doctor coexist) reads files only to list other security tools (ClawHub vetting skills, guard plugins, scanner CLIs, CI and pre-commit scanners) and reports overlaps as IH-COEX-001 to IH-COEX-011, each with a fix. It runs none of them, makes no network call and writes nothing. Detection is heuristic, and no findings is not proof that tools will not interfere. Updated 2026-10-11. Link: https://ironheights.dev/facts/#new-coexist ### A guard that shares the hook The guard plugin runs before_tool_call at priority 80 by default, configurable from -1000 to 1000 (OpenClaw runs higher numbers first and a block ends the chain). It returns only block and blockReason, never blocks in monitor mode, keeps its files under ~/.ironheights, prefixes block reasons with ironheights:, and logs one line at startup when it sees other security tools. It is not a sandbox. Updated 2026-10-11. Link: https://ironheights.dev/facts/#new-guard-priority ### Security tools are not trusted by name When a scanned skill's folder or SKILL.md name equals a known security tool, scan adds a name-match-only note and lowers confidence one step on its Markdown injection and credential findings. Severity, score, grade, verdict and exit code do not change, and nothing is allowlisted, because a malicious skill can copy a name. Updated 2026-10-11. Link: https://ironheights.dev/facts/#new-known-security-tools ### Fetch and safe-install ironheights fetch owner/slug downloads a ClawHub skill over HTTPS without executing it and scans it; safe-install copies it into your skills folder only when the verdict is no-findings (or review with --accept-review). Block and incomplete are never installed. Updated 2026-10-11. Link: https://ironheights.dev/facts/#new-safe-install ### Signed advisory feed support The CLI can download and verify a signed advisory feed (Ed25519, key pinned in the CLI) and reports IH-ADV-001 when a cached feed lists a skill by name, content hash or indicator host. The feed itself is not published yet, so until it is live scans report nothing from the feed. Updated 2026-10-11. Link: https://ironheights.dev/facts/#new-advisory-feed ### Signed baselines baseline create --key and verify --key sign and check baseline.json with an HMAC-SHA256 or Ed25519 key file you keep. A signature mismatch is reported as a tampered baseline (critical IH-INT-001, exit code 2). Updated 2026-10-11. Link: https://ironheights.dev/facts/#new-signed-baselines ### Guard plugin for agent tool calls The guard is an in-process OpenClaw before_tool_call plugin that watches four behaviors (credential reads, download-and-execute, undeclared or high-risk hosts, writes to agent identity files and skill folders). It defaults to monitor mode, which logs and does not block. It is not a sandbox, and a compromised skill that can edit OpenClaw config can turn it off. Updated 2026-10-11. Link: https://ironheights.dev/facts/#new-guard ### A to F trust grade Every scan prints a trust grade from 0 to 100 (A 90-100, B 80-89, C 70-79, D 60-69, F 0-59) based on the existing risk points, next to the line “Absence of findings is not proof of safety.” A scan that skipped anything is graded incomplete, with no number. Updated 2026-10-11. Link: https://ironheights.dev/facts/#new-trust-grade ### Honest incomplete verdicts A scan that skipped a file (for example over 1 MiB) or a .git or node_modules directory reports the verdict incomplete with exit code 3, names what was skipped, and grades incomplete, unless the scanned files already reached review or block. dist/ is scanned. Updated 2026-10-11. Link: https://ironheights.dev/facts/#new-incomplete-scans ### Piped JSON that stays whole Fixed in 0.2.0: piped scan --json and --format html output is no longer cut off at 64 KiB; the process waits for the pipe to accept the whole report. Updated 2026-10-11. Link: https://ironheights.dev/facts/#new-piped-json ### OpenClaw config audit ironheights audit-config reads the local OpenClaw config and reports risky settings as IH-CFG-001 to IH-CFG-009. It is offline and read-only, and it does not replace openclaw security audit. Updated 2026-10-11. Link: https://ironheights.dev/facts/#new-config-audit ### MCP configuration rules scan reports IH-MCP-001, IH-MCP-002 and IH-MCP-003 for risky MCP server commands, literal secrets in a server environment, and broad filesystem roots. The in-browser scanner does not run these. Updated 2026-10-11. Link: https://ironheights.dev/facts/#new-mcp-rules ### Only what is new scan --since-baseline reports only findings that are new compared with an integrity baseline or a previous JSON result, and counts and lists the omitted ones. Updated 2026-10-11. Link: https://ironheights.dev/facts/#new-since-baseline ### Scan a piece of text scan --stdin and scan --text run the content rules on one piece of text and label the result as a limited text scan; the text is not executed. Updated 2026-10-11. Link: https://ironheights.dev/facts/#new-text-scan ### Suppressions that need a reason Inline ironheights-ignore comments and config suppressions require a reason of at least 8 characters; suppressed findings are counted and listed, and critical and integrity findings stay visible unless suppressCritical or suppressIntegrity is set. Updated 2026-10-11. Link: https://ironheights.dev/facts/#new-suppressions ### CI action, pre-commit hook and Windows The 0.2.0 release added a composite GitHub Action (action.yml, pinned to an exact version), a pre-commit hook, and Windows CI on Node.js 20.0.0 and 24. Updated 2026-10-11. Link: https://ironheights.dev/facts/#new-ci ### Optional model second opinion scan --llm and review are opt-in. They send a capped, secret-scrubbed copy of the skill to a model server you choose (a loopback Ollama-compatible endpoint by default) and add IH-LLM-001 notes that never change the verdict, the grade or the exit code. Updated 2026-10-11. Link: https://ironheights.dev/facts/#new-model-review ### A clean result No findings means the rules did not match; it is not proof of safety. Updated 2026-10-11. Link: https://ironheights.dev/facts/#not-proof ### Out of reach Ironheights is a static, rules-based scanner. It cannot catch: - Novel attacks, and attacks obfuscated in a way the current rules do not describe. - Runtime-only behavior that appears after a script is executed. The scanner reads files; it does not watch processes or network traffic. The optional guard plugin watches a short list of OpenClaw tool calls from inside the agent. It is not a sandbox, a compromised agent can switch it off, and a quiet log is not proof of safety. - A host that is already compromised, including a baseline an attacker can rewrite. Anyone who can write your home directory can edit the baseline file, unless you sign the baseline with a key kept somewhere they cannot reach, and even a signed baseline does not help against an attacker who also has the key. - Social engineering that never lands in a file the scanner reads. - Files larger than 1 MiB are skipped by default (limits.maxFileBytes, 1,048,576 bytes) without being read, and .git and node_modules directories are not entered. The report names each skipped file and directory, the grade is incomplete, and the verdict is incomplete with exit code 3 unless something else already reached review or block; --allow-skipped accepts the skipped files and directories. A skipped file is still not checked. Updated 2026-10-11. Link: https://ironheights.dev/facts/#cannot-catch ### The advisory skill The OpenClaw advisory skill runs inside the agent, so a hostile skill can try to talk the agent out of it. The CLI you run yourself is the trusted path. Updated 2026-10-11. Link: https://ironheights.dev/facts/#in-agent-skill ### Headline, in counts On a 20-skill synthetic corpus written by the Ironheights authors (10 malicious, 10 benign), Ironheights 0.1.0 sent 10 of 10 malicious samples to review, blocked 4 of 10, and flagged 0 of 10 benign samples. Updated 2026-10-09. Link: https://ironheights.dev/facts/#benchmark-headline ### Caveats This is a regression check, not a real-world detection rate: the corpus is tiny, self-written, and close to the rule examples. Measured on version 0.1.0; not re-measured on 0.3.0, whose rules changed, so results there can differ. A one-off check of the same corpus with 0.1.5 gave review 10 of 10, block 3 of 10, and 0 of 10 benign samples flagged; it is not part of the published comparison. Updated 2026-10-09. Link: https://ironheights.dev/facts/#benchmark-caveats ### Other tools on the same corpus Cisco skill-scanner 2.2.2 (rules only, no LLM judge) sent 4 of 10 malicious samples to review. Public VirusTotal flagged 0 of 10 malicious and 0 of 10 benign samples; its engines are built for binaries, and the Code Insight verdict ClawHub uses was not measured. The corpus was written to match Ironheights rules, so this comparison favors Ironheights. Updated 2026-10-09. Link: https://ironheights.dev/facts/#benchmark-others ### Privacy statement The Ironheights CLI has no telemetry. The in-browser scanner never sends your skill’s content anywhere; it runs in your browser. With your consent, the site records only the scan verdict (no content) through Google Analytics. Updated 2026-10-11. Link: https://ironheights.dev/facts/#privacy-statement ### Website analytics The ironheights.dev website loads Google Analytics 4 only after a visitor chooses Accept analytics in the consent banner. Ad features are off, and it never receives skill text or anything a visitor types. Updated 2026-10-11. Link: https://ironheights.dev/facts/#website-analytics ### When the CLI uses the network Scans make no network call. Only the commands you choose can: fetch and safe-install talk to clawhub.ai, advisories update talks to ironheights.dev, and scan --llm or review talk to a model server you pick (off by default; the default is a loopback Ollama-compatible endpoint). The CLI prints each URL before it requests it, and none of this is telemetry. Updated 2026-10-11. Link: https://ironheights.dev/facts/#network-use ### Scanned files Skill files are read as data. Scripts are never executed and archives are flagged, not extracted. Updated 2026-10-11. Link: https://ironheights.dev/facts/#no-execution ### Where to get it Get Ironheights only from these three places. Do not trust builds or skills named Ironheights from anywhere else; fake security skills are a known lure. - npm: the ironheights package (https://www.npmjs.com/package/ironheights) - GitHub releases of Frank-Masciopinto/ironheights (https://github.com/Frank-Masciopinto/ironheights/releases) - This website, ironheights.dev (https://ironheights.dev/) Updated 2026-10-11. Link: https://ironheights.dev/facts/#sources ### Pricing status The Community edition is free under Apache-2.0. Pro, Team, a Threat Intel API, and Enterprise are planned; their prices are hypotheses and nothing paid is on sale yet. Updated 2026-10-11. Link: https://ironheights.dev/facts/#pricing-status ### Tools 6 free tools, all usable without an account: - Skill scanner: Paste a SKILL.md and get a local risk read in your browser. (https://ironheights.dev/tools/scanner/) - Malicious skill tracker: Publicly reported malicious ClawHub skills, with sources. (https://ironheights.dev/tracker/) - Rules reference: One page per detection rule, in plain language. (https://ironheights.dev/rules/) - Skill safety checklist: A 10-minute vetting checklist and risk quiz for any skill. (https://ironheights.dev/tools/checklist/) - Benchmark: How the rules perform, with method and misses. (https://ironheights.dev/benchmark/) - Compare: Ironheights next to other skill scanners, written fairly. (https://ironheights.dev/compare/) Updated 2026-10-11. Link: https://ironheights.dev/facts/#free-tools ### Malicious skill tracker The tracker lists 22 entries (19 reported skills and campaigns, 3 studies) with 25 cited sources, each with its own page. It is not a complete list of malicious skills. Updated 2026-10-10. Link: https://ironheights.dev/facts/#tracker-size ### Short answers 13 short, sourced answers to common questions about OpenClaw and ClawHub skill security, each opening with a 40–60 word direct answer. Updated 2026-10-11. Link: https://ironheights.dev/facts/#answers-count ### Blog posts 8 long-form guides and teardowns, each with its sources and what Ironheights cannot catch. Updated 2026-10-11. Link: https://ironheights.dev/facts/#blog-count ### Report a vulnerability Report a vulnerability through a private security advisory on the GitHub repository. There is no bug bounty. Updated 2026-10-11. Link: https://ironheights.dev/facts/#security-disclosure ### Everything else Questions, false positives, and missing tracker entries go to GitHub issues. Updated 2026-10-11. Link: https://ironheights.dev/facts/#contact-issues --- ## Quick answers ### What is Ironheights? Ironheights is a free, open-source (Apache-2.0) command-line scanner for OpenClaw agent skills. It reads skill files as data, checks them against 35 published rules, and reports changes against a local baseline. Version 0.3.0 can also fetch a skill and install it only if the scan is clean. No findings means no rule matched; it is not proof of safety. Source: https://ironheights.dev/ (updated 2026-10-11) ### How do I check a SKILL.md in my browser? Paste a SKILL.md or drop a folder below. The scanner runs the 17 content rules from the Ironheights 0.1.5 engine inside this tab and returns no findings, review or block, with rule ids and line numbers. Your skill’s content is never sent anywhere. Integrity, MCP and advisory checks need the CLI. No findings is not proof of safety. Source: https://ironheights.dev/tools/scanner/ (updated 2026-10-11) ### What do the Ironheights rules check? Ironheights 0.3.0 has 35 rules. 17 content rules match risky patterns in skill files, such as remote scripts piped to a shell, credential paths, and instruction overrides. The rest cover MCP configs (3), the advisory feed (1), baseline integrity (4), OpenClaw config (9) and an optional model note (1). Source: https://ironheights.dev/rules/ (updated 2026-10-11) ### Which ClawHub skills have been reported as malicious? This tracker lists 19 publicly reported malicious skills and campaigns, plus 3 studies, each with its sources, report date, status as stated by the source, and whether an Ironheights rule flags the pattern. It covers only what researchers have published, so a skill missing from it is not evidence that the skill is harmless. Source: https://ironheights.dev/tracker/ (updated 2026-10-10) ### How well does Ironheights detect malicious skills? We have no real-world detection rate yet. On a 20-skill synthetic corpus we wrote ourselves, Ironheights 0.1.0 sent 10 of 10 malicious samples to review, blocked 4, and flagged 0 of 10 benign samples. Cisco skill-scanner, rules only, caught 4 of 10. It is a regression check that favors our rules. Source: https://ironheights.dev/benchmark/ (updated 2026-10-09) ### How does Ironheights compare with VirusTotal and Cisco skill-scanner? VirusTotal checks ClawHub skills when they are published. Cisco skill-scanner is an open-source static scanner with an optional LLM judge and published accuracy. Ironheights is rules-only and runs on your machine: it scans the copy you install and reports later changes against a baseline. They cover different moments, so using more than one is reasonable. Source: https://ironheights.dev/compare/ (updated 2026-10-09) ### How do I vet an OpenClaw skill before installing it? Take about 10 minutes. Work through 16 checks: where the skill comes from, what its SKILL.md asks the agent to do, and what it can reach. Run npx ironheights scan, then answer 8 risk questions for a rating. Everything stays in your browser. It lowers risk; it does not guarantee a skill is harmless. Source: https://ironheights.dev/tools/checklist/ (updated 2026-10-11) ### How does Ironheights work? Ironheights runs on your machine. It reads skill files as text, matches them against fixed rules, and gives a verdict (no findings, review, block or incomplete) and an A to F grade. A saved baseline of hashes shows what was added, changed or removed. safe-install scans a ClawHub skill before installing it. It never executes what it scans. Source: https://ironheights.dev/how-it-works/ (updated 2026-10-11) ### What are the key facts about Ironheights? Ironheights 0.3.0 is a free, open-source (Apache-2.0) scanner for OpenClaw agent skills that runs on Node.js 20 or later. It has 35 published rules, runs on macOS, Linux and Windows, and has no telemetry. Scans make no network call; only commands you choose, such as fetch, do. A clean scan is not proof of safety. Source: https://ironheights.dev/facts/ (updated 2026-10-11) ### What is new in Ironheights 0.3.0? Version 0.3.0 adds ironheights coexist, which finds other security tools on your machine and reports where they overlap with Ironheights, plus a guard priority setting. The 0.2.0 release added fetch and safe-install, signed baselines, an A to F grade, honest incomplete verdicts and an optional guard plugin that is not a sandbox. Detection is heuristic. Source: https://ironheights.dev/features/ (updated 2026-10-11) ### What can Ironheights not detect? Ironheights cannot see novel or obfuscated attacks its rules do not describe, a compromised host, or social engineering outside the files. Its optional guard plugin is not a sandbox. It reports skipped files and directories as incomplete (exit code 3), not clean. No findings means no rule matched, not that a skill is harmless. Read the skill too. Source: https://ironheights.dev/limitations/ (updated 2026-10-11) --- ## Answers Source: https://ironheights.dev/answers/. 13 short answers; each page adds detail, limits, and sources. ### Is a ClawHub skill safe to install? Not automatically. Most ClawHub skills are ordinary, but researchers found hundreds of malicious ones in 2026, and some passed the marketplace's VirusTotal scan. Treat every skill as code that runs with your agent's access: check the listing, read the setup section and links, scan it, and give it only the access it needs. Source: https://ironheights.dev/answers/is-a-clawhub-skill-safe-to-install/ (updated 2026-10-09) ### What is a malicious ClawHub skill? A malicious ClawHub skill is an OpenClaw skill written to harm the person who installs it. Its SKILL.md instructions get the agent, or you, to run a hidden installer, send credentials or files to an attacker, weaken the agent's safeguards, or move money. Most reported cases hid malware behind a fake setup step. Source: https://ironheights.dev/answers/what-is-a-malicious-clawhub-skill/ (updated 2026-10-09) ### What is prompt injection in an agent skill? Prompt injection in an agent skill is text in the skill's files that tries to take control of the agent: telling it to ignore earlier rules, hide actions from you, turn off confirmations, or edit its own instruction files. It works because the agent cannot reliably tell trusted instructions from text supplied by the skill's author. Source: https://ironheights.dev/answers/what-is-prompt-injection-in-an-agent-skill/ (updated 2026-10-09) ### What is OpenClaw skill supply-chain risk? OpenClaw skill supply-chain risk is the risk you take on by running instructions written by someone else. A third-party skill, a later update to it, or a website or file it depends on can turn harmful, and it acts with your agent's access to files, accounts and keys. It is the agent version of a malicious package. Source: https://ironheights.dev/answers/what-is-openclaw-skill-supply-chain-risk/ (updated 2026-10-09) ### Does VirusTotal scan ClawHub skills? Yes. Since 7 February 2026, every skill published to ClawHub is scanned with VirusTotal, including Code Insight, an LLM review of SKILL.md and the files it references. Benign skills are approved, suspicious ones get a warning, malicious ones are blocked from download, and active skills are re-scanned daily. OpenClaw calls it helpful but not a silver bullet. Source: https://ironheights.dev/answers/does-virustotal-scan-clawhub-skills/ (updated 2026-10-09) ### How do I scan an OpenClaw skill for malware? Run npx ironheights scan with the path to the skill folder, or paste its SKILL.md into the free browser scanner on this site. Both read the files as text, never run them, and report each risky pattern with a rule id, line and evidence. Then read every finding: no findings means no rule matched, not that the skill is safe. Source: https://ironheights.dev/answers/how-do-i-scan-an-openclaw-skill-for-malware/ (updated 2026-10-11) ### How do I verify a skill from ClawHub? Confirm you are on the skill's real ClawHub listing and the name and publisher are what you expect, read its VirusTotal status, then read the raw SKILL.md setup section, commands and links yourself. Scan the downloaded folder with a local scanner, install only if everything fits the skill's job, and record a baseline right after. Source: https://ironheights.dev/answers/how-do-i-verify-a-skill-from-clawhub/ (updated 2026-10-11) ### How do I check if a skill changed after install? Record a baseline right after you install and review the skill: npx ironheights baseline create stores a hash, size and mode for every watched file. Later, npx ironheights verify compares the current files with that record and lists every file that was added, modified, removed or had its permissions changed, with a rule id for each. Source: https://ironheights.dev/answers/how-do-i-check-if-a-skill-changed-after-install/ (updated 2026-10-11) ### How do I install Ironheights? You need Node.js 20 or newer. Run npx ironheights scan with the path to a skill to use it without installing, or install the command globally with npm install -g ironheights; ih is a shorter alias for the same command. Get it only from the ironheights package on npm, the project's GitHub releases, or this site. Source: https://ironheights.dev/answers/how-do-i-install-ironheights/ (updated 2026-10-11) ### Is Ironheights free and open source? Yes. The Ironheights command-line scanner, its detection rules, the benchmark harness and the advisory OpenClaw skill are free and open source under the Apache-2.0 license, with the source on GitHub. Paid Pro, Team, Threat Intel API and Enterprise tiers are planned, but their prices are hypotheses and nothing paid is on sale yet. Source: https://ironheights.dev/answers/is-ironheights-free-and-open-source/ (updated 2026-10-11) ### Does Ironheights send my data anywhere? The CLI has no telemetry, and a scan makes no network call. Only commands you run on purpose use the network, such as fetch or the optional model review. The in-browser scanner never sends your skill's content anywhere. The website uses Google Analytics only after you accept it, and then records only the scan verdict. Source: https://ironheights.dev/answers/does-ironheights-send-my-data-anywhere/ (updated 2026-10-11) ### Can I run Ironheights alongside other security scanners? Yes. Ironheights reads files and never runs another tool, and its guard stays in monitor mode unless you change it, so it can sit beside other scanners. Run ironheights coexist to list the other security tools it can see and where they overlap, with a fix for each. The check is heuristic, and a clean report is not proof. Source: https://ironheights.dev/answers/can-i-run-ironheights-alongside-other-security-scanners/ (updated 2026-10-11) ### What does Ironheights not detect? Ironheights only sees patterns its rules describe in the files it reads. It misses payloads hosted on a linked website or paste site, files over 1 MiB by default, behavior that appears only at runtime, instructions to move money, novel or heavily obfuscated attacks, and tampering by someone who can rewrite its baseline. No findings is not proof of safety. Source: https://ironheights.dev/answers/what-does-ironheights-not-detect/ (updated 2026-10-11) --- ## Blog posts Source: https://ironheights.dev/blog/. 8 posts, newest first. ### Ironheights 0.3.0: running next to the security tools you already have Ironheights 0.3.0 adds ironheights coexist, which finds other scanners and guards on your agent and reports overlaps. How it works, and where it stops. Published 2026-10-11. Link: https://ironheights.dev/blog/ironheights-0-3-0-run-next-to-other-security-tools/ ### Ironheights 0.2.0: protection beyond scanning, and where it stops Ironheights 0.2.0 adds fetch and safe-install, signed baselines, a guard plugin for agent tool calls, an A to F grade and advisory feed support. Plain language. Published 2026-10-11. Link: https://ironheights.dev/blog/ironheights-0-2-0-protection-beyond-scanning/ ### What our scanner cannot catch (and what to do about it) What Ironheights misses: payloads on linked sites, files over 1 MiB, runtime behavior, money-moving instructions and a compromised host, with a fix for each. Published 2026-10-09. Link: https://ironheights.dev/blog/what-ironheights-cannot-catch/ ### Baselines for agent files: detecting silent tampering How to record a known-good baseline of OpenClaw skills and agent files like AGENTS.md, SOUL.md and MEMORY.md, and verify later what was added, modified or removed. Published 2026-10-09. Link: https://ironheights.dev/blog/agent-file-baselines-detect-silent-tampering/ ### Where your agent leaks credentials without you noticing The quiet places an OpenClaw agent exposes API keys, SSH keys and wallets: chat, memory, .env files, skill files and outbound requests. How to check each. Published 2026-10-09. Link: https://ironheights.dev/blog/where-openclaw-agents-leak-credentials/ ### Why a security skill that runs inside the agent can be bypassed A security skill shares the agent's context with the skills it checks, so a hostile skill can talk the agent out of it. Where the real trust boundary is. Published 2026-10-09. Link: https://ironheights.dev/blog/why-in-agent-security-skills-can-be-bypassed/ ### A 10-minute checklist for vetting an OpenClaw skill A 10-minute routine to vet an OpenClaw or ClawHub skill before install: where it comes from, what to read in SKILL.md, what it can reach, what to record. Published 2026-10-09. Link: https://ironheights.dev/blog/vet-openclaw-skill-10-minute-checklist/ ### How malicious skills trick agents: anatomy of a prerequisite attack How fake 'Prerequisites' sections in ClawHub skills get agents and people to run malware, the variants seen in 2026, and what a file scanner can and cannot see. Published 2026-10-09. Link: https://ironheights.dev/blog/malicious-skill-prerequisite-attack-anatomy/ --- ## Features Source: https://ironheights.dev/features/ Version 0.3.0 checks how Ironheights sits beside the other security tools on your agent. The 0.2.0 release went beyond scanning: it can fetch and vet a skill before installing it, match skills against a signed advisory feed, sign your baseline, and watch an agent's tool calls. Each feature below says what it does, how to run it, and where it stops. Every command below is in ironheights 0.3.0 on npm. Angle brackets such as `/` are placeholders you fill in. A scan reports what its rules match. No findings is not proof of safety, and none of these features changes that. ### New in 0.3.0: next to your other security tools Most agents that care about security already run something else. Ironheights now looks for it, tells you where the two would collide, and stays out of the way. New in 0.3.0 ### Works next to your other security tools Many OpenClaw setups already run a ClawHub vetting skill, a guard plugin or a scanner such as Cisco's skill-scanner. ironheights coexist looks for them and reports where two tools would get in each other's way, with a fix for each. It reads files only, runs none of the other tools, and changes nothing. - It reads your OpenClaw config (plugin and hook entries), plugin manifests, skill and hook folders, known state folders, PATH, and CI or pre-commit files in a project. Each tool it lists shows the file that gave it away. - Eleven checks, IH-COEX-001 to IH-COEX-011: two guards on the same tool call, Ironheights in enforce mode blocking another tool, two tools restoring the same files, shared state paths, a config that exempts a security tool by name, and more. Each has a severity and a fix. - Text for people, --json for scripts, and --fail-on to exit 1 in CI when a finding reaches a severity. - doctor prints a one-line summary, and the guard plugin writes one log line at startup when it sees another tool. See what runs next to Ironheights ``` npx ironheights coexist ``` Fail a CI job on a medium or higher overlap ``` npx ironheights coexist --json --fail-on medium ``` Include a project's CI and pre-commit files ``` npx ironheights coexist --repo ``` Where it stops Detection is heuristic. It reads files and names, so a tool that is not on its list, was renamed, or is only loaded in a running Gateway can be missed, and anyone can copy a name. No findings is not proof that two tools will not interfere. Coexistence docs (opens in a new tab) New in 0.3.0 ### A guard that shares the hook OpenClaw runs before_tool_call handlers from the highest priority down, and a block ends the chain. The Ironheights guard now runs at priority 80, and one setting changes it. In monitor mode, the default, it never blocks, so another guard can own blocking. - Set plugins.entries.ironheights-guard.config.priority to an integer from -1000 to 1000. Higher runs first, and OpenClaw's own default is 0. - The guard returns only block and blockReason. It never rewrites parameters and never asks for approval, so it cannot collide with another plugin's rewrite or prompt. - Every block reason starts with ironheights:, so you can tell whose block you are reading. - Its files all live under ~/.ironheights, apart from other tools' folders. coexist flags the case where IRONHEIGHTS_HOME points at a shared folder. - At startup the plugin writes one log line when it sees other security tools. It has a three-second limit and cannot delay OpenClaw. Plugin config with a priority ``` { "plugins": { "entries": { "ironheights-guard": { "enabled": true, "config": { "mode": "monitor", "priority": 80 } } } } } ``` Check mode, policy and log ``` npx ironheights guard status ``` Where it stops Priority sets the order, not who is right. When two guards enforce, the higher one blocks first and the other never sees that call, so its log is missing it. The hook still runs inside the agent and is not a sandbox. Hook order follows OpenClaw's plugin docs as checked on 11 October 2026 and can change. Guard docs and threat model (opens in a new tab) New in 0.3.0 ### Security tools are not trusted by name Security skills quote attack strings and list credential paths because that is their job, so a scanner flags them. When a scanned skill's folder or SKILL.md name matches a tool Ironheights knows, scan adds a note and lowers confidence by one step on its Markdown injection and credential findings. It never hides a finding, and the verdict, grade and exit code do not change. - The note reads: name match only, not verified. Anyone can copy a name. - Only injection and credential findings in Markdown files are affected. Scripts, config, binaries, network, obfuscation, persistence and exec findings are untouched. - Nothing is allowlisted. If you trust one copy, review it, then baseline it, or add a suppression with a written reason for that file and line. - coexist reports IH-COEX-010 when your own config exempts a path that carries the name of a security tool. Scan a security skill and read the note ``` npx ironheights scan ``` Where it stops A name match proves nothing about the files. The note helps you read findings. It is not a clearance, and a malicious skill that borrows a familiar name gets the same verdict as any other. Coexistence docs (opens in a new tab) ### New in 0.2.0: protection beyond scanning Checks before you install a skill, while your agent runs, and after something changes. New in 0.2.0 ### Fetch and safe-install Until now you had to download a skill, then point the scanner at it. Now one command does both. fetch downloads a ClawHub skill into a staging folder without running anything and scans it. safe-install does the same and copies the skill into your skills folder only when the verdict is no-findings. - Nothing that is downloaded is executed. Files are written readable only by you (mode 0600) and archives are never extracted. - block and incomplete verdicts are never installed. A review verdict installs only if you add --accept-review. - If a copy of the skill is already installed it is backed up first and restored if the new copy fails. - The download goes to clawhub.ai over HTTPS, redirects are refused, and each file's size and sha256 must match what ClawHub lists. The CLI prints every URL before it asks. Scan without installing ``` npx ironheights fetch / ``` Install only if the scan is clean ``` npx ironheights safe-install / ``` Pin a version and a folder ``` npx ironheights safe-install /@ --dir ~/.openclaw/workspace/skills ``` Where it stops A clean verdict means no rule matched, not that the skill is safe. This is one of the few commands that uses the network, and only when you run it. Fetch and safe-install docs (opens in a new tab) New in 0.2.0 ### Signed advisory feed support Pattern rules find risky text. An advisory finds a skill that someone has already reported, even when its text looks harmless. The 0.2.0 release can download a signed advisory feed, verify its signature against a key built into the CLI, and report a match as IH-ADV-001. - The feed is checked with an Ed25519 signature. A bad signature is rejected and never cached. - scan and fetch compare the skill name, file hashes and indicator hosts with the cached feed, offline. A match is critical, so it blocks safe-install. - ironheights advisories update is the only command that downloads the feed. There is no telemetry and no client id. - The CLI never invents severity. The status shown is the one the source stated. Download and verify the feed ``` npx ironheights advisories update ``` Show what is cached ``` npx ironheights advisories show ``` Scan; a match is reported as IH-ADV-001 ``` npx ironheights scan ``` Where it stops The feed is not published yet. Until it is, advisories update has nothing to download and scans report nothing from the feed. A skill missing from a feed is not evidence that it is harmless. Advisory feed docs (opens in a new tab) New in 0.2.0 ### Signed baselines A baseline is a saved list of hashes for your skills and agent files. If an attacker can edit that list as well as the files, verify has nothing to compare against. Now you can sign the baseline with a key file you keep somewhere safer, and verify checks the signature. - Sign with an HMAC-SHA256 or an Ed25519 key file. Ironheights does not create or store the key for you, and on macOS and Linux it refuses a key file that other users can read. - A baseline whose signature does not match is reported as a tampered baseline: a critical IH-INT-001 finding and exit code 2. - A baseline rewritten so its hashes still agree with each other still fails the signature check. Make a key file (run in a clone of the repository) ``` node scripts/generate-baseline-key.mjs --alg ed25519 --out ~/.ironheights/baseline.key ``` Create a signed baseline ``` npx ironheights baseline create --key ~/.ironheights/baseline.key ``` Verify it, signature included ``` npx ironheights verify --key ~/.ironheights/baseline.key ``` Where it stops An attacker who can write your home directory and also has the key can sign a new baseline. Keep the key file private, and a copy of it off the machine if you can. Baseline signing docs (opens in a new tab) New in 0.2.0 ### Guard plugin for agent tool calls Scanning reads files. The guard watches what the agent is about to do. It is an OpenClaw plugin that checks each tool call against four risky behaviors and writes a redacted line to a local log. It starts in monitor mode: it logs and does not block anything. Enforce mode is opt-in. - Credential reads: SSH, cloud and wallet folders, private keys, .env files, and OpenClaw credentials. - Download-and-execute: curl or wget piped into a shell, and a downloaded file that is then run. - Network: a request to a host that is not on your allowlist, or to a paste site, file-drop host, tunnel or raw IP address. - Writes to the agent's identity and memory files, such as AGENTS.md, SOUL.md and MEMORY.md, and to skill folders. - In enforce mode a matching call is blocked until your policy file has an allow entry with a reason. Enable the plugin in OpenClaw ``` openclaw plugins install --link /path/to/ironheights --force openclaw plugins enable ironheights-guard ``` Check mode, policy and log ``` npx ironheights guard status ``` Read the recent log ``` npx ironheights guard log ``` Where it stops The guard is not a sandbox. It runs inside the OpenClaw process, so a compromised skill that can edit your OpenClaw config or the policy file can switch it off. It sees only the tool name and parameters OpenClaw passes in. A quiet log is not proof that nothing happened. Guard docs and threat model (opens in a new tab) New in 0.2.0 ### A to F trust grade Every scan now prints a grade next to the verdict: a score from 0 to 100 turned into a letter. It is a summary of the same risk points the rules already add up, so it never says more than the findings do. The grade appears in JSON, in a one-file HTML report, and as a README badge line that does not call any badge service. - A is 90 to 100, B 80 to 89, C 70 to 79, D 60 to 69, and F 0 to 59. - The grade uses the worst skill in the scan, after suppressions. - scan --html writes one self-contained report with no scripts and a strict content security policy. - Every grade is printed with the line “Absence of findings is not proof of safety.” Scan and read the grade ``` npx ironheights scan ``` Write a shareable HTML report ``` npx ironheights scan --html report.html ``` Where it stops An A means the rules found little to add up. It does not mean the skill is safe. A scan that skipped anything is graded incomplete, with no number. Grade and report docs (opens in a new tab) New in 0.2.0 ### Honest incomplete verdicts A padded file or a folder the scanner did not enter should never read as a clean result. When a file is skipped for size, or .git or node_modules is not entered, the report names each one, the verdict is incomplete and the exit code is 3, unless the scanned files already reached review or block. - dist/ is scanned like any other folder, so a pipe-to-shell line there is a finding. - .git and node_modules are listed in the text report, in JSON skippedDirectories and in SARIF. - --allow-skipped keeps the warning and returns the finding verdict; the grade stays incomplete. - ignoreDirs in config, with a written reason, acknowledges a folder so it no longer makes the scan incomplete. A scan that skipped something exits 3 ``` npx ironheights scan ; echo $? ``` Accept the skipped folders, with the warning kept ``` npx ironheights scan --allow-skipped ``` Where it stops Incomplete means part of the skill was not checked at all. --allow-skipped and ignoreDirs let you accept that. They do not scan what was skipped. Scan limits docs (opens in a new tab) Fixed in 0.2.0 ### Piped JSON that stays whole Earlier versions could cut a long report off at 64 KiB when you piped it, which left broken JSON. The 0.2.0 release waits until the pipe has taken the whole report before it exits. The exit code is unchanged. - Applies to scan --json, scan --format html, and every other command that writes to stdout. - A report written to a file with --sarif or --html was already complete. Pipe a full report ``` npx ironheights scan --all --json | jq '.verdict' ``` Where it stops This is a bug fix, not a new detection. It does not change what a scan finds. Changelog (opens in a new tab) ### Also in 0.2.0 Smaller additions that make the scanner easier to fit into CI, other agents and your own config. New in 0.2.0 ### OpenClaw config audit audit-config reads your local OpenClaw config and reports nine kinds of risky setting: an exposed Gateway, missing auth, open DMs or groups, literal secrets, loose file permissions, broad tool power, extra skill folders, and a disabled sandbox. - Offline and read-only. Secret values are replaced with . - Rules IH-CFG-001 to IH-CFG-009, output as text, JSON or SARIF. - It does not replace openclaw security audit, which also probes a running Gateway. Audit your config ``` npx ironheights audit-config npx ironheights audit-config --json --fail-on high ``` Where it stops It reads the file, not the running system. Settings that come from environment variables are not seen. audit-config docs (opens in a new tab) New in 0.2.0 ### MCP configuration rules scan now reads MCP configuration files and reports a server started from a downloaded script or an unpinned npx package, a literal secret in a server's environment, and a filesystem server pointed at a whole disk or home folder. - Rules IH-MCP-001, IH-MCP-002 and IH-MCP-003. - Works on Claude Code, Codex and Cursor skill folders too: point scan at the folder. Scan a folder with an MCP config ``` npx ironheights scan ``` Where it stops CLI only: the in-browser scanner does not run these rules. A pinned package can still be malicious. Other agents and MCP docs (opens in a new tab) New in 0.2.0 ### Only what is new scan --since-baseline compares the scan with a saved baseline or a previous JSON result and reports only findings that are new. The ones left out are counted and listed, and the exit code follows the new findings. - Works with an integrity baseline or a previous --json result. - Omitted findings still count toward the grade. Report only new findings ``` npx ironheights scan --since-baseline previous.json ``` Where it stops A finding you already accepted is hidden from the list, not made safe. Changelog (opens in a new tab) New in 0.2.0 ### Scan a piece of text scan --stdin and scan --text run the same content rules on one piece of text, labelled as a limited text scan. The text is never executed. - --stdin reads a pipe and returns a usage error on a terminal. - Text scans are never sent to a model. Scan pasted text ``` cat | npx ironheights scan --stdin npx ironheights scan --text "" ``` Where it stops A text scan has no skill folder, so it cannot check files, hashes or the baseline. Changelog (opens in a new tab) New in 0.2.0 ### Suppressions that need a reason An inline ironheights-ignore comment or a config suppression must carry a written reason of at least eight characters. Suppressed findings are counted and listed, and critical and integrity findings stay visible unless you say otherwise. - A marker with no usable reason is listed and does not hide the finding. - A comment applies to its own line and the next. An inline suppression ``` ## ironheights-ignore IH-CRED-001 reason="reviewed local demo" ``` Where it stops A suppression records your decision. It does not make the line safe. Changelog (opens in a new tab) New in 0.2.0 ### CI action, pre-commit hook and Windows A composite GitHub Action runs a pinned npm release of the scanner. A pre-commit hook scans a tree when a SKILL.md changes. Windows CI now builds and tests the CLI on Node.js 20.0.0 and 24, and path handling accepts ~\ and %USERPROFILE%. - The action needs an exact version, such as 0.3.0, and takes no token for scanning. - Exit code 3 still means the scan was incomplete. GitHub Actions step ``` - uses: Frank-Masciopinto/ironheights@v0.3.0 with: version: '0.3.0' path: . fail-on: high ``` Where it stops Windows support is new in 0.2.0 and is checked in CI, not yet as widely used as macOS and Linux. CI docs (opens in a new tab) New in 0.2.0 ### Optional model second opinion scan --llm and review send a capped, secret-scrubbed copy of the skill to a model server you choose and add advisory notes as IH-LLM-001. It is off unless you ask. The default is a loopback Ollama-compatible server. - A non-local server needs --llm-consent and an API key, and the exact request is printed before it is sent. --dry-run prints it without sending. - Notes score zero. They never change the verdict, the grade or the exit code. See what would be sent ``` npx ironheights review --dry-run ``` Where it stops Models can be wrong, and the scrub can miss a secret. A silent model is not a clearance. Model review docs (opens in a new tab) ### What none of this is - The guard is not a sandbox, an antivirus, or a process outside the agent. A compromised skill that can edit your OpenClaw config can turn it off. - A grade, a signature or a quiet log is not a safety rating. Absence of findings is not proof of safety. - The advisory feed is not published yet, so a scan reports nothing from it today. When a feed is live, a skill missing from it is still not evidence that the skill is harmless. - Detecting other security tools is heuristic. It reads files and names, can miss a renamed or unlisted tool, and cannot tell whether a plugin is loaded in a running Gateway. A name can be copied, so Ironheights never trusts a tool by name. - The in-browser scanner runs the content rules only. MCP, advisory, config audit, guard and coexistence checks need the CLI. Read the docs Read every limitation --- ## How it works Source: https://ironheights.dev/how-it-works/ Ironheights is a command-line tool that runs on your machine. It does three things: it scans skill files for risky patterns, it records a baseline of your installed skills and agent files, and it tells you when that baseline no longer matches. ### 1. Scan: read skills as data A skill is a folder with a `SKILL.md` and sometimes scripts. Ironheights walks the folder within the limits you set (file size, file count, depth), reads each file as text, and matches it against fixed rules. It never executes a file, and it does not extract archives; a bundled archive is a finding on its own. ``` npx ironheights scan ~/.openclaw/workspace/skills/some-skill npx ironheights scan --all --sarif results.sarif --fail-on high ``` ### 2. Score: findings become a verdict Each finding has a rule id, severity, confidence, file and line, the evidence, a message, and a remediation. Severities add up to a score: critical 100, high 40, medium 15, low 5, info 0. - block: any critical finding, or a score of 80 or more. - review: any high or medium finding, or a score of 15 or more. - no-findings: nothing matched. This is not proof of safety. - incomplete: a file was skipped (for example one over 1 MiB) or a `.git` or `node_modules` directory was not entered, and nothing that was scanned reached review or block. The exit code is 3, and each skipped file and directory is named in the report. Review and block still win; `--allow-skipped` accepts what was skipped. Every scan also prints an A to F grade, a 0 to 100 score built from the same points (A is 90 or more, F is below 60). It is a summary, not a safety rating, and a scan that skipped anything is graded `incomplete`. Thresholds are configurable in `ironheights.config.json`, and individual rules can be disabled or re-rated with `ruleOverrides`. ### 3. Baseline and verify: notice what changed `ironheights baseline create` writes a file with a sha256, size, and mode for each watched path, plus a tree hash. Watched paths default to your skill directories and agent files such as `AGENTS.md`, `SOUL.md`, `MEMORY.md`, `openclaw.json`, `credentials/`, and `.env` under the OpenClaw state directory. `ironheights verify` reports files that were added, modified, removed, or had their mode changed since the baseline. These are the integrity rules. With `--key`, the baseline is also signed and checked, so an edited baseline shows up as tampered. ### 4. Quarantine: move, do not delete `ironheights quarantine ` moves a skill into a private quarantine directory so the agent stops loading it. `ironheights quarantine restore ` moves it back. Ironheights does not delete a skill on its own. ### New in 0.3.0: before, during and after Before you install: `ironheights safe-install /` downloads a ClawHub skill, scans it, and installs it only when the verdict is `no-findings`. The CLI can also use a signed advisory feed to match known-bad skills, though that feed is not published yet. While the agent runs: the optional guard plugin watches a short list of tool calls and logs them. It is not a sandbox. After something changes: a signed baseline and `verify` catch edits to your skills and agent files, including edits to the baseline itself. See every command and limit on the features page. ### The advisory OpenClaw skill An optional skill tells your agent to run `ironheights scan --json`, summarize the result, and stop on a `block` verdict until you confirm. It asks for no network access and no secrets. Because it runs inside the agent, a hostile skill can try to bypass it. The CLI you run yourself is the trusted path. ### What is not built yet A sandbox or egress proxy, a credential broker, full injection screening of inbound content, and a team console are on the roadmap. They are not part of version 0.3.0. The guard plugin and the text scan are early, partial steps in that direction, not replacements. See Limitations and Pricing. --- ## Limitations Source: https://ironheights.dev/limitations/ No scanner gives complete protection, and we would rather you hear that from us. Here is what Ironheights 0.3.0 does not do. ### What it cannot detect - Novel attacks, and attacks obfuscated in a way the current rules do not describe. - Runtime-only behavior that appears after a script is executed. The scanner reads files; it does not watch processes or network traffic. The optional guard plugin watches a short list of OpenClaw tool calls from inside the agent. It is not a sandbox, a compromised agent can switch it off, and a quiet log is not proof of safety. - A host that is already compromised, including a baseline an attacker can rewrite. Anyone who can write your home directory can edit the baseline file, unless you sign the baseline with a key kept somewhere they cannot reach, and even a signed baseline does not help against an attacker who also has the key. - Social engineering that never lands in a file the scanner reads. - Files larger than 1 MiB. The CLI skips any file over the size limit (`limits.maxFileBytes`, 1,048,576 bytes by default) without reading it, and it does not enter `.git` or `node_modules`. The report names each skipped file and directory and the verdict is `incomplete` with exit code 3, so a padded file no longer passes as clean, but its content is still not scanned. `dist/` is scanned. Pass `--allow-skipped` only if you accept that, or raise `limits.maxFileBytes` in your config if your skills contain large files. The browser scanner shows the same incomplete result when it skips a file for size. Use `ignoreDirs` with a written reason to acknowledge `.git` or `node_modules` so they no longer make a scan incomplete. ### What a verdict means `no-findings` means the rules did not match. It does not mean the skill is safe. `incomplete` means a file or directory was skipped and was not checked at all. The A to F grade is only a summary of the risk points the rules added up; it is not a safety rating, and a scan that skipped anything is graded `incomplete`. `review` and `block` can also be false positives; tune them with `ruleOverrides` and `allowDomains`. ### Scope today - `scan --all` includes OpenClaw bundled skills, custodian skills, and the directories behind `~/.openclaw/plugin-skills` symlinks. Bundled skills do not declare their hosts yet, so a stock install still reports their API hosts. - The advisory OpenClaw skill runs inside the agent, so a hostile skill can try to bypass it. - The guard is not a sandbox. The guard plugin runs inside the OpenClaw process and sees only the tool name and parameters OpenClaw passes in. A compromised skill that can edit your OpenClaw config, the policy file or the plugin can switch it off. Monitor mode, the default, only logs. A quiet log is not proof that nothing happened. - A signed baseline only helps while the key stays private. Anyone who can write your home directory and also has the key can sign a new baseline. Keep a copy of the key off the machine if you can. - Advisory feed support is in the CLI, but the feed is not published yet, so `advisories update` has nothing to download and scans report nothing from it. A skill missing from a feed is not evidence that it is harmless. - The browser scanner runs the content rules from the 0.1.5 engine. MCP, advisory, config audit, grade and guard checks need the CLI. - Windows support is new in 0.3.0. It is tested in CI on Node.js 20.0.0 and 24, which is not the same as years of use. ### Benchmark The benchmark corpus in the repository is synthetic: harmless text that matches rules. A public comparison against other scanners on known malicious samples is in progress, and we will publish the method and the misses along with the results. See the benchmark documentation. --- ## Privacy Source: https://ironheights.dev/privacy/ Short version: The Ironheights CLI has no telemetry. The in-browser scanner never sends your skill’s content anywhere; it runs in your browser. With your consent, the site records only the scan verdict (no content) through Google Analytics. ### The Ironheights CLI Scans, baselines, and quarantine stay on your machine. There is no telemetry, no account, and no default network call. The baseline is written to `~/.ironheights/baseline.json` with owner-only permissions, or under `IRONHEIGHTS_HOME` if you set it. Scans make no network call. Only the commands you choose can: fetch and safe-install talk to clawhub.ai, advisories update talks to ironheights.dev, and scan --llm or review talk to a model server you pick (off by default; the default is a loopback Ollama-compatible endpoint). The CLI prints each URL before it requests it, and none of this is telemetry. The guard plugin writes a redacted audit line for each flagged tool call to a local log (mode `0600`) and sends it nowhere. Installing through npm is subject to npm’s own policies. Reports you file on GitHub are subject to GitHub’s. ### The in-browser scanner and the checklist The scanner on `/tools/scanner/` runs the rule engine inside your browser tab. The scanner never sends your skill’s content anywhere: your skill text, file names, and findings never leave the tab. Share links keep the text after the `#`, which browsers never send to a server. The risk checklist keeps your answers in this browser’s local storage only. With your consent (site analytics, below), the site records only the scan verdict (no findings, review, or block), with no content, and that a checklist was completed with its result level. Nothing else from these tools is sent. ### Website analytics (only with your consent) ironheights.dev uses Google Analytics 4 (measurement ID `G-1VW743D63T`) to count visits and see which pages and tools are useful. It runs only after you choose “Accept analytics” in the banner. Until then, and if you choose “No thanks”, the Google script is not loaded, no analytics cookie is set, and nothing is sent to Google. We use Google Consent Mode v2 with every storage type denied by default; advertising storage, ad user data, and ad personalization stay denied even after you accept. What is collected after you accept: - Pages you view, as the address without any query string or `#` part, the page title, and the referring page. - Device and browser details (type, operating system, browser, screen size, language) and visit timing. - Approximate location (country and region or city), which Google derives from your IP address. Google Analytics 4 does not log or store IP addresses, and we ask for IP anonymization on top. - A few events with fixed values only: a scan’s verdict label, a click on a scanner example, a completed checklist or risk quiz (with its result level), a click on the tracker’s report link, copying an `npx ironheights` command (the subcommand name only), and clicks on links to GitHub, npm, or ClawHub (the domain only). Never collected: skill text you paste or upload, file names, findings, search terms, checklist answers or notes, or anything else you type. The analytics helper accepts only a fixed list of events and values and drops anything else. Google Signals, advertising features, and ad personalization are off. Cookies: `_ga` and `_ga_`, first-party cookies holding a random identifier, set only after you accept and kept for up to 13 months. Your choice itself is stored in this browser’s local storage, not in a cookie. Retention: Google Analytics keeps event-level data for 2 months, after which only aggregated reports remain. Legal basis: your consent (GDPR Article 6(1)(a)). Google acts as our processor; data may be processed in the United States under the EU-US Data Privacy Framework and Google’s standard contractual clauses. Change your mind at any time: use Cookie settings (also in the footer) and choose “No thanks”. Analytics stop at once and the `_ga` cookies are deleted. You can also block Google Analytics everywhere with Google’s opt-out browser add-on or your browser’s tracker blocking; the site works the same either way. ### Hosting ironheights.dev is a static site hosted on Vercel. Our hosting provider keeps standard server logs (such as IP address, user agent, and requested URL) to operate and secure the service. There are no advertising scripts and no other third-party scripts. ### Contact Questions about privacy, or a request to access or delete data: open an issue on GitHub. Last updated 2026-10-11. --- ## FAQ Source: https://ironheights.dev/faq/ ### What is Ironheights? A free, open-source command-line scanner and integrity monitor for OpenClaw skills. It flags risky patterns in skill files with fixed rules and reports changes to installed skills and agent files against a baseline you save on your machine. ### Does a clean scan mean a skill is safe? No. No findings means the rules did not match. Novel, heavily obfuscated, or runtime-only attacks can still get through. Treat a clean scan as one signal and still read the skill. ### Does Ironheights send my files or results anywhere? Not during a scan. Scans run locally, there is no telemetry, and no scan makes a network call. Only commands you run on purpose use the network: fetch and safe-install download a skill from clawhub.ai, advisories update (or --online) downloads a signed advisory feed from ironheights.dev, and scan --llm or review send capped, secret-scrubbed skill text to a model server you choose. The CLI prints each request first. ### Can Ironheights install a skill for me? Yes, carefully. ironheights safe-install owner/slug downloads a ClawHub skill into a staging folder without running anything, scans it, and copies it into your skills folder only when the verdict is no-findings. Review installs only with --accept-review. Block and incomplete are never installed. No findings still does not mean a skill is safe. ### Is the runtime guard a sandbox? No. The guard is an OpenClaw plugin that runs inside the agent process and checks a short list of tool calls: credential reads, download-and-execute commands, undeclared or high-risk hosts, and writes to agent identity files and skill folders. It starts in monitor mode, which only logs. A compromised skill that can edit your OpenClaw config can turn it off, and a quiet log is not proof of safety. ### Can I run Ironheights next to other security scanners? Yes, and ironheights coexist helps you check. It lists the other security tools it can see on your machine (skills, plugins, scanner commands, CI files), reports overlaps such as two guards on the same tool call, and suggests a fix for each. It reads files only. Detection is heuristic, so a renamed or unlisted tool is missed, and no findings does not prove that tools will not interfere. ### Is the advisory feed live? Not yet. The CLI can download a signed advisory feed, verify its Ed25519 signature, and report matches as IH-ADV-001, but the feed is not published yet. Until it is, ironheights advisories update has nothing to download and scans report nothing from the feed. A skill missing from a feed would still not be proof that it is harmless. ### Does this website use analytics? Only if you agree. ironheights.dev uses Google Analytics after you choose Accept analytics in the consent banner; until then, and if you choose No thanks, the Google script never loads. It never receives skill text, file names, search terms, or anything you type. Change your choice any time with Cookie settings in the footer. The CLI has no telemetry. The in-browser scanner never sends your skill’s content anywhere; it runs in your browser. With your consent, the site records only the scan verdict (no content). Details are on the privacy page. ### Does it run the skills it scans? No. Skill files are read as data, up to a configured size. Archives are flagged, not extracted, and scripts are never executed. A skill downloaded by fetch or safe-install is written to disk and scanned, never run. ### Which Node.js version do I need? Node.js 20 or newer for Ironheights. OpenClaw itself has stricter requirements; ironheights doctor prints whether your runtime fits the OpenClaw range. ### Where should I download it? Only from the ironheights package on npm, the GitHub releases of Frank-Masciopinto/ironheights, or links on ironheights.dev. Fake “antivirus” skills are a known lure, so do not install Ironheights from anywhere else. ### Is the OpenClaw skill enough on its own? No. The advisory skill runs inside the agent, and a hostile skill can try to talk the agent out of it. The CLI you run yourself, or a process outside the agent, is the trusted path. ### Can I use it in CI? Yes. Use --json, --sarif, --md, or --html for reports, --since-baseline to fail only on new findings, and --fail-on to choose the severity that fails the job. A GitHub Action pinned to an exact version and a pre-commit hook are included. Exit codes are 0 for no findings, 1 for review, 2 for block, 3 for an incomplete scan (a file or directory was skipped), 64 for usage errors, and 70 for internal errors. ### How much does it cost? The Community edition is free under Apache-2.0. Pro, Team, a Threat Intel API, and Enterprise are planned; the prices on the pricing page are hypotheses and nothing paid is on sale yet. ### How do I report a vulnerability in Ironheights? Open a private security advisory on the GitHub repository. Include the rule id if there is one, a minimal synthetic skill that triggers the issue, and the output of ironheights --version. --- ## Rules Source: https://ironheights.dev/rules/ 35 rules: 17 content rules (scan, also in the browser scanner), 3 MCP config rules and 1 advisory feed rule (scan, CLI only), 4 integrity rules (verify), 9 OpenClaw config rules (audit-config) and 1 optional model note. Review at a score of 15 or any high or medium finding; block at 80 or any critical finding. - IH-EXEC-001 (critical): Remote content piped into an interpreter. Fetching remote text and passing it straight to a shell or runtime executes attacker-controlled code. Page: https://ironheights.dev/rules/ih-exec-001/ - IH-EXEC-002 (high): Prerequisite install from an external URL. Skills sometimes tell the agent to install a tool from a URL or git link before doing anything else. Each command is reported once, on the line that contains it. Page: https://ironheights.dev/rules/ih-exec-002/ - IH-EXEC-003 (high): Dynamic code execution. eval, the Function constructor, and shell-enabled subprocess calls run strings as code. Page: https://ironheights.dev/rules/ih-exec-003/ - IH-NET-001 (medium): Undeclared network destination. A skill that contacts a host outside the allowlist can send data somewhere the user did not expect. A download, install, or fetch instruction is a contact, and so is a paste site or a file-drop host. A homepage field, a license URL, a schema link, or an official API host in prose is not a contact. Page: https://ironheights.dev/rules/ih-net-001/ - IH-NET-002 (high): Possible exfiltration. A sensitive read and an outbound request in the same few lines can move credentials off the machine. Telling the agent to send a credential path to a URL counts. Page: https://ironheights.dev/rules/ih-net-002/ - IH-CRED-001 (high): Access to a sensitive path. References to keys, browser stores, wallets, shell history, or OpenClaw auth files expose credentials. A credential directory such as ~/.ssh, ~/.aws, ~/.gnupg, or ~/.azure counts with or without a file name after it. Windows forms count too: ~\.ssh, %USERPROFILE%\.ssh, and AppData paths for Chrome, Firefox, or the credential store. Page: https://ironheights.dev/rules/ih-cred-001/ - IH-CRED-002 (high): Hard-coded secret. Private keys and live tokens checked into a skill can be copied by anyone who reads the skill. Page: https://ironheights.dev/rules/ih-cred-002/ - IH-CRED-003 (medium): Secret asked for in chat or memory. Asking the user to paste a secret into chat or memory stores it in the transcript. Page: https://ironheights.dev/rules/ih-cred-003/ - IH-INJ-001 (high): Instruction override. Phrases that tell the agent to ignore prior rules are a common way to hide malicious steps. Page: https://ironheights.dev/rules/ih-inj-001/ - IH-INJ-002 (high): Hidden content. Invisible characters, HTML comments, and huge base64 blobs can hide instructions from a person reading the file. Page: https://ironheights.dev/rules/ih-inj-002/ - IH-INJ-003 (high): Weaken agent safeguards. Instructions to disable approvals or edit agent files change the trust boundary of the assistant. Page: https://ironheights.dev/rules/ih-inj-003/ - IH-OBF-001 (medium): Obfuscated code. Packed or encoded payloads are used to hide a command from a person reviewing the skill. Page: https://ironheights.dev/rules/ih-obf-001/ - IH-PERSIST-001 (high): Persistence mechanism. Scheduled tasks, login hooks, and shell startup files keep code running after the skill is closed. Page: https://ironheights.dev/rules/ih-persist-001/ - IH-PRIV-001 (high): Privilege or OS protection bypass. sudo, broad chmod, and commands that turn off Gatekeeper or firewall protections weaken the host. Page: https://ironheights.dev/rules/ih-priv-001/ - IH-BIN-001 (high): Bundled executable or archive. Executables and archives shipped inside a skill can hide an installer. Archives are flagged and never extracted. Page: https://ironheights.dev/rules/ih-bin-001/ - IH-FS-001 (medium): Suspicious filesystem access. Symlinks that leave the skill, path traversal, and hidden files can read or hide data outside the skill. Page: https://ironheights.dev/rules/ih-fs-001/ - IH-META-001 (low): Skill metadata problem. OpenClaw discovers a skill from SKILL.md frontmatter. Missing fields make the skill harder to identify and review. Page: https://ironheights.dev/rules/ih-meta-001/ - IH-MCP-001 (high): MCP server launched from a remote command. An MCP config that starts a server with curl piped into a shell, or with npx of a package that is not pinned to a version, runs code the operator has not reviewed. A shell pipe is critical. A pinned package such as name@1.2.3, a local path, and a local node script are not. Page: https://ironheights.dev/rules/ih-mcp-001/ - IH-MCP-002 (high): Secret in an MCP server environment. A literal secret in an MCP server env block is copied onto disk and into the server process. A reference such as ${API_KEY} is not a literal. Page: https://ironheights.dev/rules/ih-mcp-002/ - IH-MCP-003 (medium): MCP server given a broad filesystem root. A filesystem MCP server pointed at /, a drive root, or a home directory can read far more than the project. A subdirectory such as ./notes or /home/alex/projects/notes is not a broad root. Page: https://ironheights.dev/rules/ih-mcp-003/ - IH-INT-001 (high): Skill file modified. A file in an installed skill no longer matches the saved baseline. Page: https://ironheights.dev/rules/ih-int-001/ - IH-INT-002 (medium): New skill file. A file or skill directory appeared after the baseline was created. Page: https://ironheights.dev/rules/ih-int-002/ - IH-INT-003 (medium): Skill file removed. A file that was in the baseline is gone. Page: https://ironheights.dev/rules/ih-int-003/ - IH-INT-004 (high): Watched agent file changed. An agent instruction, personality, memory, or config file changed since the baseline. Page: https://ironheights.dev/rules/ih-int-004/ - IH-ADV-001 (critical): Advisory feed match. The cached signed advisory feed lists this skill name, a file content hash, or an indicator host. The match is reported only when a local cache is present. Scan does not contact the network to refresh the feed. Page: https://ironheights.dev/rules/ih-adv-001/ - IH-CFG-001 (high): Gateway bind is not loopback. gateway.bind is lan, tailnet, custom, auto, or an all-interfaces address, or gateway.tailscale.mode is funnel. OpenClaw's native check gateway.bind_no_auth covers a remote bind without a shared secret, and gateway.tailscale_funnel covers public Funnel. This rule only reads the config value. It does not probe the listener. auto is medium because the effective bind is chosen at runtime. Funnel and 0.0.0.0 are critical. Page: https://ironheights.dev/rules/ih-cfg-001/ - IH-CFG-002 (critical): Gateway auth is missing or a placeholder. gateway.auth.mode is none or trusted-proxy, a non-loopback bind has no auth object, or the token or password in the file is empty or a known placeholder. Native checks gateway.bind_no_auth, gateway.loopback_no_auth, gateway.token_placeholder_value, and gateway.trusted_proxy_auth overlap this rule. A loopback bind that omits auth is not flagged: OpenClaw's default is authenticated, and the token may live in OPENCLAW_GATEWAY_TOKEN, which this command does not read. trusted-proxy is critical because the proxy becomes the auth boundary; proxy IPs and headers are left to the native audit. Page: https://ironheights.dev/rules/ih-cfg-002/ - IH-CFG-003 (critical): DM policy is open. A channel dmPolicy (or dm.policy) is open, so anyone can DM the agent. This matches the native check channels..dm.open. Mutable allowFrom entries and name matching are not reimplemented. Page: https://ironheights.dev/rules/ih-cfg-003/ - IH-CFG-004 (high): Group policy is open. A channel groupPolicy is open, so any member of a group can talk to the agent. Severity rises to critical when the same config also enables host exec, elevated tools, or an open DM policy. Native security.exposure.open_groups_with_elevated and security.exposure.open_channels_with_exec cover the live combination; this rule only reads the file. Page: https://ironheights.dev/rules/ih-cfg-004/ - IH-CFG-005 (high): Plaintext secret in OpenClaw config. A token, password, secret, or API key is a literal string in the config file. ${ENV} references and SecretRef objects (source env, file, exec, or store) are not literals. Placeholder literals are reported as IH-CFG-002 instead. Evidence is the key path plus . Native config.secrets.gateway_password_in_config and config.secrets.hooks_token_in_config are the overlapping checks; other secret keys in the file are reported here too. Page: https://ironheights.dev/rules/ih-cfg-005/ - IH-CFG-006 (critical): OpenClaw config permissions. On POSIX, the config file is group-writable, world-writable, world-readable, or group-readable. A symlink is reported at medium severity because OpenClaw documents that a symlinked openclaw.json is unsupported. Native checks fs.config.perms_world_readable, fs.config.perms_writable, fs.config.perms_group_readable, and fs.config.symlink. Windows ACLs are not Unix mode bits. This rule does not report permission findings on Windows and does not run icacls. OpenClaw's audit does. Page: https://ironheights.dev/rules/ih-cfg-006/ - IH-CFG-007 (high): Dangerous tool permissions. tools.exec.security or an agent exec security is full, exec ask is off while security is not deny, or tools.elevated is enabled. Elevated allowFrom containing * is critical. Native tools.exec.security_full_configured and tools.elevated.allowFrom..wildcard overlap this rule. Interpreter allowlists, safeBins, and approval-file drift are left to the native audit. Page: https://ironheights.dev/rules/ih-cfg-007/ - IH-CFG-008 (medium): Skills load from an extra directory. skills.load.extraDirs or skills.load.allowSymlinkTargets is set. Extra directories are the lowest-precedence skill roots and are trusted by the operator. OpenClaw tells you to keep allowSymlinkTargets narrow. A home directory, a filesystem root, or a path that contains .. is critical. Other extra directories are medium. The native audit does not have this check; it does have skills.workspace.symlink_escape, which walks the workspace and is not repeated here. Page: https://ironheights.dev/rules/ih-cfg-008/ - IH-CFG-009 (medium): Sandbox disabled while tools can act. Sandbox mode is off, or sandbox.docker is set while mode is off, and the file also enables host exec, elevated tools, or an open room. A personal agent with sandbox off and tools.exec.security deny is a documented OpenClaw pattern and stays quiet. Native sandbox.docker_config_mode_off and the security.exposure.open_groups_with_runtime_or_fs checks overlap the noisy cases. Docker bind mounts, seccomp, and AppArmor are not reimplemented. Page: https://ironheights.dev/rules/ih-cfg-009/ - IH-LLM-001 (info): Advisory model review. An optional language-model review added a note. This is not a pattern rule and it does not scan files by itself. The model sees redacted skill text and the deterministic findings, and it can be wrong. The note never changes the verdict or the exit code. It appears only after `scan --llm` or `review`, and only when the model output matched the review schema. Page: https://ironheights.dev/rules/ih-llm-001/ --- ## Benchmark summary Source: https://ironheights.dev/benchmark/ (measured 2026-10-09) On a 20-skill synthetic corpus written by the Ironheights authors (10 malicious, 10 benign), Ironheights 0.1.0 sent 10 of 10 malicious samples to review, blocked 4 of 10, and flagged 0 of 10 benign samples. This is a regression check, not a real-world detection rate: the corpus is tiny, self-written, and close to the rule examples. Measured on version 0.1.0; not re-measured on 0.3.0, whose rules changed, so results there can differ. A one-off check of the same corpus with 0.1.5 gave review 10 of 10, block 3 of 10, and 0 of 10 benign samples flagged; it is not part of the published comparison. - Ironheights 0.1.0: review 10/10, block 4/10, benign flagged 0/10 - Cisco skill-scanner (Rules only (balanced and strict gave identical results); LLM judge off): review 4/10, benign flagged 0/10 - VirusTotal (public API uploads): flagged 0/10, benign flagged 0/10; Code Insight not measured --- ## Malicious skill tracker summary Source: https://ironheights.dev/tracker/ (JSON Feed: https://ironheights.dev/tracker/feed.json). Last updated 2026-10-10. 22 entries from public reports. Not a complete list: a skill missing from it is not evidence that it is harmless. ### letssendit (agentic front-running) (skill, reported 2026-06-23 by Palo Alto Networks Unit 42) Instructed installed agents to pool Solana cryptocurrency into the operator’s wallet for a meme-token launch. The operator bought first at the lowest price, then the token launched publicly, where coordinated agent activity could look like real demand. Status as stated by the source: removed. Unit 42 says OpenClaw banned the accounts and deleted the skills after its report. Ironheights coverage: not-covered. No Ironheights rule covers instructions to move funds. The scheme needs no code, download or credential path. Link: https://ironheights.dev/tracker/letssendit/ Sources: - Palo Alto Networks Unit 42, "OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat" (2026-06-23): https://unit42.paloaltonetworks.com/openclaw-ai-supply-chain-risk/ ### money-radar (runtime affiliate injection) (skill, reported 2026-06-23 by Palo Alto Networks Unit 42) Presented itself as an overseas financial-product advisor. On every use it made the agent fetch a product list from a remote domain and always recommend the affiliate links in it, so the operator could change the advice after install without republishing. Status as stated by the source: removed. Unit 42 says OpenClaw banned the accounts and deleted the skills after its report. Ironheights coverage: partial (IH-NET-001). IH-NET-001 flags the undeclared host the list is fetched from, because the line tells the agent to fetch it. Nothing flags the instruction to always use referral links; that is behaviour, not a pattern our rules know. Link: https://ironheights.dev/tracker/money-radar/ Sources: - Palo Alto Networks Unit 42, "OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat" (2026-06-23): https://unit42.paloaltonetworks.com/openclaw-ai-supply-chain-risk/ ### TradingView assistant skills delivering the cluw stealer (skill, reported 2026-06-23 by Palo Alto Networks Unit 42) Two skills published on 17 May 2026 posed as macOS trading assistants. A required step sent the agent to a paste-site page with an encoded command that fetched a macOS infostealer called cluw from new attacker infrastructure. Unit 42 says ClawHub’s automated audit returned Pass or no verdict for them. Status as stated by the source: removed. Unit 42 says OpenClaw banned the accounts and deleted the skills after its report. Ironheights coverage: partial (IH-NET-001). The paste-site link is flagged by IH-NET-001 (high, because paste sites are on the high-risk host list). The command lived on the paste site. Link: https://ironheights.dev/tracker/tradingview-cluw/ Sources: - Palo Alto Networks Unit 42, "OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat" (2026-06-23): https://unit42.paloaltonetworks.com/openclaw-ai-supply-chain-risk/ ### soroban-trader-skill and burhanclaw-soroban-trader (skill, reported 2026-04-14 by Community report on GitHub (Rayzar)) Stellar trading skills that, per the report, told the agent to ask the user for starting capital, swapped real funds for worthless tokens from a fake issuer, stored wallet keys with a weak hard-coded salt, and signed mainnet transactions without confirmation. Status as stated by the source: unknown. An OpenClaw maintainer replied “user banned” on 14 April 2026. The reply does not say whether the skills were removed. Ironheights coverage: not-covered. No Ironheights rule covers a fake token issuer, a request for funds, or the key-storage path the report describes. Link: https://ironheights.dev/tracker/soroban-trader/ Sources: - GitHub (openclaw/clawhub issue tracker), "openclaw/clawhub issue #1664: Malicious skill: soroban-trader-skill — confirmed on-chain scam with fake USDC" (2026-04-14): https://github.com/openclaw/clawhub/issues/1664 ### omnicogg (22 MB padded README) (skill, reported 2026-03-06 by JFrog Security Research) Posed as a unified API for Reddit, Steam, Spotify, GitHub, Discord and YouTube and asked for tokens to all of them. An encoded download-and-run command was hidden in a README padded to about 22 MB, which pushed it past the size limits of the scanners that reviewed it. JFrog reported over 5,000 downloads in 19 days. Status as stated by the source: removed. Unit 42 reported the skill to ClawHub; it says OpenClaw banned the accounts and deleted all five skills in its report. Ironheights coverage: not-covered. Ironheights would miss this with default settings. Files over 1 MiB are skipped without being read. The scan is now reported as incomplete (exit code 3) instead of no findings, but the padded file itself is still not checked. In our synthetic test, raising limits.maxFileBytes above the file size let IH-EXEC-001 flag a decode-and-run line in a padded file. Link: https://ironheights.dev/tracker/omnicogg/ Sources: - JFrog Security Research, "Anatomy of a Deception: Uncovering the ‘omnicogg’ Dropper in ClawHub" (2026-03-06): https://research.jfrog.com/post/omnicogg-malicious-skill/ - Palo Alto Networks Unit 42, "OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat" (2026-06-23): https://unit42.paloaltonetworks.com/openclaw-ai-supply-chain-risk/ ### Skills distributing an Atomic macOS Stealer variant (campaign, reported 2026-02-23 by Trend Micro) Trend Micro identified 39 skills that told the agent to install a fake OpenClawCLI from a lookalike website, which served an obfuscated command that downloaded an AMOS variant. The stealer showed a fake password prompt and collected keychains, browser data, documents and wallet data. Trend Micro observed that a more capable model refused the install while another kept asking the user to run it. Status as stated by the source: removed. Trend Micro says the 39 skills had all been taken down at the time of writing, while their code remained in ClawHub’s GitHub repository and on other skill sites. Ironheights coverage: partial (IH-NET-001). Only the link to the lookalike website is flagged (IH-NET-001). The command lived on the website. Link: https://ironheights.dev/tracker/trendmicro-amos-openclawcli/ Sources: - Trend Micro, "Malicious OpenClaw Skills Used to Distribute Atomic macOS Stealer" (2026-02-23): https://www.trendmicro.com/en/research/26/b/openclaw-skills-used-to-distribute-atomic-macos-stealer.html ### copywritings and airbnb by StveenLi (skill, reported 2026-02-10 by Community reports on GitHub (loganaden)) The skills required a tool from a lookalike website. The website, not the skill, carried the obfuscated install commands for Windows and macOS, which pointed to the same raw IP address as the earlier campaigns. Status as stated by the source: removed. On 13 March 2026 an OpenClaw maintainer wrote that the publisher is banned and the reported skills are hidden. Ironheights coverage: partial (IH-NET-001). Only the link to the undeclared website is flagged (IH-NET-001, medium). The payload lives on the website, which Ironheights does not fetch. Link: https://ironheights.dev/tracker/stveenli-openclawcli-forum/ Sources: - GitHub (openclaw/clawhub issue tracker), "openclaw/clawhub issue #190: Malicious ai-skill (StveenLi/copywritings)" (2026-02-10): https://github.com/openclaw/clawhub/issues/190 - GitHub (openclaw/clawhub issue tracker), "openclaw/clawhub issue #191: Malicious ai-skill (StveenLi/airbnb)" (2026-02-10): https://github.com/openclaw/clawhub/issues/191 ### google-qx4 (fake openclaw-core requirement) (skill, reported 2026-02-10 by Snyk) A Google Workspace skill said an “openclaw-core” utility was required. Windows users were sent to a password-protected archive in a GitHub release and macOS users to a paste-site page with a command to copy into the terminal. openclaw-core does not exist. Status as stated by the source: unknown. Snyk says the skill was flagged after warnings and that clones often reappear within hours. It does not say the skill was removed. Ironheights coverage: partial (IH-NET-001). The paste-site link is flagged by IH-NET-001 (high, because paste sites are on the high-risk host list). The GitHub archive link is not flagged, and the command itself lived on the paste site. Link: https://ironheights.dev/tracker/google-qx4/ Sources: - Snyk, "How a Malicious Google Skill on ClawHub Tricks Users Into Installing Malware" (2026-02-10): https://snyk.io/blog/clawhub-malicious-google-skill-openclaw-malware/ ### Fake “OpenClawCLI” website lure (thiagoruss0, stveenli) (campaign, reported 2026-02-09 by OpenSourceMalware) About 40 trojanized skills from two accounts contained no malicious code, only a line saying a tool called OpenClawCLI must be installed first, with a link to a polished lookalike website that served the obfuscated install command. Because the skill files were clean, VirusTotal scanning of the skills did not catch them. Status as stated by the source: unknown. The report says the website was offline as of 9 February 2026 and that the skills remained in the openclaw/skills GitHub repository. It does not state the status of the skills on ClawHub. Ironheights coverage: partial (IH-NET-001). Only the link to the undeclared website is flagged (IH-NET-001, medium, a review verdict). The install command lived on the website. Link: https://ironheights.dev/tracker/openclawcli-vercel/ Sources: - OpenSourceMalware, "Malicious ClawHub Skills Use External Websites to Hide in Plain Sight" (2026-02-09): https://opensourcemalware.com/blog/malicious-clawhub-skills-use-external-websites-to-hide-in-plain-sight ### Bitdefender Labs analysis of OpenClaw skills (study, reported 2026-02-05 by Bitdefender Labs) Found about 17% of the OpenClaw skills it analyzed in the first week of February 2026 behaving maliciously, 54% of those crypto-themed. It tied 199 skills to one publisher, sakaen736jih, and described a “sync” skill that searched the workspace for private-key files and sent them to an attacker endpoint. Status as stated by the source: unknown. A study, not a single listing. No status given for individual skills. Ironheights coverage: not-assessed. A measurement across many skills. We have not mapped its findings to individual rules. Link: https://ironheights.dev/tracker/bitdefender-17pct/ Sources: - Bitdefender Labs, "Helpful Skills or Hidden Payloads? Bitdefender Labs Dives Deep into the OpenClaw Malicious Skill Trap" (2026-02-05): https://www.bitdefender.com/en-us/blog/labs/helpful-skills-or-hidden-payloads-bitdefender-labs-dives-deep-into-the-openclaw-malicious-skill-trap ### security-check (security-audit) and nanopdf (skill, reported 2026-02-05 by Community report on GitHub (Jeff Schell)) A security-auditing skill and a PDF skill carried the same encoded command in their install sections, which fetched and ran code from a raw IP address. Status as stated by the source: removed. On 13 March 2026 an OpenClaw maintainer wrote that the skills are no longer public and the malware cluster was taken down. Ironheights coverage: covered (IH-EXEC-001). The inline decode-and-run line is flagged by IH-EXEC-001. Link: https://ironheights.dev/tracker/security-check-nanopdf/ Sources: - GitHub (openclaw/clawhub issue tracker), "openclaw/clawhub issue #135: MALICIOUS SKILLS: security-check (security-audit) and nanopdf contain backdoor" (2026-02-05): https://github.com/openclaw/clawhub/issues/135 ### ToxicSkills study (study, reported 2026-02-05 by Snyk) Scanned 3,984 skills from ClawHub and skills.sh. Snyk confirmed 76 malicious payloads by hand and found 534 skills (13.4%) with at least one critical issue and 1,467 (36.82%) with any issue. Eight confirmed malicious skills were still installable on ClawHub at publication. Status as stated by the source: unknown. A study, not a single listing. Eight confirmed malicious skills were live at publication; current status not stated. Ironheights coverage: not-assessed. A measurement across many skills. We have not mapped its findings to individual rules. Link: https://ironheights.dev/tracker/snyk-toxicskills/ Sources: - Snyk, "Snyk Finds Prompt Injection in 36%, 1467 Malicious Payloads in a ToxicSkills Study of Agent Skills" (2026-02-05): https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/ - Snyk Labs, "Exploring the Threat Landscape of Agent Skills" (2026-02-05): https://research.snyk.io/blog/agent-skills-threat-landscape/ ### More skills by zaycv: linkedin-job-application, autoupdater, deepresearch (skill, reported 2026-02-04 by Community reports on GitHub (adrianwedd, hendrysadrak, rafadiasbsb)) Skills from the same publisher used a fake required “driver” or installer: an obfuscated macOS command that fetched code from a raw IP address, and a password-protected archive for Windows. The linkedin-job-application report says the command appeared four times in one SKILL.md, including a variant run with sudo. Status as stated by the source: removed. On 13 March 2026 an OpenClaw maintainer wrote on each issue that the publisher is banned or hidden and the reported skills are no longer public. Ironheights coverage: covered (IH-EXEC-001, IH-PRIV-001, IH-NET-001). The inline decode-and-run line is flagged by IH-EXEC-001 (critical, so the verdict is block), the sudo variant also by IH-PRIV-001, and the decoy installer host by IH-NET-001. The Windows archive link is not flagged. Link: https://ironheights.dev/tracker/zaycv-more/ Sources: - GitHub (openclaw/clawhub issue tracker), "openclaw/clawhub issue #124: Malicious skill linkedin-job-application by zaycv contained RCE payload" (2026-02-04): https://github.com/openclaw/clawhub/issues/124 - GitHub (openclaw/clawhub issue tracker), "openclaw/clawhub issue #138: Malicious skill ‘autoupdater’ contains malware payload" (2026-02-05): https://github.com/openclaw/clawhub/issues/138 - GitHub (openclaw/clawhub issue tracker), "openclaw/clawhub issue #154: Malicious skill distributing malware - zaycv/deepresearch" (2026-02-06): https://github.com/openclaw/clawhub/issues/154 ### Fake “ClawHub CLI” skills by zaycv (clawhub, clawdhub1) (skill, reported 2026-02-02 by Snyk; GitHub issue by lycfyi) A skill posing as the official ClawHub command-line tool, promising “advanced caching”. It told macOS users to run an obfuscated command that fetched a second stage from a raw IP address, and Windows users to run a file from a password-protected archive in a GitHub release. Snyk reported about 7,700 downloads of the original before it was removed on 3 February, and a renamed copy that was still live when its advisory was published. Status as stated by the source: removed. On 13 March 2026 an OpenClaw maintainer wrote on issue #108 that the publisher is banned or hidden and the reported skills are no longer public. Ironheights coverage: partial (IH-EXEC-001, IH-NET-001). Issue #108 quotes the decode-and-run line from the SKILL.md, which IH-EXEC-001 flags, along with the decoy host (IH-NET-001). Snyk describes the macOS step as a glot.io paste-site link, which only IH-NET-001 flags (high). The GitHub-hosted archive is not flagged. Link: https://ironheights.dev/tracker/zaycv-clawhub-cli/ Sources: - GitHub (openclaw/clawhub issue tracker), "openclaw/clawhub issue #108: Malicious skill zaycv/clawhub distributes malware via base64-encoded payload" (2026-02-02): https://github.com/openclaw/clawhub/issues/108 - Snyk, "Inside the ‘clawdhub’ Malicious Campaign: AI Agent Skills Drop Reverse Shells on OpenClaw Marketplace" (2026-02-04): https://snyk.io/articles/clawdhub-malicious-campaign-ai-agent-skills/ ### VirusTotal Code Insight findings on OpenClaw skills (study, reported 2026-02-02 by VirusTotal) VirusTotal reported analysing more than 3,016 OpenClaw skills, hundreds of them with malicious characteristics, including 314 tied to a single user. Its point: nothing in such a skill file is malware by itself; the malware is the workflow it asks you to run. Status as stated by the source: unknown. A study, not a single listing. Ironheights coverage: not-assessed. A measurement across many skills. We have not mapped its findings to individual rules. Link: https://ironheights.dev/tracker/virustotal-code-insight/ Sources: - VirusTotal Blog, "From Automation to Infection: How OpenClaw AI Agent Skills Are Being Weaponized" (2026-02-02): https://blog.virustotal.com/2026/02/from-automation-to-infection-how.html ### WhatsApp and security-check lookalikes by moonshine-100rze (skill, reported 2026-02-02 by Community reports on GitHub (diegofornalha, biagiom)) Skills posing as WhatsApp automation and as a skill security checker carried base64-encoded shell commands disguised as installation steps, which fetched code from the same raw IP address used across the early campaigns. Status as stated by the source: removed. On 13 March 2026 an OpenClaw maintainer wrote on both issues that the publisher is banned or hidden and the reported skills are no longer public. Ironheights coverage: covered (IH-EXEC-001, IH-NET-001). The inline decode-and-run line is flagged by IH-EXEC-001; the decoy installer host in #110 by IH-NET-001. Link: https://ironheights.dev/tracker/moonshine-100rze/ Sources: - GitHub (openclaw/clawhub issue tracker), "openclaw/clawhub issue #109: Security Alert: Malicious WhatsApp Skills Detected on ClawHub" (2026-02-02): https://github.com/openclaw/clawhub/issues/109 - GitHub (openclaw/clawhub issue tracker), "openclaw/clawhub issue #110: Security Alert: malicious skill moonshine-100rze/skills-security-check-ngv" (2026-02-02): https://github.com/openclaw/clawhub/issues/110 ### “AuthTool” trading skills (campaign, reported 2026-02-01 by Koi Security) Crypto-trading skills that required a fake “AuthTool”: a password-protected archive from GitHub on Windows, and an obfuscated command on macOS that fetched code from the shared raw IP address. Status as stated by the source: unknown. No skill-specific status found. Unit 42 (23 June 2026) says skills from the early campaigns were “removed from the marketplace or marked as malicious”, which does not say which. Ironheights coverage: partial (IH-EXEC-001, IH-NET-001). The macOS decode-and-run line is flagged by IH-EXEC-001 and its decoy host by IH-NET-001. The Windows archive link on GitHub is not flagged. Link: https://ironheights.dev/tracker/authtool/ Sources: - Koi Security (Internet Archive copy, 10 February 2026), "ClawHavoc: 341 Malicious Clawed Skills Found by the Bot They Were Targeting" (2026-02-01): https://web.archive.org/web/20260210212946/https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting - Bitdefender Labs, "Helpful Skills or Hidden Payloads? Bitdefender Labs Dives Deep into the OpenClaw Malicious Skill Trap" (2026-02-05): https://www.bitdefender.com/en-us/blog/labs/helpful-skills-or-hidden-payloads-bitdefender-labs-dives-deep-into-the-openclaw-malicious-skill-trap ### ClawHavoc (campaign, reported 2026-02-01 by Koi Security) Koi audited all 2,857 skills then on ClawHub and reported 341 as malicious, 335 of them from one campaign it named ClawHavoc. The skills posed as crypto, Polymarket, YouTube, Google Workspace, auto-updater and ClawHub-lookalike tools. A fake “Prerequisites” section asked the user to paste an obfuscated command on macOS, which fetched the Atomic macOS Stealer (AMOS), or to run a file from a password-protected archive on Windows. Koi’s 16 February update raised the count to 824 as the registry grew past 10,700 skills. Status as stated by the source: unknown. No skill-specific status found. Unit 42 (23 June 2026) says skills from the early campaigns were “removed from the marketplace or marked as malicious”, which does not say which. Ironheights coverage: partial (IH-EXEC-001, IH-NET-001). IH-EXEC-001 flags the decode-and-run line when it is written in the skill, and IH-NET-001 flags the decoy or paste-site host. A Windows step that only links to a password-protected archive on GitHub is not flagged: GitHub is on the built-in allowlist and nothing is bundled. Link: https://ironheights.dev/tracker/clawhavoc/ Sources: - Koi Security (Internet Archive copy, 10 February 2026), "ClawHavoc: 341 Malicious Clawed Skills Found by the Bot They Were Targeting" (2026-02-01): https://web.archive.org/web/20260210212946/https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting - The Hacker News, "Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Users" (2026-02-02): https://thehackernews.com/2026/02/researchers-find-341-malicious-clawhub.html - Palo Alto Networks Unit 42, "OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat" (2026-06-23): https://unit42.paloaltonetworks.com/openclaw-ai-supply-chain-risk/ ### Malicious ClawHub skills targeting crypto and trading users (campaign, reported 2026-02-01 by OpenSourceMalware (Paul McCarty)) Reported 28 malicious skills published 27–29 January and a second group of 386 published 31 January–2 February, posing as crypto-trading and social-media tools. All shared the same command-and-control address and used social engineering to get users to run commands that stole exchange API keys, wallet keys, SSH credentials and browser passwords. The Hacker News reports this as the same activity Koi named ClawHavoc. Status as stated by the source: unknown. At publication the report said most of these skills were still in the openclaw/skills GitHub repository. No skill-specific status found. Unit 42 (23 June 2026) says skills from the early campaigns were “removed from the marketplace or marked as malicious”, which does not say which. Ironheights coverage: partial (IH-EXEC-001, IH-NET-001). Same delivery pattern as ClawHavoc: the inline decode-and-run line is flagged; a link to an archive on GitHub is not. Link: https://ironheights.dev/tracker/osm-first-wave/ Sources: - OpenSourceMalware, "Malicious ClawHub Skills Target OpenClaw Users" (2026-02-01): https://opensourcemalware.com/blog/malicious-clawhub-skills-target-openclaw-users - The Hacker News, "Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Users" (2026-02-02): https://thehackernews.com/2026/02/researchers-find-341-malicious-clawhub.html ### Polymarket skills with a hidden reverse shell (skill, reported 2026-02-01 by Koi Security; community report on GitHub (NCC-David)) Working Polymarket search code with one extra call buried in a search function. It downloaded a script from a raw IP address and ran it in a shell, opening a reverse shell to the attacker whenever the skill was used normally. Status as stated by the source: removed. On 13 March 2026 an OpenClaw maintainer wrote on issue #152 that polymarket-all-in-one is no longer public. We found no separate statement for better-polymarket. Ironheights coverage: covered (IH-EXEC-001, IH-EXEC-003, IH-NET-001). The shell call is flagged by IH-EXEC-001 (critical) and IH-EXEC-003, and the raw IP address raises IH-NET-001 to high. Link: https://ironheights.dev/tracker/polymarket-backdoor/ Sources: - Koi Security (Internet Archive copy, 10 February 2026), "ClawHavoc: 341 Malicious Clawed Skills Found by the Bot They Were Targeting" (2026-02-01): https://web.archive.org/web/20260210212946/https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting - GitHub (openclaw/clawhub issue tracker), "openclaw/clawhub issue #152: Malicious Skill Report (polymarket-all-in-one)" (2026-02-05): https://github.com/openclaw/clawhub/issues/152 ### rankaj (credential exfiltration) (skill, reported 2026-02-01 by Koi Security) Posed as a weather tool. It read the bot’s .env file, where API keys are kept, and posted the contents to a public request-catcher service. Status as stated by the source: unknown. No skill-specific status found. Unit 42 (23 June 2026) says skills from the early campaigns were “removed from the marketplace or marked as malicious”, which does not say which. Ironheights coverage: covered (IH-CRED-001, IH-NET-001). The .env path is flagged by IH-CRED-001, and the request-catcher host raises IH-NET-001 to high. Reading plus sending is flagged by IH-NET-002 only when a request call (curl, fetch( and similar) or an instruction to send sits within a few lines of the path; our rebuild names the path and the host without a call, so we do not claim IH-NET-002 here. Link: https://ironheights.dev/tracker/rankaj/ Sources: - Koi Security (Internet Archive copy, 10 February 2026), "ClawHavoc: 341 Malicious Clawed Skills Found by the Bot They Were Targeting" (2026-02-01): https://web.archive.org/web/20260210212946/https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting - The Hacker News, "Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Users" (2026-02-02): https://thehackernews.com/2026/02/researchers-find-341-malicious-clawhub.html ### x-trends-nvdfx (bundled Windows executable) (skill, reported 2026-02-01 by Community report on GitHub (plgonzalezrx8)) The skill shipped a Windows executable named openclaw-agent.exe. The reporter says multiple antivirus engines on VirusTotal flagged it as malicious. Status as stated by the source: removed. On 13 March 2026 an OpenClaw maintainer wrote that the skill is no longer public and the publisher is no longer reachable. Ironheights coverage: covered (IH-BIN-001). A bundled .exe is flagged by IH-BIN-001 (high). Ironheights does not judge whether the executable is malware; it flags that one is there. Link: https://ironheights.dev/tracker/x-trends-nvdfx/ Sources: - GitHub (openclaw/clawhub issue tracker), "openclaw/clawhub issue #93: Found a malicious skill uploaded by an user. Including malicious binary report." (2026-02-01): https://github.com/openclaw/clawhub/issues/93 - Bitdefender Labs, "Helpful Skills or Hidden Payloads? Bitdefender Labs Dives Deep into the OpenClaw Malicious Skill Trap" (2026-02-05): https://www.bitdefender.com/en-us/blog/labs/helpful-skills-or-hidden-payloads-bitdefender-labs-dives-deep-into-the-openclaw-malicious-skill-trap