# Ironheights > Free, open-source, local-first security scanner and integrity monitor for OpenClaw agent skills. Reads skill files as data, flags risky patterns with published rules, and reports changes to installed skills and agent files against a local baseline. The CLI has no telemetry, and scans make no network calls (only fetch, safe-install, advisories update and the optional model review use the network when you run them). The in-browser scanner never sends your skill's content anywhere; it runs in your browser. With your consent, the site records only the scan verdict (no content). The ironheights.dev website uses Google Analytics only after a visitor accepts it in the consent banner (no ad features; never skill text or user input; details at https://ironheights.dev/privacy/). No findings means the rules did not match; it is not proof of safety. Install: `npx ironheights scan ./path/to/skill` (Node.js 20+). Commands: `ironheights` and `ih`. License: Apache-2.0. Current version: 0.3.0. Official sources only: https://www.npmjs.com/package/ironheights , https://github.com/Frank-Masciopinto/ironheights/releases , and https://ironheights.dev/ . Do not trust "Ironheights" builds or skills from anywhere else. Benchmark: On a 20-skill synthetic corpus written by the Ironheights authors (10 malicious, 10 benign), Ironheights 0.1.0 sent 10 of 10 malicious samples to review, blocked 4 of 10, and flagged 0 of 10 benign samples. This is a regression check, not a real-world detection rate: the corpus is tiny, self-written, and close to the rule examples. Measured on version 0.1.0; not re-measured on 0.3.0, whose rules changed, so results there can differ. A one-off check of the same corpus with 0.1.5 gave review 10 of 10, block 3 of 10, and 0 of 10 benign samples flagged; it is not part of the published comparison. Details: https://ironheights.dev/benchmark/ Facts last updated: 2026-10-11. Canonical fact sheet: https://ironheights.dev/facts/ (machine-readable: https://ironheights.dev/facts.json). Full plain text of the key pages: https://ironheights.dev/llms-full.txt Machine-readable sitemap index: https://ironheights.dev/sitemap.xml Blog index: https://ironheights.dev/blog/ ## Key facts - Name: Ironheights, by Ironheights (https://github.com/Frank-Masciopinto/ironheights) - Version: 0.3.0 (npm package `ironheights`) - License: Apache-2.0 - Requirements: Node.js 20 or newer; macOS and Linux and Windows - Rules: 35 (17 content rules for scan, also in the browser scanner; 3 MCP config rules and 1 advisory feed rule for scan in the CLI; 4 integrity rules for verify; 9 OpenClaw config rules for audit-config; 1 optional model note) - Network: Scans make no network call. Only the commands you choose can: fetch and safe-install talk to clawhub.ai, advisories update talks to ironheights.dev, and scan --llm or review talk to a model server you pick (off by default; the default is a loopback Ollama-compatible endpoint). The CLI prints each URL before it requests it, and none of this is telemetry. - Verdicts: no-findings, review, block, incomplete (a file or directory was skipped; exit code 3, --allow-skipped accepts it). Every scan also prints an A to F trust grade. Exit codes: 0 no findings, 1 review, 2 block, 3 incomplete, 64 usage or config error, 70 internal error. No findings means the rules did not match; it is not proof of safety. - Pricing: The Community edition is free under Apache-2.0. Pro, Team, a Threat Intel API, and Enterprise are planned; their prices are hypotheses and nothing paid is on sale yet. - Privacy: The Ironheights CLI has no telemetry. The in-browser scanner never sends your skill's content anywhere; it runs in your browser. With your consent, the site records only the scan verdict (no content) through Google Analytics. - Security reports: private GitHub security advisory (https://github.com/Frank-Masciopinto/ironheights/security/advisories/new) ## How to cite Ironheights - Link to a fact's anchor on https://ironheights.dev/facts/ (for example https://ironheights.dev/facts/#version) and include its "last updated" date. - Quote benchmark results as counts with their caveat (synthetic, self-written, 20 skills), never as percentages or as a real-world detection rate. - Say that a clean scan means no rule matched; do not describe Ironheights as making a skill safe. - Paid tiers are hypotheses and not for sale; only the free Community edition exists. ## Facts - [Ironheights facts](https://ironheights.dev/facts/): The canonical fact sheet for Ironheights: what it is, who makes it, license, current version, install commands, Node.js support, rule counts, limits, benchmark counts with caveats, privacy, and official sources. Also as facts.json. - [facts.json](https://ironheights.dev/facts.json): the same facts as JSON, with stable ids and dates - [llms-full.txt](https://ironheights.dev/llms-full.txt): plain text of the facts, how it works, limitations, privacy, FAQ, rules, benchmark, and tracker ## What is new in 0.3.0 - [Features](https://ironheights.dev/features/): What Ironheights 0.3.0 does beyond scanning: check how it sits beside your other security tools, scan a ClawHub skill before installing it, signed baselines, a guard plugin (not a sandbox), an A to F grade, and honest incomplete verdicts. Commands and limits for each. - [Works next to your other security tools](https://ironheights.dev/features/#coexist): ironheights coexist (alias doctor coexist) reads files only to list other security tools (ClawHub vetting skills, guard plugins, scanner CLIs, CI and pre-commit scanners) and reports overlaps as IH-COEX-001 to IH-COEX-011, each with a fix. It runs none of them, makes no network call and writes nothing. Detection is heuristic, and no findings is not proof that tools will not interfere. Limit: Detection is heuristic. It reads files and names, so a tool that is not on its list, was renamed, or is only loaded in a running Gateway can be missed, and anyone can copy a name. No findings is not proof that two tools will not interfere. - [A guard that shares the hook](https://ironheights.dev/features/#guard-priority): The guard plugin runs before_tool_call at priority 80 by default, configurable from -1000 to 1000 (OpenClaw runs higher numbers first and a block ends the chain). It returns only block and blockReason, never blocks in monitor mode, keeps its files under ~/.ironheights, prefixes block reasons with ironheights:, and logs one line at startup when it sees other security tools. It is not a sandbox. Limit: Priority sets the order, not who is right. When two guards enforce, the higher one blocks first and the other never sees that call, so its log is missing it. The hook still runs inside the agent and is not a sandbox. Hook order follows OpenClaw's plugin docs as checked on 11 October 2026 and can change. - [Security tools are not trusted by name](https://ironheights.dev/features/#known-security-tools): When a scanned skill's folder or SKILL.md name equals a known security tool, scan adds a name-match-only note and lowers confidence one step on its Markdown injection and credential findings. Severity, score, grade, verdict and exit code do not change, and nothing is allowlisted, because a malicious skill can copy a name. Limit: A name match proves nothing about the files. The note helps you read findings. It is not a clearance, and a malicious skill that borrows a familiar name gets the same verdict as any other. - [Fetch and safe-install](https://ironheights.dev/features/#safe-install): ironheights fetch owner/slug downloads a ClawHub skill over HTTPS without executing it and scans it; safe-install copies it into your skills folder only when the verdict is no-findings (or review with --accept-review). Block and incomplete are never installed. Limit: A clean verdict means no rule matched, not that the skill is safe. This is one of the few commands that uses the network, and only when you run it. - [Signed advisory feed support](https://ironheights.dev/features/#advisory-feed): The CLI can download and verify a signed advisory feed (Ed25519, key pinned in the CLI) and reports IH-ADV-001 when a cached feed lists a skill by name, content hash or indicator host. The feed itself is not published yet, so until it is live scans report nothing from the feed. Limit: The feed is not published yet. Until it is, advisories update has nothing to download and scans report nothing from the feed. A skill missing from a feed is not evidence that it is harmless. - [Signed baselines](https://ironheights.dev/features/#signed-baselines): baseline create --key and verify --key sign and check baseline.json with an HMAC-SHA256 or Ed25519 key file you keep. A signature mismatch is reported as a tampered baseline (critical IH-INT-001, exit code 2). Limit: An attacker who can write your home directory and also has the key can sign a new baseline. Keep the key file private, and a copy of it off the machine if you can. - [Guard plugin for agent tool calls](https://ironheights.dev/features/#guard): The guard is an in-process OpenClaw before_tool_call plugin that watches four behaviors (credential reads, download-and-execute, undeclared or high-risk hosts, writes to agent identity files and skill folders). It defaults to monitor mode, which logs and does not block. It is not a sandbox, and a compromised skill that can edit OpenClaw config can turn it off. Limit: The guard is not a sandbox. It runs inside the OpenClaw process, so a compromised skill that can edit your OpenClaw config or the policy file can switch it off. It sees only the tool name and parameters OpenClaw passes in. A quiet log is not proof that nothing happened. - [A to F trust grade](https://ironheights.dev/features/#trust-grade): Every scan prints a trust grade from 0 to 100 (A 90-100, B 80-89, C 70-79, D 60-69, F 0-59) based on the existing risk points, next to the line “Absence of findings is not proof of safety.” A scan that skipped anything is graded incomplete, with no number. Limit: An A means the rules found little to add up. It does not mean the skill is safe. A scan that skipped anything is graded incomplete, with no number. - [Honest incomplete verdicts](https://ironheights.dev/features/#incomplete-scans): A scan that skipped a file (for example over 1 MiB) or a .git or node_modules directory reports the verdict incomplete with exit code 3, names what was skipped, and grades incomplete, unless the scanned files already reached review or block. dist/ is scanned. Limit: Incomplete means part of the skill was not checked at all. --allow-skipped and ignoreDirs let you accept that. They do not scan what was skipped. - [Piped JSON that stays whole](https://ironheights.dev/features/#piped-json): Fixed in 0.2.0: piped scan --json and --format html output is no longer cut off at 64 KiB; the process waits for the pipe to accept the whole report. Limit: This is a bug fix, not a new detection. It does not change what a scan finds. - [OpenClaw config audit](https://ironheights.dev/features/#config-audit): ironheights audit-config reads the local OpenClaw config and reports risky settings as IH-CFG-001 to IH-CFG-009. It is offline and read-only, and it does not replace openclaw security audit. Limit: It reads the file, not the running system. Settings that come from environment variables are not seen. - [MCP configuration rules](https://ironheights.dev/features/#mcp-rules): scan reports IH-MCP-001, IH-MCP-002 and IH-MCP-003 for risky MCP server commands, literal secrets in a server environment, and broad filesystem roots. The in-browser scanner does not run these. Limit: CLI only: the in-browser scanner does not run these rules. A pinned package can still be malicious. - [Only what is new](https://ironheights.dev/features/#since-baseline): scan --since-baseline reports only findings that are new compared with an integrity baseline or a previous JSON result, and counts and lists the omitted ones. Limit: A finding you already accepted is hidden from the list, not made safe. - [Scan a piece of text](https://ironheights.dev/features/#text-scan): scan --stdin and scan --text run the content rules on one piece of text and label the result as a limited text scan; the text is not executed. Limit: A text scan has no skill folder, so it cannot check files, hashes or the baseline. - [Suppressions that need a reason](https://ironheights.dev/features/#suppressions): Inline ironheights-ignore comments and config suppressions require a reason of at least 8 characters; suppressed findings are counted and listed, and critical and integrity findings stay visible unless suppressCritical or suppressIntegrity is set. Limit: A suppression records your decision. It does not make the line safe. - [CI action, pre-commit hook and Windows](https://ironheights.dev/features/#ci): The 0.2.0 release added a composite GitHub Action (action.yml, pinned to an exact version), a pre-commit hook, and Windows CI on Node.js 20.0.0 and 24. Limit: Windows support is new in 0.2.0 and is checked in CI, not yet as widely used as macOS and Linux. - [Optional model second opinion](https://ironheights.dev/features/#model-review): scan --llm and review are opt-in. They send a capped, secret-scrubbed copy of the skill to a model server you choose (a loopback Ollama-compatible endpoint by default) and add IH-LLM-001 notes that never change the verdict, the grade or the exit code. Limit: Models can be wrong, and the scrub can miss a secret. A silent model is not a clearance. ## Product - [Ironheights home](https://ironheights.dev/): Free, open-source, local-first scanner and integrity monitor for OpenClaw skills. - [Features](https://ironheights.dev/features/): What Ironheights 0.3.0 does beyond scanning: check how it sits beside your other security tools, scan a ClawHub skill before installing it, signed baselines, a guard plugin (not a sandbox), an A to F grade, and honest incomplete verdicts. Commands and limits for each. - [How it works](https://ironheights.dev/how-it-works/): Ironheights reads OpenClaw skill files as data, matches them against published rules, scores a verdict, and compares installed skills and agent files with a local baseline. - [What it detects](https://ironheights.dev/detects/): Every Ironheights detection rule: remote shells, prerequisite installs, undeclared network hosts, credential paths, hard-coded secrets, prompt-injection overrides, hidden text, persistence, bundled binaries, MCP and OpenClaw config settings, advisory matches, and integrity changes. - [Limitations](https://ironheights.dev/limitations/): What Ironheights cannot detect: novel and heavily obfuscated attacks, runtime-only behavior, compromised hosts, and social engineering. No findings means no rule matched, not that a skill is safe. - [Pricing](https://ironheights.dev/pricing/): Ironheights Community is free and open source. Pro, Team, Threat Intel API, and Enterprise tiers are planned; prices are early hypotheses and nothing paid is on sale yet. - [Docs](https://ironheights.dev/docs/): Install Ironheights with npx or npm, run doctor, scan a skill, fetch and safe-install from ClawHub, create and sign a baseline, and verify. Commands, exit codes, config keys, and OpenClaw paths. - [Security and disclosure](https://ironheights.dev/security/): How to report a vulnerability in Ironheights, which versions are supported, official download sources, and how we handle malicious skill research. - [FAQ](https://ironheights.dev/faq/): Answers about Ironheights: what it scans, whether a clean scan means safe, privacy, Node.js versions, CI use, official sources, pricing, and vulnerability reports. - [Skill safety checklist](https://ironheights.dev/tools/checklist/): A free 10-minute checklist and risk quiz for vetting an OpenClaw or ClawHub skill before you install it. Runs in your browser, saves nothing online, and exports a client-ready summary. - [Benchmark](https://ironheights.dev/benchmark/): How Ironheights and Cisco skill-scanner (rules only) score on a 20-skill synthetic, self-written test corpus. Every sample, every miss, the limits, VirusTotal status, and the commands to reproduce it. - [Compare](https://ironheights.dev/compare/): Fair, sourced comparisons of Ironheights with VirusTotal scanning on ClawHub and Cisco's open-source skill-scanner. Where each one is stronger, what each one costs, and when to use both. - [Ironheights vs VirusTotal](https://ironheights.dev/compare/virustotal/): VirusTotal scans every ClawHub skill at publish time with Code Insight. Ironheights scans the copy on your machine and watches it for changes. What each does, where VirusTotal is stronger, and sources. - [Ironheights vs Cisco skill-scanner](https://ironheights.dev/compare/cisco-skill-scanner/): Cisco's open-source skill-scanner adds an LLM judge and publishes held-out recall. Ironheights is rules-only and adds baselines for OpenClaw. A sourced comparison, including where Cisco is stronger. - [Ironheights facts](https://ironheights.dev/facts/): The canonical fact sheet for Ironheights: what it is, who makes it, license, current version, install commands, Node.js support, rule counts, limits, benchmark counts with caveats, privacy, and official sources. Also as facts.json. - [Privacy](https://ironheights.dev/privacy/): The Ironheights CLI has no telemetry, and the in-browser scanner never sends your skill's content anywhere. This website uses Google Analytics only after you accept it; here is what it collects and how to opt out. - [Terms](https://ironheights.dev/terms/): Terms for using the Ironheights website and the open-source Ironheights CLI, licensed under Apache-2.0 and provided without warranty. ## Free tools - [Skill scanner](https://ironheights.dev/tools/scanner/): Paste a SKILL.md or drop a skill folder and get an Ironheights verdict in your browser: rule ids, severity, line numbers, and evidence. Nothing is uploaded. Same rules as the CLI. Runs entirely in the browser with the CLI's content rules (integrity checks need the CLI). Verdicts: no-findings, review (score 15+ or any high/medium finding), block (score 80+ or any critical finding), incomplete (a file was skipped). - [Detection rules reference](https://ironheights.dev/rules/): Plain-language reference for all 35 Ironheights rules: what each matches, severity and score, false positives, how to fix or tune it, and what it cannot catch. - [IH-EXEC-001: Remote content piped into an interpreter](https://ironheights.dev/rules/ih-exec-001/): critical. Fetching remote text and passing it straight to a shell or runtime executes attacker-controlled code. - [IH-EXEC-002: Prerequisite install from an external URL](https://ironheights.dev/rules/ih-exec-002/): high. Skills sometimes tell the agent to install a tool from a URL or git link before doing anything else. Each command is reported once, on the line that contains it. - [IH-EXEC-003: Dynamic code execution](https://ironheights.dev/rules/ih-exec-003/): high. eval, the Function constructor, and shell-enabled subprocess calls run strings as code. - [IH-NET-001: Undeclared network destination](https://ironheights.dev/rules/ih-net-001/): medium. A skill that contacts a host outside the allowlist can send data somewhere the user did not expect. A download, install, or fetch instruction is a contact, and so is a paste site or a file-drop host. A homepage field, a license URL, a schema link, or an official API host in prose is not a contact. - [IH-NET-002: Possible exfiltration](https://ironheights.dev/rules/ih-net-002/): high. A sensitive read and an outbound request in the same few lines can move credentials off the machine. Telling the agent to send a credential path to a URL counts. - [IH-CRED-001: Access to a sensitive path](https://ironheights.dev/rules/ih-cred-001/): high. References to keys, browser stores, wallets, shell history, or OpenClaw auth files expose credentials. A credential directory such as ~/.ssh, ~/.aws, ~/.gnupg, or ~/.azure counts with or without a file name after it. Windows forms count too: ~\.ssh, %USERPROFILE%\.ssh, and AppData paths for Chrome, Firefox, or the credential store. - [IH-CRED-002: Hard-coded secret](https://ironheights.dev/rules/ih-cred-002/): high. Private keys and live tokens checked into a skill can be copied by anyone who reads the skill. - [IH-CRED-003: Secret asked for in chat or memory](https://ironheights.dev/rules/ih-cred-003/): medium. Asking the user to paste a secret into chat or memory stores it in the transcript. - [IH-INJ-001: Instruction override](https://ironheights.dev/rules/ih-inj-001/): high. Phrases that tell the agent to ignore prior rules are a common way to hide malicious steps. - [IH-INJ-002: Hidden content](https://ironheights.dev/rules/ih-inj-002/): high. Invisible characters, HTML comments, and huge base64 blobs can hide instructions from a person reading the file. - [IH-INJ-003: Weaken agent safeguards](https://ironheights.dev/rules/ih-inj-003/): high. Instructions to disable approvals or edit agent files change the trust boundary of the assistant. - [IH-OBF-001: Obfuscated code](https://ironheights.dev/rules/ih-obf-001/): medium. Packed or encoded payloads are used to hide a command from a person reviewing the skill. - [IH-PERSIST-001: Persistence mechanism](https://ironheights.dev/rules/ih-persist-001/): high. Scheduled tasks, login hooks, and shell startup files keep code running after the skill is closed. - [IH-PRIV-001: Privilege or OS protection bypass](https://ironheights.dev/rules/ih-priv-001/): high. sudo, broad chmod, and commands that turn off Gatekeeper or firewall protections weaken the host. - [IH-BIN-001: Bundled executable or archive](https://ironheights.dev/rules/ih-bin-001/): high. Executables and archives shipped inside a skill can hide an installer. Archives are flagged and never extracted. - [IH-FS-001: Suspicious filesystem access](https://ironheights.dev/rules/ih-fs-001/): medium. Symlinks that leave the skill, path traversal, and hidden files can read or hide data outside the skill. - [IH-META-001: Skill metadata problem](https://ironheights.dev/rules/ih-meta-001/): low. OpenClaw discovers a skill from SKILL.md frontmatter. Missing fields make the skill harder to identify and review. - [IH-MCP-001: MCP server launched from a remote command](https://ironheights.dev/rules/ih-mcp-001/): high. An MCP config that starts a server with curl piped into a shell, or with npx of a package that is not pinned to a version, runs code the operator has not reviewed. A shell pipe is critical. A pinned package such as name@1.2.3, a local path, and a local node script are not. - [IH-MCP-002: Secret in an MCP server environment](https://ironheights.dev/rules/ih-mcp-002/): high. A literal secret in an MCP server env block is copied onto disk and into the server process. A reference such as ${API_KEY} is not a literal. - [IH-MCP-003: MCP server given a broad filesystem root](https://ironheights.dev/rules/ih-mcp-003/): medium. A filesystem MCP server pointed at /, a drive root, or a home directory can read far more than the project. A subdirectory such as ./notes or /home/alex/projects/notes is not a broad root. - [IH-INT-001: Skill file modified](https://ironheights.dev/rules/ih-int-001/): high. A file in an installed skill no longer matches the saved baseline. - [IH-INT-002: New skill file](https://ironheights.dev/rules/ih-int-002/): medium. A file or skill directory appeared after the baseline was created. - [IH-INT-003: Skill file removed](https://ironheights.dev/rules/ih-int-003/): medium. A file that was in the baseline is gone. - [IH-INT-004: Watched agent file changed](https://ironheights.dev/rules/ih-int-004/): high. An agent instruction, personality, memory, or config file changed since the baseline. - [IH-ADV-001: Advisory feed match](https://ironheights.dev/rules/ih-adv-001/): critical. The cached signed advisory feed lists this skill name, a file content hash, or an indicator host. The match is reported only when a local cache is present. Scan does not contact the network to refresh the feed. - [IH-CFG-001: Gateway bind is not loopback](https://ironheights.dev/rules/ih-cfg-001/): high. gateway.bind is lan, tailnet, custom, auto, or an all-interfaces address, or gateway.tailscale.mode is funnel. OpenClaw's native check gateway.bind_no_auth covers a remote bind without a shared secret, and gateway.tailscale_funnel covers public Funnel. This rule only reads the config value. It does not probe the listener. auto is medium because the effective bind is chosen at runtime. Funnel and 0.0.0.0 are critical. - [IH-CFG-002: Gateway auth is missing or a placeholder](https://ironheights.dev/rules/ih-cfg-002/): critical. gateway.auth.mode is none or trusted-proxy, a non-loopback bind has no auth object, or the token or password in the file is empty or a known placeholder. Native checks gateway.bind_no_auth, gateway.loopback_no_auth, gateway.token_placeholder_value, and gateway.trusted_proxy_auth overlap this rule. A loopback bind that omits auth is not flagged: OpenClaw's default is authenticated, and the token may live in OPENCLAW_GATEWAY_TOKEN, which this command does not read. trusted-proxy is critical because the proxy becomes the auth boundary; proxy IPs and headers are left to the native audit. - [IH-CFG-003: DM policy is open](https://ironheights.dev/rules/ih-cfg-003/): critical. A channel dmPolicy (or dm.policy) is open, so anyone can DM the agent. This matches the native check channels..dm.open. Mutable allowFrom entries and name matching are not reimplemented. - [IH-CFG-004: Group policy is open](https://ironheights.dev/rules/ih-cfg-004/): high. A channel groupPolicy is open, so any member of a group can talk to the agent. Severity rises to critical when the same config also enables host exec, elevated tools, or an open DM policy. Native security.exposure.open_groups_with_elevated and security.exposure.open_channels_with_exec cover the live combination; this rule only reads the file. - [IH-CFG-005: Plaintext secret in OpenClaw config](https://ironheights.dev/rules/ih-cfg-005/): high. A token, password, secret, or API key is a literal string in the config file. ${ENV} references and SecretRef objects (source env, file, exec, or store) are not literals. Placeholder literals are reported as IH-CFG-002 instead. Evidence is the key path plus . Native config.secrets.gateway_password_in_config and config.secrets.hooks_token_in_config are the overlapping checks; other secret keys in the file are reported here too. - [IH-CFG-006: OpenClaw config permissions](https://ironheights.dev/rules/ih-cfg-006/): critical. On POSIX, the config file is group-writable, world-writable, world-readable, or group-readable. A symlink is reported at medium severity because OpenClaw documents that a symlinked openclaw.json is unsupported. Native checks fs.config.perms_world_readable, fs.config.perms_writable, fs.config.perms_group_readable, and fs.config.symlink. Windows ACLs are not Unix mode bits. This rule does not report permission findings on Windows and does not run icacls. OpenClaw's audit does. - [IH-CFG-007: Dangerous tool permissions](https://ironheights.dev/rules/ih-cfg-007/): high. tools.exec.security or an agent exec security is full, exec ask is off while security is not deny, or tools.elevated is enabled. Elevated allowFrom containing * is critical. Native tools.exec.security_full_configured and tools.elevated.allowFrom..wildcard overlap this rule. Interpreter allowlists, safeBins, and approval-file drift are left to the native audit. - [IH-CFG-008: Skills load from an extra directory](https://ironheights.dev/rules/ih-cfg-008/): medium. skills.load.extraDirs or skills.load.allowSymlinkTargets is set. Extra directories are the lowest-precedence skill roots and are trusted by the operator. OpenClaw tells you to keep allowSymlinkTargets narrow. A home directory, a filesystem root, or a path that contains .. is critical. Other extra directories are medium. The native audit does not have this check; it does have skills.workspace.symlink_escape, which walks the workspace and is not repeated here. - [IH-CFG-009: Sandbox disabled while tools can act](https://ironheights.dev/rules/ih-cfg-009/): medium. Sandbox mode is off, or sandbox.docker is set while mode is off, and the file also enables host exec, elevated tools, or an open room. A personal agent with sandbox off and tools.exec.security deny is a documented OpenClaw pattern and stays quiet. Native sandbox.docker_config_mode_off and the security.exposure.open_groups_with_runtime_or_fs checks overlap the noisy cases. Docker bind mounts, seccomp, and AppArmor are not reimplemented. - [IH-LLM-001: Advisory model review](https://ironheights.dev/rules/ih-llm-001/): info. An optional language-model review added a note. This is not a pattern rule and it does not scan files by itself. The model sees redacted skill text and the deterministic findings, and it can be wrong. The note never changes the verdict or the exit code. It appears only after `scan --llm` or `review`, and only when the model output matched the review schema. - [Malicious ClawHub skill tracker](https://ironheights.dev/tracker/): Publicly reported malicious ClawHub and OpenClaw skills: who reported them and when, what they did, status as stated by the source, and which Ironheights rules flag the pattern. - [letssendit (agentic front-running)](https://ironheights.dev/tracker/letssendit/): Skill reported by Palo Alto Networks Unit 42 on 2026-06-23. Ironheights coverage: Not covered. - [money-radar (runtime affiliate injection)](https://ironheights.dev/tracker/money-radar/): Skill reported by Palo Alto Networks Unit 42 on 2026-06-23. Ironheights coverage: Partly covered (IH-NET-001). - [TradingView assistant skills delivering the cluw stealer](https://ironheights.dev/tracker/tradingview-cluw/): Skill reported by Palo Alto Networks Unit 42 on 2026-06-23. Ironheights coverage: Partly covered (IH-NET-001). - [soroban-trader-skill and burhanclaw-soroban-trader](https://ironheights.dev/tracker/soroban-trader/): Skill reported by Community report on GitHub (Rayzar) on 2026-04-14. Ironheights coverage: Not covered. - [omnicogg (22 MB padded README)](https://ironheights.dev/tracker/omnicogg/): Skill reported by JFrog Security Research on 2026-03-06. Ironheights coverage: Not covered. - [Skills distributing an Atomic macOS Stealer variant](https://ironheights.dev/tracker/trendmicro-amos-openclawcli/): Campaign reported by Trend Micro on 2026-02-23. Ironheights coverage: Partly covered (IH-NET-001). - [copywritings and airbnb by StveenLi](https://ironheights.dev/tracker/stveenli-openclawcli-forum/): Skill reported by Community reports on GitHub (loganaden) on 2026-02-10. Ironheights coverage: Partly covered (IH-NET-001). - [google-qx4 (fake openclaw-core requirement)](https://ironheights.dev/tracker/google-qx4/): Skill reported by Snyk on 2026-02-10. Ironheights coverage: Partly covered (IH-NET-001). - [Fake “OpenClawCLI” website lure (thiagoruss0, stveenli)](https://ironheights.dev/tracker/openclawcli-vercel/): Campaign reported by OpenSourceMalware on 2026-02-09. Ironheights coverage: Partly covered (IH-NET-001). - [Bitdefender Labs analysis of OpenClaw skills](https://ironheights.dev/tracker/bitdefender-17pct/): Study published by Bitdefender Labs on 2026-02-05. Ironheights coverage: Not assessed. - [security-check (security-audit) and nanopdf](https://ironheights.dev/tracker/security-check-nanopdf/): Skill reported by Community report on GitHub (Jeff Schell) on 2026-02-05. Ironheights coverage: Covered (IH-EXEC-001). - [ToxicSkills study](https://ironheights.dev/tracker/snyk-toxicskills/): Study published by Snyk on 2026-02-05. Ironheights coverage: Not assessed. - [More skills by zaycv: linkedin-job-application, autoupdater, deepresearch](https://ironheights.dev/tracker/zaycv-more/): Skill reported by Community reports on GitHub (adrianwedd, hendrysadrak, rafadiasbsb) on 2026-02-04. Ironheights coverage: Covered (IH-EXEC-001, IH-PRIV-001, IH-NET-001). - [Fake “ClawHub CLI” skills by zaycv (clawhub, clawdhub1)](https://ironheights.dev/tracker/zaycv-clawhub-cli/): Skill reported by Snyk; GitHub issue by lycfyi on 2026-02-02. Ironheights coverage: Partly covered (IH-EXEC-001, IH-NET-001). - [VirusTotal Code Insight findings on OpenClaw skills](https://ironheights.dev/tracker/virustotal-code-insight/): Study published by VirusTotal on 2026-02-02. Ironheights coverage: Not assessed. - [WhatsApp and security-check lookalikes by moonshine-100rze](https://ironheights.dev/tracker/moonshine-100rze/): Skill reported by Community reports on GitHub (diegofornalha, biagiom) on 2026-02-02. Ironheights coverage: Covered (IH-EXEC-001, IH-NET-001). - [“AuthTool” trading skills](https://ironheights.dev/tracker/authtool/): Campaign reported by Koi Security on 2026-02-01. Ironheights coverage: Partly covered (IH-EXEC-001, IH-NET-001). - [ClawHavoc](https://ironheights.dev/tracker/clawhavoc/): Campaign reported by Koi Security on 2026-02-01. Ironheights coverage: Partly covered (IH-EXEC-001, IH-NET-001). - [Malicious ClawHub skills targeting crypto and trading users](https://ironheights.dev/tracker/osm-first-wave/): Campaign reported by OpenSourceMalware (Paul McCarty) on 2026-02-01. Ironheights coverage: Partly covered (IH-EXEC-001, IH-NET-001). - [Polymarket skills with a hidden reverse shell](https://ironheights.dev/tracker/polymarket-backdoor/): Skill reported by Koi Security; community report on GitHub (NCC-David) on 2026-02-01. Ironheights coverage: Covered (IH-EXEC-001, IH-EXEC-003, IH-NET-001). - [rankaj (credential exfiltration)](https://ironheights.dev/tracker/rankaj/): Skill reported by Koi Security on 2026-02-01. Ironheights coverage: Covered (IH-CRED-001, IH-NET-001). - [x-trends-nvdfx (bundled Windows executable)](https://ironheights.dev/tracker/x-trends-nvdfx/): Skill reported by Community report on GitHub (plgonzalezrx8) on 2026-02-01. Ironheights coverage: Covered (IH-BIN-001). - [Tracker JSON feed](https://ironheights.dev/tracker/feed.json): JSON Feed 1.1 of every tracker entry with its sources ## Answers Each answer page opens with a short direct answer (quoted below), followed by detail, limits, and sources. - [Answers](https://ironheights.dev/answers/): Short, sourced answers to common questions about ClawHub skill safety, malicious OpenClaw skills, prompt injection, VirusTotal scanning, and how Ironheights works and where it stops. - [Is a ClawHub skill safe to install?](https://ironheights.dev/answers/is-a-clawhub-skill-safe-to-install/): Not automatically. Most ClawHub skills are ordinary, but researchers found hundreds of malicious ones in 2026, and some passed the marketplace's VirusTotal scan. Treat every skill as code that runs with your agent's access: check the listing, read the setup section and links, scan it, and give it only the access it needs. - [What is a malicious ClawHub skill?](https://ironheights.dev/answers/what-is-a-malicious-clawhub-skill/): A malicious ClawHub skill is an OpenClaw skill written to harm the person who installs it. Its SKILL.md instructions get the agent, or you, to run a hidden installer, send credentials or files to an attacker, weaken the agent's safeguards, or move money. Most reported cases hid malware behind a fake setup step. - [What is prompt injection in an agent skill?](https://ironheights.dev/answers/what-is-prompt-injection-in-an-agent-skill/): Prompt injection in an agent skill is text in the skill's files that tries to take control of the agent: telling it to ignore earlier rules, hide actions from you, turn off confirmations, or edit its own instruction files. It works because the agent cannot reliably tell trusted instructions from text supplied by the skill's author. - [What is OpenClaw skill supply-chain risk?](https://ironheights.dev/answers/what-is-openclaw-skill-supply-chain-risk/): OpenClaw skill supply-chain risk is the risk you take on by running instructions written by someone else. A third-party skill, a later update to it, or a website or file it depends on can turn harmful, and it acts with your agent's access to files, accounts and keys. It is the agent version of a malicious package. - [Does VirusTotal scan ClawHub skills?](https://ironheights.dev/answers/does-virustotal-scan-clawhub-skills/): Yes. Since 7 February 2026, every skill published to ClawHub is scanned with VirusTotal, including Code Insight, an LLM review of SKILL.md and the files it references. Benign skills are approved, suspicious ones get a warning, malicious ones are blocked from download, and active skills are re-scanned daily. OpenClaw calls it helpful but not a silver bullet. - [How do I scan an OpenClaw skill for malware?](https://ironheights.dev/answers/how-do-i-scan-an-openclaw-skill-for-malware/): Run npx ironheights scan with the path to the skill folder, or paste its SKILL.md into the free browser scanner on this site. Both read the files as text, never run them, and report each risky pattern with a rule id, line and evidence. Then read every finding: no findings means no rule matched, not that the skill is safe. - [How do I verify a skill from ClawHub?](https://ironheights.dev/answers/how-do-i-verify-a-skill-from-clawhub/): Confirm you are on the skill's real ClawHub listing and the name and publisher are what you expect, read its VirusTotal status, then read the raw SKILL.md setup section, commands and links yourself. Scan the downloaded folder with a local scanner, install only if everything fits the skill's job, and record a baseline right after. - [How do I check if a skill changed after install?](https://ironheights.dev/answers/how-do-i-check-if-a-skill-changed-after-install/): Record a baseline right after you install and review the skill: npx ironheights baseline create stores a hash, size and mode for every watched file. Later, npx ironheights verify compares the current files with that record and lists every file that was added, modified, removed or had its permissions changed, with a rule id for each. - [How do I install Ironheights?](https://ironheights.dev/answers/how-do-i-install-ironheights/): You need Node.js 20 or newer. Run npx ironheights scan with the path to a skill to use it without installing, or install the command globally with npm install -g ironheights; ih is a shorter alias for the same command. Get it only from the ironheights package on npm, the project's GitHub releases, or this site. - [Is Ironheights free and open source?](https://ironheights.dev/answers/is-ironheights-free-and-open-source/): Yes. The Ironheights command-line scanner, its detection rules, the benchmark harness and the advisory OpenClaw skill are free and open source under the Apache-2.0 license, with the source on GitHub. Paid Pro, Team, Threat Intel API and Enterprise tiers are planned, but their prices are hypotheses and nothing paid is on sale yet. - [Does Ironheights send my data anywhere?](https://ironheights.dev/answers/does-ironheights-send-my-data-anywhere/): The CLI has no telemetry, and a scan makes no network call. Only commands you run on purpose use the network, such as fetch or the optional model review. The in-browser scanner never sends your skill's content anywhere. The website uses Google Analytics only after you accept it, and then records only the scan verdict. - [Can I run Ironheights alongside other security scanners?](https://ironheights.dev/answers/can-i-run-ironheights-alongside-other-security-scanners/): Yes. Ironheights reads files and never runs another tool, and its guard stays in monitor mode unless you change it, so it can sit beside other scanners. Run ironheights coexist to list the other security tools it can see and where they overlap, with a fix for each. The check is heuristic, and a clean report is not proof. - [What does Ironheights not detect?](https://ironheights.dev/answers/what-does-ironheights-not-detect/): Ironheights only sees patterns its rules describe in the files it reads. It misses payloads hosted on a linked website or paste site, files over 1 MiB by default, behavior that appears only at runtime, instructions to move money, novel or heavily obfuscated attacks, and tampering by someone who can rewrite its baseline. No findings is not proof of safety. ## Source - [GitHub repository](https://github.com/Frank-Masciopinto/ironheights): source, issues, and releases - [npm package](https://www.npmjs.com/package/ironheights): published with provenance - [Rule reference](https://github.com/Frank-Masciopinto/ironheights/blob/main/docs/rules.md): every detection rule with examples - [Security policy](https://github.com/Frank-Masciopinto/ironheights/blob/main/SECURITY.md): report vulnerabilities through a private GitHub advisory ## Blog - [Ironheights 0.3.0: running next to the security tools you already have](https://ironheights.dev/blog/ironheights-0-3-0-run-next-to-other-security-tools/): Ironheights 0.3.0 adds ironheights coexist, which finds other scanners and guards on your agent and reports overlaps. How it works, and where it stops. - [Ironheights 0.2.0: protection beyond scanning, and where it stops](https://ironheights.dev/blog/ironheights-0-2-0-protection-beyond-scanning/): Ironheights 0.2.0 adds fetch and safe-install, signed baselines, a guard plugin for agent tool calls, an A to F grade and advisory feed support. Plain language. - [What our scanner cannot catch (and what to do about it)](https://ironheights.dev/blog/what-ironheights-cannot-catch/): What Ironheights misses: payloads on linked sites, files over 1 MiB, runtime behavior, money-moving instructions and a compromised host, with a fix for each. - [Baselines for agent files: detecting silent tampering](https://ironheights.dev/blog/agent-file-baselines-detect-silent-tampering/): How to record a known-good baseline of OpenClaw skills and agent files like AGENTS.md, SOUL.md and MEMORY.md, and verify later what was added, modified or removed. - [Where your agent leaks credentials without you noticing](https://ironheights.dev/blog/where-openclaw-agents-leak-credentials/): The quiet places an OpenClaw agent exposes API keys, SSH keys and wallets: chat, memory, .env files, skill files and outbound requests. How to check each. - [Why a security skill that runs inside the agent can be bypassed](https://ironheights.dev/blog/why-in-agent-security-skills-can-be-bypassed/): A security skill shares the agent's context with the skills it checks, so a hostile skill can talk the agent out of it. Where the real trust boundary is. - [A 10-minute checklist for vetting an OpenClaw skill](https://ironheights.dev/blog/vet-openclaw-skill-10-minute-checklist/): A 10-minute routine to vet an OpenClaw or ClawHub skill before install: where it comes from, what to read in SKILL.md, what it can reach, what to record. - [How malicious skills trick agents: anatomy of a prerequisite attack](https://ironheights.dev/blog/malicious-skill-prerequisite-attack-anatomy/): How fake 'Prerequisites' sections in ClawHub skills get agents and people to run malware, the variants seen in 2026, and what a file scanner can and cannot see. ## Optional - [llms-full.txt](https://ironheights.dev/llms-full.txt): full plain text of the key pages - [RSS](https://ironheights.dev/blog/feed.xml): blog feed - [Privacy](https://ironheights.dev/privacy/) - [Terms](https://ironheights.dev/terms/)