v0.3.035 rules

Detection rules reference

Every rule Ironheights ships, in plain language: what it looks for, why it matters, how it scores, where it misfires, and what it cannot see. 17 rules read skill files during scan (and run in the browser scanner); 4 more join scan in the CLI; 4 come from verify; 9 from audit-config; 1 is an optional model note.

Quick answerLast updated

What do the Ironheights rules check?

Ironheights 0.3.0 has 35 rules. 17 content rules match risky patterns in skill files, such as remote scripts piped to a shell, credential paths, and instruction overrides. The rest cover MCP configs (3), the advisory feed (1), baseline integrity (4), OpenClaw config (9) and an optional model note (1).

All rules

All 35 rules

How severity turns into a verdict

Each finding adds points: critical 100, high 40, medium 15, low 5. A skill is block when any finding is critical or the total reaches 80; it is review when any finding is high or medium or the total reaches 15. You can change both thresholds, turn rules off, or change a rule's severity in the config. See configuration.

The rule list and metadata on this site are checked against the CLI's docs/rules.md on every build, so the ids, severities, and summaries here match the released scanner. Rules describe known patterns. A skill that matches none of them can still be harmful, and files larger than 1 MiB are skipped without being read and make the verdict incomplete, so they are never covered; read Limitations.