What does IH-ADV-001 flag?
Reports a skill that matches the signed advisory feed cached on your machine: the skill name, a file content hash, or an indicator host listed as bad.
- The skill folder name or the name in SKILL.md is listed in the cached feed, for the listed versions (an empty version list means every version).
- A file in the skill has a sha256 that is listed in the feed.
- The skill text contains an indicator host from the feed, matched as a whole host.
- Reported only when a verified feed cache exists on this machine. With no cache the rule reports nothing, and scan never downloads the feed.
Why it matters
Pattern rules find risky text. An advisory finds a skill someone has already reported, even when its text looks harmless. This is the only rule that compares a skill with a list of known-bad skills.
Severity: Critical, so one match is a block. The status shown comes from the source that reported the skill; Ironheights does not re-rate it.
Examples
Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.
Can IH-ADV-001 fire on a safe skill?
- A skill reused under a name that appears in the feed. Read the linked sources before you decide.
- A legitimate skill that quotes a listed indicator host in a warning.
How do I fix an IH-ADV-001 finding?
- Do not install or enable the skill.
- Read the source links in the finding.
- Quarantine the copy if it is already on disk: the ironheights quarantine command with the skill name.
CLI guidance: Do not install or enable this skill. Read the source links, then quarantine the copy if it is already on disk.
How do I tune or allow IH-ADV-001?
You can lower or disable the rule for one project with ruleOverrides. That hides a signed-feed match, so do it only after you have read the sources.
Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-ADV-001.
What can IH-ADV-001 miss?
- Anything not in the feed. A skill missing from the feed is not evidence that it is harmless.
- A feed that was never downloaded. Run ironheights advisories update first.
- A feed that is out of date. The feed lists only what its maintainers have published.
No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.
Related rules
ironheights rules list.