IH-ADV-001criticalAdvisory feed

Advisory feed match

The cached signed advisory feed lists this skill name, a file content hash, or an indicator host. The match is reported only when a local cache is present. Scan does not contact the network to refresh the feed.

What does IH-ADV-001 flag?

Reports a skill that matches the signed advisory feed cached on your machine: the skill name, a file content hash, or an indicator host listed as bad.

  • The skill folder name or the name in SKILL.md is listed in the cached feed, for the listed versions (an empty version list means every version).
  • A file in the skill has a sha256 that is listed in the feed.
  • The skill text contains an indicator host from the feed, matched as a whole host.
  • Reported only when a verified feed cache exists on this machine. With no cache the rule reports nothing, and scan never downloads the feed.

Why it matters

Pattern rules find risky text. An advisory finds a skill someone has already reported, even when its text looks harmless. This is the only rule that compares a skill with a list of known-bad skills.

Severity: Critical, so one match is a block. The status shown comes from the source that reported the skill; Ironheights does not re-rate it.

Examples

Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.

Name listed in the feed
Flagged
skill slug <skill-name> is listed in the advisory feed
Content hash listed
Flagged
file sha256 matches an advisory content hash
No cache present
Not flagged
no advisory cache is present
Version not listed
Not flagged
a version-specific advisory does not list this version

Can IH-ADV-001 fire on a safe skill?

  • A skill reused under a name that appears in the feed. Read the linked sources before you decide.
  • A legitimate skill that quotes a listed indicator host in a warning.

How do I fix an IH-ADV-001 finding?

  • Do not install or enable the skill.
  • Read the source links in the finding.
  • Quarantine the copy if it is already on disk: the ironheights quarantine command with the skill name.

CLI guidance: Do not install or enable this skill. Read the source links, then quarantine the copy if it is already on disk.

How do I tune or allow IH-ADV-001?

You can lower or disable the rule for one project with ruleOverrides. That hides a signed-feed match, so do it only after you have read the sources.

Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-ADV-001.

What can IH-ADV-001 miss?

  • Anything not in the feed. A skill missing from the feed is not evidence that it is harmless.
  • A feed that was never downloaded. Run ironheights advisories update first.
  • A feed that is out of date. The feed lists only what its maintainers have published.

No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.

Scores and thresholds shown are the CLI defaults; your config can change them. List every rule from the terminal with ironheights rules list.

All 35 rules