IH-BIN-001highBinaries

Bundled executable or archive

Executables and archives shipped inside a skill can hide an installer. Archives are flagged and never extracted.

What does IH-BIN-001 flag?

Flags executables and archives inside the skill folder, recognised by file extension or by the file's first bytes. Archives are never extracted.

  • Executables: .exe, .dll, .msi, .dmg, .pkg, .so, .dylib and .apk, or an executable file header.
  • Archives: .zip, .tar, .gz, .tgz, .7z, .rar, .bz2, .xz and .jar, or an archive file header.

Why it matters

A skill is instructions and small scripts. A bundled executable or archive can hide an installer, and one reported ClawHub skill shipped a Windows executable that antivirus engines flagged.

Severity: Executables are high (40 points). Archives are reported as medium (15 points), and password-protected zip files are called out in the message.

Examples

Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.

Bundled executable
Flagged
skill/<name>.exe
Bundled archive
Flagged
skill/setup.zip
Text and images
Not flagged
notes.txt, diagram.png

Can IH-BIN-001 fire on a safe skill?

  • Skills that ship a legitimate native module or a .jar for a Java tool.
  • Sample data archives.

How do I fix an IH-BIN-001 finding?

  • Remove the binary.
  • Document a package-manager install instead of bundling an executable or archive.

How do I tune or allow IH-BIN-001?

If a binary is expected, verify where it came from, then exclude that path with ignoreGlobs.

{
  "ignoreGlobs": [
    "docs/known-example.md"
  ]
}

Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-BIN-001.

What can IH-BIN-001 miss?

  • Executables downloaded later from a release page or website the skill links to. Several campaigns hosted password-protected archives in GitHub releases.
  • What is inside an archive, because archives are not extracted.
  • Scripts, which are text and are covered by the other rules.

No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.

In the tracker

Publicly reported cases where a synthetic copy of the reported pattern raises IH-BIN-001. Coverage is about the pattern, not a scan of the original files.

Scores and thresholds shown are the CLI defaults; your config can change them. List every rule from the terminal with ironheights rules list.

All 35 rules