What does IH-CFG-002 flag?
Flags a Gateway whose authentication is off, trusts a proxy, is missing on a non-loopback bind, or uses an empty or placeholder token or password.
- gateway.auth.mode is none or trusted-proxy.
- A non-loopback bind with no gateway.auth.
- A token or password in the file that is empty or a known placeholder.
- Not reported: a loopback bind with auth omitted, because OpenClaw's default is authenticated and the token may live in an environment variable the command does not read.
Why it matters
Authentication is what stands between a reachable Gateway and anyone who can reach it. A copied placeholder token is as good as no token.
Examples
Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.
Can IH-CFG-002 fire on a safe skill?
- trusted-proxy is flagged because the proxy becomes the security boundary. If you run one on purpose, the finding is a reminder, not a fault.
How do I fix an IH-CFG-002 finding?
- Set gateway.auth.mode to token or password.
- Keep the secret in the environment or a SecretRef.
- For trusted-proxy, run openclaw security audit and keep gateway.trustedProxies tight.
CLI guidance: Set gateway.auth.mode to token or password and store the secret in the environment or a SecretRef, not as a placeholder. This command never prints the secret.
How do I tune or allow IH-CFG-002?
Tune with ruleOverrides in your Ironheights config only for a setup you have reviewed. The command never prints the secret; evidence is the key path plus a redaction marker.
Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-CFG-002.
What can IH-CFG-002 miss?
- Token strength or length.
- Secrets supplied only through the environment.
- Proxy addresses and headers; the native audit covers those.
No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.
Related rules
ironheights rules list.