IH-CFG-003criticalOpenClaw config

DM policy is open

A channel dmPolicy (or dm.policy) is open, so anyone can DM the agent. This matches the native check channels.<channel>.dm.open. Mutable allowFrom entries and name matching are not reimplemented.

What does IH-CFG-003 flag?

Flags a messaging channel whose direct-message policy is open, so anyone who finds the bot can message the agent.

  • A channel dmPolicy, or dm.policy, set to open.

Why it matters

An agent that accepts messages from strangers can be steered by them, including into using its tools.

Examples

Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.

Open DMs
Flagged
channels.telegram.dmPolicy: "open"
Pairing
Not flagged
channels.telegram.dmPolicy: "pairing"
Allowlist
Not flagged
channels.telegram.dmPolicy: "allowlist"

Can IH-CFG-003 fire on a safe skill?

  • A public demo bot with no tools and no private data.

How do I fix an IH-CFG-003 finding?

  • Set dmPolicy to pairing or allowlist.
  • Run openclaw security audit before exposing a bot.

CLI guidance: Open is a last resort in the OpenClaw docs.

How do I tune or allow IH-CFG-003?

Use ruleOverrides in your Ironheights config only for a bot you have reviewed and that has no sensitive tools.

Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-CFG-003.

What can IH-CFG-003 miss?

  • Mutable allowFrom lists and name matching; the rule reads only the policy value.
  • Channels configured outside the file.

No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.

Scores and thresholds shown are the CLI defaults; your config can change them. List every rule from the terminal with ironheights rules list.

All 35 rules