IH-CFG-004highOpenClaw config

Group policy is open

A channel groupPolicy is open, so any member of a group can talk to the agent. Severity rises to critical when the same config also enables host exec, elevated tools, or an open DM policy. Native security.exposure.open_groups_with_elevated and security.exposure.open_channels_with_exec cover the live combination; this rule only reads the file.

What does IH-CFG-004 flag?

Flags a group or room policy that is open, so any member of a group can talk to the agent.

  • A channel groupPolicy set to open.
  • Raised to critical when the same file also enables host exec, elevated tools, or an open DM policy.

Why it matters

Everyone in an open room is a possible instruction source. The risk grows when the same config lets the agent run commands.

Severity: High, and critical when the same config also opens DMs or enables host exec or elevated tools.

Examples

Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.

Open group
Flagged
channels.telegram.groupPolicy: "open"
Allowlist
Not flagged
channels.telegram.groupPolicy: "allowlist"
Disabled
Not flagged
channels.telegram.groupPolicy: "disabled"

Can IH-CFG-004 fire on a safe skill?

  • A small room where every member is trusted.

How do I fix an IH-CFG-004 finding?

  • Set groupPolicy to allowlist and require mentions.
  • Do not combine an open room with exec security full or elevated tools.

CLI guidance: Do not combine an open room with tools.exec.security full or tools.elevated.

How do I tune or allow IH-CFG-004?

Use ruleOverrides in your Ironheights config only after you have reviewed who is in the room.

{
  "ruleOverrides": {
    "IH-CFG-004": {
      "severity": "low"
    }
  }
}

Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-CFG-004.

What can IH-CFG-004 miss?

  • Who is actually in a group.
  • The live combination of open rooms and tools; openclaw security audit checks that.

No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.

Scores and thresholds shown are the CLI defaults; your config can change them. List every rule from the terminal with ironheights rules list.

All 35 rules