What does IH-CFG-005 flag?
Flags a token, password, secret or API key written as a literal string in the OpenClaw config file.
- A literal value under a token, password, secret or API key setting.
- Not reported: ${ENV} references and SecretRef objects (source env, file, exec or store).
- Placeholder values are reported as IH-CFG-002 instead.
Why it matters
A literal secret in a config file spreads into backups, repositories and screenshots. Whoever reads the file can use it.
Examples
Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.
Can IH-CFG-005 fire on a safe skill?
- A non-secret value stored under a key that has secret in its name.
How do I fix an IH-CFG-005 finding?
- Remove the literal and use a SecretRef or an environment variable.
- Rotate the value if the file was copied or committed.
CLI guidance: Remove the literal. Use a SecretRef or an environment variable. This command does not print the value.
How do I tune or allow IH-CFG-005?
Fix the file rather than silence the rule. The command does not print values: evidence is the key path plus a redaction marker.
Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-CFG-005.
What can IH-CFG-005 miss?
- Secrets stored in other files.
- A secret that has already leaked. Rotating it is a separate step.
No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.
Related rules
ironheights rules list.