IH-CFG-005highOpenClaw config

Plaintext secret in OpenClaw config

A token, password, secret, or API key is a literal string in the config file. ${ENV} references and SecretRef objects (source env, file, exec, or store) are not literals. Placeholder literals are reported as IH-CFG-002 instead. Evidence is the key path plus <redacted>. Native config.secrets.gateway_password_in_config and config.secrets.hooks_token_in_config are the overlapping checks; other secret keys in the file are reported here too.

What does IH-CFG-005 flag?

Flags a token, password, secret or API key written as a literal string in the OpenClaw config file.

  • A literal value under a token, password, secret or API key setting.
  • Not reported: ${ENV} references and SecretRef objects (source env, file, exec or store).
  • Placeholder values are reported as IH-CFG-002 instead.

Why it matters

A literal secret in a config file spreads into backups, repositories and screenshots. Whoever reads the file can use it.

Examples

Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.

Literal secret
Flagged
hooks.token: "<literal-value>"
Environment reference
Not flagged
gateway.auth.token: "${OPENCLAW_GATEWAY_TOKEN}"
SecretRef object
Not flagged
gateway.auth.token: { source: "env", id: "OPENCLAW_GATEWAY_TOKEN" }

Can IH-CFG-005 fire on a safe skill?

  • A non-secret value stored under a key that has secret in its name.

How do I fix an IH-CFG-005 finding?

  • Remove the literal and use a SecretRef or an environment variable.
  • Rotate the value if the file was copied or committed.

CLI guidance: Remove the literal. Use a SecretRef or an environment variable. This command does not print the value.

How do I tune or allow IH-CFG-005?

Fix the file rather than silence the rule. The command does not print values: evidence is the key path plus a redaction marker.

Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-CFG-005.

What can IH-CFG-005 miss?

  • Secrets stored in other files.
  • A secret that has already leaked. Rotating it is a separate step.

No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.

Scores and thresholds shown are the CLI defaults; your config can change them. List every rule from the terminal with ironheights rules list.

All 35 rules