What does IH-CFG-006 flag?
Checks the permissions of openclaw.json on macOS and Linux and flags a file that other users can write or read, or a symlinked config.
- Mode bits that make the file group-writable, world-writable, world-readable or group-readable.
- A symlinked openclaw.json, reported at medium severity because OpenClaw documents it as unsupported.
- Windows is not checked: ACLs are not Unix mode bits, so this rule reports nothing there and does not run icacls.
Why it matters
The config holds secrets and security settings. If others can write it they can change how the agent behaves, and if they can read it they can read what is in it.
Severity: Critical for group or world write and for world read; medium for group read or a symlink.
Examples
Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.
Can IH-CFG-006 fire on a safe skill?
- A shared lab machine where the access is intended.
How do I fix an IH-CFG-006 finding?
- On macOS or Linux, chmod 600 the config file and do not symlink it.
- On Windows, run openclaw security audit so ACLs can be reviewed.
CLI guidance: On POSIX, chmod 600 the config file and do not symlink it. On Windows, run openclaw security audit so ACL resets can be reviewed. This command never changes permissions.
How do I tune or allow IH-CFG-006?
The command never changes permissions. Fix the mode, then run it again.
Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-CFG-006.
What can IH-CFG-006 miss?
- Windows access control lists.
- Who actually has an account on the machine.
No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.
Related rules
ironheights rules list.