IH-CFG-008mediumOpenClaw config

Skills load from an extra directory

skills.load.extraDirs or skills.load.allowSymlinkTargets is set. Extra directories are the lowest-precedence skill roots and are trusted by the operator. OpenClaw tells you to keep allowSymlinkTargets narrow. A home directory, a filesystem root, or a path that contains .. is critical. Other extra directories are medium. The native audit does not have this check; it does have skills.workspace.symlink_escape, which walks the workspace and is not repeated here.

What does IH-CFG-008 flag?

Flags skills.load.extraDirs and skills.load.allowSymlinkTargets, which make OpenClaw load skills from folders outside the normal skill roots.

  • skills.load.extraDirs or skills.load.allowSymlinkTargets is set.
  • A home directory, a filesystem root, a drive root, or a path containing .. is critical. Other extra directories are medium.

Why it matters

Every extra directory is trusted as a source of instructions. A directory that points at your home folder or the filesystem root trusts everything inside it.

Severity: Medium, and critical for a home directory, a filesystem root, a drive root or a path containing ...

Examples

Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.

Untrusted folder
Flagged
skills.load.extraDirs: ["~/Dev/untrusted/skills"]
Home directory
Flagged
skills.load.extraDirs: ["~"]
Not set
Not flagged
skills.load.extraDirs omitted

Can IH-CFG-008 fire on a safe skill?

  • An extra folder you maintain and review yourself.

How do I fix an IH-CFG-008 finding?

  • Remove extra directories you do not trust.
  • Never point extraDirs or allowSymlinkTargets at ~, / or a drive root.
  • Scan those directories with ironheights scan before OpenClaw loads them.

CLI guidance: Do not point extraDirs or allowSymlinkTargets at ~, /, or a drive root. Scan those directories with ironheights scan before loading them.

How do I tune or allow IH-CFG-008?

A folder you own and have scanned is a reasonable exception. Record it with ruleOverrides in your Ironheights config.

{
  "ruleOverrides": {
    "IH-CFG-008": {
      "severity": "low"
    }
  }
}

Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-CFG-008.

What can IH-CFG-008 miss?

  • What is inside the extra directories. Use ironheights scan on them.
  • Symlinks inside the workspace; openclaw security audit has a separate check for those.

No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.

Scores and thresholds shown are the CLI defaults; your config can change them. List every rule from the terminal with ironheights rules list.

All 35 rules