What does IH-CFG-009 flag?
Flags a config where the sandbox is off while the agent can also run host commands, use elevated tools, or answer an open room.
- Sandbox mode off, or sandbox.docker set while the mode is off, together with host exec, elevated tools, or an open room.
- Not reported: a personal agent with sandbox off and exec security set to deny, which OpenClaw documents as a valid pattern.
Why it matters
A sandbox limits what a tricked agent can touch. With it off, the same trick reaches your real files and accounts.
Severity: Medium, and high when the file also enables host exec, elevated tools or an open room.
Examples
Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.
Can IH-CFG-009 fire on a safe skill?
- A machine you accept as fully exposed to the agent.
How do I fix an IH-CFG-009 finding?
- Set agents.defaults.sandbox.mode to all for any agent that can exec or that strangers can message.
- Otherwise set tools.exec.security to deny.
CLI guidance: Run openclaw security audit for sandbox mount checks.
How do I tune or allow IH-CFG-009?
Use ruleOverrides in your Ironheights config only for a setup you have reviewed.
Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-CFG-009.
What can IH-CFG-009 miss?
- Docker bind mounts, seccomp and AppArmor profiles; openclaw security audit checks sandbox mounts.
No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.
Related rules
ironheights rules list.