IH-CFG-009mediumOpenClaw config

Sandbox disabled while tools can act

Sandbox mode is off, or sandbox.docker is set while mode is off, and the file also enables host exec, elevated tools, or an open room. A personal agent with sandbox off and tools.exec.security deny is a documented OpenClaw pattern and stays quiet. Native sandbox.docker_config_mode_off and the security.exposure.open_groups_with_runtime_or_fs checks overlap the noisy cases. Docker bind mounts, seccomp, and AppArmor are not reimplemented.

What does IH-CFG-009 flag?

Flags a config where the sandbox is off while the agent can also run host commands, use elevated tools, or answer an open room.

  • Sandbox mode off, or sandbox.docker set while the mode is off, together with host exec, elevated tools, or an open room.
  • Not reported: a personal agent with sandbox off and exec security set to deny, which OpenClaw documents as a valid pattern.

Why it matters

A sandbox limits what a tricked agent can touch. With it off, the same trick reaches your real files and accounts.

Severity: Medium, and high when the file also enables host exec, elevated tools or an open room.

Examples

Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.

Sandbox off with full exec
Flagged
agents.defaults.sandbox.mode: "off" with tools.exec.security: "full"
Docker set but sandbox off
Flagged
sandbox.docker is set and sandbox.mode: "off"
Sandbox on
Not flagged
agents.defaults.sandbox.mode: "all"

Can IH-CFG-009 fire on a safe skill?

  • A machine you accept as fully exposed to the agent.

How do I fix an IH-CFG-009 finding?

  • Set agents.defaults.sandbox.mode to all for any agent that can exec or that strangers can message.
  • Otherwise set tools.exec.security to deny.

CLI guidance: Run openclaw security audit for sandbox mount checks.

How do I tune or allow IH-CFG-009?

Use ruleOverrides in your Ironheights config only for a setup you have reviewed.

{
  "ruleOverrides": {
    "IH-CFG-009": {
      "severity": "low"
    }
  }
}

Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-CFG-009.

What can IH-CFG-009 miss?

  • Docker bind mounts, seccomp and AppArmor profiles; openclaw security audit checks sandbox mounts.

No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.

Scores and thresholds shown are the CLI defaults; your config can change them. List every rule from the terminal with ironheights rules list.

All 35 rules