What does IH-EXEC-001 flag?
Flags a line that downloads text from the internet and hands it straight to a shell or language runtime, so whatever the server sends back runs at once.
- A download tool (curl, wget, iwr, Invoke-WebRequest or Invoke-RestMethod) on the same line as a pipe into sh, bash, zsh, python, node, PowerShell, pwsh or Invoke-Expression, with or without sudo in front of the interpreter.
- A shell or runtime started on a command substitution that calls curl or wget.
- A shell reading from a process substitution that starts with curl or wget.
- base64 decoding (-d or --decode, any case) piped into a shell or runtime on the same line.
Why it matters
Nobody reviews the code that runs. The server can change it at any time, and it runs with the permissions of whoever pastes it, or of the agent. The ClawHub malware waves reported in early 2026 used this exact step, often hidden behind base64 so the line looks like an installer banner.
Examples
Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.
Can IH-EXEC-001 fire on a safe skill?
- Vendor install one-liners for real tools match too. The rule cannot tell a trusted vendor from an attacker; that judgment stays with you.
- Documentation that quotes the pattern as a warning matches, because matching is per line and does not read intent.
How do I fix an IH-EXEC-001 finding?
- Download the script to a file, read it, pin a version or checksum, and run the local copy.
- Better still, install the tool from its language registry or the operating-system package manager.
CLI guidance: Download to a file, review it, and run a pinned local copy instead of piping a URL into a shell.
How do I tune or allow IH-EXEC-001?
If you have read the installer and accept it, exclude that one file with ignoreGlobs rather than turning off a critical rule for the whole project. Keep the change in the project's own ironheights.config.json rather than your global one.
Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-EXEC-001.
What can IH-EXEC-001 miss?
- Commands split across lines or variables, or assembled at run time.
- A payload that lives on a paste site or lookalike website the skill only links to. The link alone raises IH-NET-001 at most.
- Files larger than the scan size limit (1 MiB by default). They are skipped without being read, and the verdict can still read no findings.
No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.
In the tracker
Publicly reported cases where a synthetic copy of the reported pattern raises IH-EXEC-001. Coverage is about the pattern, not a scan of the original files.
- security-check (security-audit) and nanopdfCommunity report on GitHub (Jeff Schell) · 5 February 2026Covered
- More skills by zaycv: linkedin-job-application, autoupdater, deepresearchCommunity reports on GitHub (adrianwedd, hendrysadrak, rafadiasbsb) · 4 February 2026Covered
- Fake “ClawHub CLI” skills by zaycv (clawhub, clawdhub1)Snyk; GitHub issue by lycfyi · 2 February 2026Partly covered
- WhatsApp and security-check lookalikes by moonshine-100rzeCommunity reports on GitHub (diegofornalha, biagiom) · 2 February 2026Covered
- “AuthTool” trading skillsKoi Security · 1 February 2026Partly covered
- ClawHavocKoi Security · 1 February 2026Partly covered
- Malicious ClawHub skills targeting crypto and trading usersOpenSourceMalware (Paul McCarty) · 1 February 2026Partly covered
- Polymarket skills with a hidden reverse shellKoi Security; community report on GitHub (NCC-David) · 1 February 2026Covered
Related rules
ironheights rules list.