What does IH-EXEC-003 flag?
Flags code that runs strings as code: eval, the Function constructor, os.system, and subprocess or child-process calls with the shell turned on.
- eval( and new Function( in scripts and markdown.
- os.system( in Python.
- subprocess.run, Popen, call, check_output or check_call with shell=True.
- exec, execSync or spawn with shell: true in Node.js.
Why it matters
A string run as code can come from anywhere: a downloaded file, a model response, a chat message. That turns any injection into code execution and hides what will actually run from the person reviewing the skill. One reported ClawHub backdoor sat in an os.system call inside otherwise working code.
Examples
Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.
Can IH-EXEC-003 fire on a safe skill?
- Code that evaluates a constant, or build tooling that really needs a shell, still matches.
- The text eval( inside prose or a code comment matches, because the scan reads text.
How do I fix an IH-EXEC-003 finding?
- Call a fixed function instead of building code from strings.
- Pass an argument list with the shell disabled.
- Parse data with a parser such as JSON.parse instead of evaluating it.
CLI guidance: Call a fixed function or pass an argument array with shell disabled.
How do I tune or allow IH-EXEC-003?
If a script legitimately needs a shell, document why next to the call and lower the rule's severity for that project with ruleOverrides.
Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-EXEC-003.
What can IH-EXEC-003 miss?
- Aliased or indirect calls, such as assigning eval to another name or looking functions up by string.
- Execution through APIs that are not on the list, such as Python's exec() and compile().
- Harmful logic that never builds code from strings.
No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.
In the tracker
Publicly reported cases where a synthetic copy of the reported pattern raises IH-EXEC-003. Coverage is about the pattern, not a scan of the original files.
Related rules
ironheights rules list.