What does IH-INJ-003 flag?
Flags instructions to turn off approvals, edit the agent's own configuration or other skills, or add the skill to startup.
- disable, skip, bypass or turn off near confirmation(s) or approval(s).
- edit, modify, overwrite, rewrite, patch or change near openclaw.json, AGENTS.md, SOUL.md, MEMORY.md, agent config, another skill or other skills.
- add itself or add this skill to startup or login items.
Why it matters
Approvals and agent files are the user's trust boundary. A skill that changes them can keep influencing the agent after it is removed.
Examples
Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.
Can IH-INJ-003 fire on a safe skill?
- Setup assistants whose stated job is to manage agent configuration.
- Docs that describe how approvals work.
How do I fix an IH-INJ-003 finding?
- Refuse the change.
- Agent configuration and other skills should be edited only by the user.
CLI guidance: Agent config and other skills should be edited only by the user.
How do I tune or allow IH-INJ-003?
If a skill's declared purpose is managing agent files, review it by hand and lower the rule's severity for that project with ruleOverrides.
Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-INJ-003.
What can IH-INJ-003 miss?
- Paraphrases and other languages.
- Changes made through tool calls without this wording.
- Memory poisoning phrased as “remember that …”. Use IH-INT-004 to notice changed agent files afterwards.
No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.
Related rules
ironheights rules list.