What does IH-INT-001 flag?
After you save a baseline, ironheights verify reports any file in an installed skill whose contents changed.
- A file under a watched skill folder whose content no longer matches the saved baseline.
- Reported by verify only, never by scan.
Why it matters
A skill can change after you reviewed it: an update, a compromised publisher, or an auto-updater. A changed file is the signal to read it again.
Examples
Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.
Can IH-INT-001 fire on a safe skill?
- Updates you made or accepted yourself.
How do I fix an IH-INT-001 finding?
- Review the diff.
- Restore the file, or run ironheights baseline update only after you accept the change.
CLI guidance: Restore the file or create a new baseline only after you accept the change.
How do I tune or allow IH-INT-001?
Accepted changes are recorded with ironheights baseline update. Choose which folders are watched with skillDirs.
Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-INT-001.
What can IH-INT-001 miss?
- Changes made before the baseline was created.
- Behaviour that changes through remote content without any file changing.
- Folders that are not in skillDirs.
No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.
Related rules
ironheights rules list.