IH-INT-002mediumIntegrity

New skill file

A file or skill directory appeared after the baseline was created.

What does IH-INT-002 flag?

Reports a file or a whole skill folder that appeared after the baseline was created.

  • A path under a watched folder that is not in the baseline.
  • Reported by verify only.

Why it matters

New files are where a dropped payload or an installed skill you did not expect would show up.

Examples

Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.

New file
Flagged
scripts/install.sh added
No new paths
Not flagged
no new paths since baseline

Can IH-INT-002 fire on a safe skill?

  • Skills you installed on purpose since the last baseline.

How do I fix an IH-INT-002 finding?

  • Inspect the new file before trusting the skill.
  • Update the baseline once you accept it.

CLI guidance: Inspect the new file before trusting the skill, then update the baseline if you accept it.

How do I tune or allow IH-INT-002?

Run ironheights baseline update after you accept the new files.

ironheights verify
ironheights baseline update

Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-INT-002.

What can IH-INT-002 miss?

  • Files outside the watched folders.
  • Whether the new file is harmful; scan it to find out.

No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.

Scores and thresholds shown are the CLI defaults; your config can change them. List every rule from the terminal with ironheights rules list.

All 35 rules