IH-INT-003mediumIntegrity

Skill file removed

A file that was in the baseline is gone.

What does IH-INT-003 flag?

Reports a file that was in the baseline and is now gone.

  • A baseline path that no longer exists.
  • Reported by verify only.

Why it matters

Removal is usually harmless, but it can also mean a skill was replaced or that evidence was cleaned up.

Examples

Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.

Removed file
Flagged
README.md removed
All present
Not flagged
every baseline path still exists

Can IH-INT-003 fire on a safe skill?

  • Skills or files you removed yourself.

How do I fix an IH-INT-003 finding?

  • Confirm the deletion was intentional.

CLI guidance: A missing file can also mean the skill was replaced.

How do I tune or allow IH-INT-003?

Run ironheights baseline update after you accept the removal.

ironheights verify
ironheights baseline update

Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-INT-003.

What can IH-INT-003 miss?

  • Why the file was removed.

No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.

Scores and thresholds shown are the CLI defaults; your config can change them. List every rule from the terminal with ironheights rules list.

All 35 rules