What does IH-INT-003 flag?
Reports a file that was in the baseline and is now gone.
- A baseline path that no longer exists.
- Reported by verify only.
Why it matters
Removal is usually harmless, but it can also mean a skill was replaced or that evidence was cleaned up.
Examples
Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.
Can IH-INT-003 fire on a safe skill?
- Skills or files you removed yourself.
How do I fix an IH-INT-003 finding?
- Confirm the deletion was intentional.
CLI guidance: A missing file can also mean the skill was replaced.
How do I tune or allow IH-INT-003?
Run ironheights baseline update after you accept the removal.
Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-INT-003.
What can IH-INT-003 miss?
- Why the file was removed.
No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.
Related rules
ironheights rules list.