IH-LLM-001infoModel review

Advisory model review

An optional language-model review added a note. This is not a pattern rule and it does not scan files by itself. The model sees redacted skill text and the deterministic findings, and it can be wrong. The note never changes the verdict or the exit code. It appears only after `scan --llm` or `review`, and only when the model output matched the review schema.

What does IH-LLM-001 flag?

Shows a note from the optional language-model review. It is not a pattern rule and it never changes the verdict.

  • Appears only after scan --llm or review, and only when the model's answer matched the expected format.
  • The model sees skill text that is capped, stripped of control characters and scrubbed for common secrets. The scrub can miss a secret.
  • Not produced by scan --stdin or scan --text, and not produced unless you ask.

Why it matters

A model can sometimes point at something odd that fixed rules do not describe. The note is a prompt to read the skill again, not a finding you must act on.

Severity: Info, zero points. A model note cannot raise or lower the verdict, the grade or the exit code, and a block stays a block.

Examples

Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.

Model note
Flagged
Model note: the skill tells the agent to <download-something> before reading it.
Scan without --llm
Not flagged
A skill file on its own, with scan --llm not set.

Can IH-LLM-001 fire on a safe skill?

  • Models can be wrong. A note can describe a risk that is not there.

How do I fix an IH-LLM-001 finding?

  • Read the skill yourself and decide.
  • Do not treat an absent note as a clean result.

CLI guidance: This note is advisory and can be wrong. It does not change the deterministic verdict. Confirm it yourself before you act on it.

How do I tune or allow IH-LLM-001?

The review is off unless you pass --llm or run review. The default server is a loopback Ollama-compatible endpoint; a server on another host needs --llm-consent and an API key, and --dry-run prints the exact request without sending it.

Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-LLM-001.

What can IH-LLM-001 miss?

  • Anything the model misses. Its silence is not proof of safety.
  • Anything it was not shown. Skill text is capped before it is sent.

No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.

Scores and thresholds shown are the CLI defaults; your config can change them. List every rule from the terminal with ironheights rules list.

All 35 rules