Security and disclosure
A security tool needs deep access to your machine, so it has to earn trust. Here is how we handle reports, releases, and research.
Report a vulnerability
Open a private security advisory on GitHub. Include the rule id if one exists, a minimal skill that triggers the issue, and the output of ironheights --version. Please give us time to ship a fix before writing about it in public. There is no bug bounty.
Do not send real secrets or live malware. A synthetic snippet that matches the pattern is enough.
Supported versions
| Version | Supported |
|---|---|
| 0.1.x | Yes |
Official sources
Ironheights is distributed only through:
- The ironheights package on npm, published from CI with a provenance signature
- GitHub releases of Frank-Masciopinto/ironheights
- Links on ironheights.dev
Copycat “antivirus” or “security” skills are a known way to spread malware. If you find one using our name, report it as a GitHub issue.
Malicious skill research
When we write up a malicious skill, we describe the technique and indicators without publishing a runnable payload, and we report live samples to the marketplace before we publish. Keep real samples on an isolated machine, on a read-only mount, and never run them.
No phone-home
Ironheights sends no telemetry, and a scan makes no network call. Only the commands you run on purpose (fetch, safe-install, advisories update, and the optional model review) use the network, and the CLI prints each URL first. A report you file on GitHub is the only disclosure channel. Read the SECURITY.md in the repository.