Can I run Ironheights alongside other security scanners?
Where two security tools can collide
A scanner that only reads files rarely bothers another one. Trouble starts when both tools act on the same thing. These are the cases worth checking:
- Two guards on one tool call. OpenClaw runs
before_tool_callhandlers from the highest priority down, and a block ends the chain. If two plugins can block, the higher one decides, and the other never sees that call, so its log is missing it. - Two owners of the same files. A tool that restores or removes files, and a baseline that expects them to stay put, can disagree about which copy is right.
- A shared folder. Two tools writing logs or state into one directory can overwrite each other.
- Double network use. Two scanners that both contact ClawHub, or a vendor cloud, send the same skill twice.
- Competing instructions. Several skills that tell the agent to vet every install can each give a different answer, and the model picks one.
Check with coexist
npx ironheights coexist
npx ironheights coexist --json --fail-on medium
The command reads your OpenClaw config, plugin manifests, skill and hook folders, known state folders, PATH and, if you point it at a project, CI and pre-commit files. It lists each other security tool it recognises with the file that showed it, then reports overlaps as IH-COEX-001 to IH-COEX-011, each with a severity and a fix. It makes no network call, runs none of the tools it finds, and writes nothing.
What Ironheights does to stay out of the way
- The guard returns only a block or an allow. It never rewrites a tool call and never asks for approval, so it cannot collide with another plugin's rewrite or prompt.
- In monitor mode, the default, it never blocks. If another guard already enforces, leave Ironheights in monitor mode and let one tool own blocking.
- Its priority is 80 and can be changed with the plugin's
prioritysetting. - All its files live under
~/.ironheights, apart from other tools' folders. - When
scanmeets a skill named like a known security tool, it adds a note and lowers confidence on its Markdown injection and credential findings by one step. It never allowlists the skill, because anyone can copy a name, and the verdict does not change.
Limits
Detection is heuristic. It reads files and names, so a tool it does not list, a renamed tool, or a plugin that is only loaded in a running Gateway can be missed. A name match means something with that name is present, not that it is the real tool. A report with no findings is not proof that your tools will not interfere. Hook order follows OpenClaw's plugin documentation as checked on 11 October 2026, and a later OpenClaw release can change it. See the limitations page for what Ironheights cannot catch.
Sources
- Ironheights coexistence design and limits, GitHub.
- Ironheights guard plugin and threat model, GitHub.
- OpenClaw plugin hooks, OpenClaw documentation.
- Ironheights changelog, GitHub.