Using IronheightsUpdated

Can I run Ironheights alongside other security scanners?

Short answer

Yes. Ironheights reads files and never runs another tool, and its guard stays in monitor mode unless you change it, so it can sit beside other scanners. Run ironheights coexist to list the other security tools it can see and where they overlap, with a fix for each. The check is heuristic, and a clean report is not proof.

Where two security tools can collide

A scanner that only reads files rarely bothers another one. Trouble starts when both tools act on the same thing. These are the cases worth checking:

  • Two guards on one tool call. OpenClaw runs before_tool_call handlers from the highest priority down, and a block ends the chain. If two plugins can block, the higher one decides, and the other never sees that call, so its log is missing it.
  • Two owners of the same files. A tool that restores or removes files, and a baseline that expects them to stay put, can disagree about which copy is right.
  • A shared folder. Two tools writing logs or state into one directory can overwrite each other.
  • Double network use. Two scanners that both contact ClawHub, or a vendor cloud, send the same skill twice.
  • Competing instructions. Several skills that tell the agent to vet every install can each give a different answer, and the model picks one.

Check with coexist

npx ironheights coexist
npx ironheights coexist --json --fail-on medium

The command reads your OpenClaw config, plugin manifests, skill and hook folders, known state folders, PATH and, if you point it at a project, CI and pre-commit files. It lists each other security tool it recognises with the file that showed it, then reports overlaps as IH-COEX-001 to IH-COEX-011, each with a severity and a fix. It makes no network call, runs none of the tools it finds, and writes nothing.

What Ironheights does to stay out of the way

  • The guard returns only a block or an allow. It never rewrites a tool call and never asks for approval, so it cannot collide with another plugin's rewrite or prompt.
  • In monitor mode, the default, it never blocks. If another guard already enforces, leave Ironheights in monitor mode and let one tool own blocking.
  • Its priority is 80 and can be changed with the plugin's priority setting.
  • All its files live under ~/.ironheights, apart from other tools' folders.
  • When scan meets a skill named like a known security tool, it adds a note and lowers confidence on its Markdown injection and credential findings by one step. It never allowlists the skill, because anyone can copy a name, and the verdict does not change.

Limits

Detection is heuristic. It reads files and names, so a tool it does not list, a renamed tool, or a plugin that is only loaded in a running Gateway can be missed. A name match means something with that name is present, not that it is the real tool. A report with no findings is not proof that your tools will not interfere. Hook order follows OpenClaw's plugin documentation as checked on 11 October 2026, and a later OpenClaw release can change it. See the limitations page for what Ironheights cannot catch.

Sources

  • Install Ironheights with npx ironheights or npm install -g ironheights. Needs Node.js 20+. Official sources, a first scan, a baseline, and the advisory skill.
  • The Ironheights CLI has no telemetry and a scan makes no network call. Commands you choose, such as fetch, use the network. What the website records, with consent.
  • Scan an OpenClaw skill before install with npx ironheights scan, or paste SKILL.md into the free browser scanner. What the verdicts mean, and what a scan misses.

All answers

Check the next skill before your agent reads it

Ironheights is a free, open-source, local-first scanner and integrity monitor for OpenClaw skills. It reports what its rules match; it cannot prove a skill is safe.