Does Ironheights send my data anywhere?
The command-line tool
The CLI reads skill files as data on your machine. The CLI has no telemetry, needs no account, and scan makes no network call. Four things use the network, each only when you run it, and each prints the URL first: fetch and safe-install download a ClawHub skill from clawhub.ai; advisories update downloads the signed advisory feed from ironheights.dev (the feed is not published yet, so there is nothing to download today); and scan --llm or review send skill text to a model server you choose. The default is a local Ollama on your own machine; any other host needs --llm-consent and a key. That model review is the only case where skill text can leave the machine, and the CLI prints the exact request first. The guard plugin writes a redacted log locally and sends nothing. Baselines and quarantined skills stay in ~/.ironheights (or wherever you point IRONHEIGHTS_HOME), and reports such as --json, --sarif or --md are written only where you ask. npx or npm downloads the package itself when you install it, as with any npm package.
Because the source is public, you do not have to take this on trust. You can read the code in the GitHub repository or watch the process's network activity while it scans.
The browser scanner
The browser scanner runs the CLI's content rules inside your browser. The in-browser scanner never sends your skill's content anywhere: not the text, not file names, not findings. With your consent, the site records only the scan verdict (no content), as one of three values. Share links put the skill in the URL fragment, which browsers do not send to the server.
The website
ironheights.dev uses Google Analytics 4 only after you choose "Accept analytics" in the consent banner. Until then, and if you choose "No thanks", the Google script never loads. With consent it records page views and a fixed list of events with enumerated values, never skill text, search terms or anything you type. Ad features and Google Signals are off. You can change your choice any time with "Cookie settings" in the footer. The privacy page has the details, including retention.
The advisory skill
The optional OpenClaw skill asks for no network access and no secrets. It tells the agent to run the local CLI. Your agent's model provider still sees whatever the agent sends it, as with any skill; that is outside Ironheights' control.
For teams and clients
If you need to show a client or a security reviewer where data goes, the short version is: skill files stay on the machine that scans them unless you choose a model review, and reports go only where you write them. In CI, the SARIF or JSON report is an artifact of your own pipeline; uploading it to a code-scanning service is your choice, not something Ironheights does. A security lead can confirm this by reading the source, by running a scan with outbound traffic blocked, or by checking that the result is the same with and without network access (commands that need the network, such as fetch, will fail when it is blocked). None of this requires an account or an API key.
Limits
Privacy is not the same as protection. A local, private scan is still a rules-only scan; see the limitations page.
Sources
- Ironheights README: Privacy, GitHub.
- Ironheights advisory skill, GitHub.