How do I check if a skill changed after install?
Why you would want to know
The skill you vetted is not always the skill you run. Skills update, agents write to their own memory, and a malicious skill can edit other skills or files such as AGENTS.md. None of this is visible in a normal OpenClaw setup.
What gets recorded
npx ironheights baseline create writes ~/.ironheights/baseline.json, readable only by your user. It covers your OpenClaw skill directories and, by default, these agent files under the OpenClaw state directory: AGENTS.md, SOUL.md, IDENTITY.md, USER.md, TOOLS.md, BOOTSTRAP.md, MEMORY.md, the memory/ directory, openclaw.json, credentials/ and .env. For each file it stores a sha256 hash, size and permission mode, plus a tree hash. Change the list with skillDirs and agentFiles in the config.
What verify reports
npx ironheights verify prints how many files were added, modified, removed or changed mode, then one finding per change:
- IH-INT-001: a skill file no longer matches the baseline (high).
- IH-INT-002: a new file or skill directory appeared (medium).
- IH-INT-003: a file in the baseline is gone (medium).
- IH-INT-004: a watched agent file changed (high).
It ends with a verdict and an exit code (0, 1 or 2), so a script you control can act on it.
How often to run it
Run verify after every skill install or update, and on a schedule that fits the agent's access: daily is reasonable for an agent that can reach email, code or money. Run it from your own shell or a job the agent does not start, and let the exit code decide what happens next. Start with npx ironheights doctor to see which OpenClaw directories it found.
What to do with a change
Open each reported file and make sure you recognize the change. Memory files change in normal use, so read what was added rather than ignoring them. If a skill changed, scan it again with npx ironheights scan before you accept the change with npx ironheights baseline update. If something is wrong, ironheights quarantine <skill> moves the skill out of the agent's reach without deleting it. The full routine is in Baselines for agent files.
Limits
A baseline shows that a file changed, not whether the change is harmful. It does not see a skill that changes behavior by fetching remote instructions, and it is not real-time. Anyone who can write to your home directory can also rewrite an unsigned baseline. Since 0.2.0 you can sign it with baseline create --key <file> and check it with verify --key <file>; the signature only helps while the key stays private, so keep a copy off the machine. See signed baselines. Run verify yourself, not through the agent. See the limitations page.
Sources
- Ironheights README: Integrity, GitHub.
- Ironheights ideas outside the MVP, GitHub.