Checking a skillUpdated

How do I check if a skill changed after install?

Short answer

Record a baseline right after you install and review the skill: npx ironheights baseline create stores a hash, size and mode for every watched file. Later, npx ironheights verify compares the current files with that record and lists every file that was added, modified, removed or had its permissions changed, with a rule id for each.

Why you would want to know

The skill you vetted is not always the skill you run. Skills update, agents write to their own memory, and a malicious skill can edit other skills or files such as AGENTS.md. None of this is visible in a normal OpenClaw setup.

What gets recorded

npx ironheights baseline create writes ~/.ironheights/baseline.json, readable only by your user. It covers your OpenClaw skill directories and, by default, these agent files under the OpenClaw state directory: AGENTS.md, SOUL.md, IDENTITY.md, USER.md, TOOLS.md, BOOTSTRAP.md, MEMORY.md, the memory/ directory, openclaw.json, credentials/ and .env. For each file it stores a sha256 hash, size and permission mode, plus a tree hash. Change the list with skillDirs and agentFiles in the config.

What verify reports

npx ironheights verify prints how many files were added, modified, removed or changed mode, then one finding per change:

  • IH-INT-001: a skill file no longer matches the baseline (high).
  • IH-INT-002: a new file or skill directory appeared (medium).
  • IH-INT-003: a file in the baseline is gone (medium).
  • IH-INT-004: a watched agent file changed (high).

It ends with a verdict and an exit code (0, 1 or 2), so a script you control can act on it.

How often to run it

Run verify after every skill install or update, and on a schedule that fits the agent's access: daily is reasonable for an agent that can reach email, code or money. Run it from your own shell or a job the agent does not start, and let the exit code decide what happens next. Start with npx ironheights doctor to see which OpenClaw directories it found.

What to do with a change

Open each reported file and make sure you recognize the change. Memory files change in normal use, so read what was added rather than ignoring them. If a skill changed, scan it again with npx ironheights scan before you accept the change with npx ironheights baseline update. If something is wrong, ironheights quarantine <skill> moves the skill out of the agent's reach without deleting it. The full routine is in Baselines for agent files.

Limits

A baseline shows that a file changed, not whether the change is harmful. It does not see a skill that changes behavior by fetching remote instructions, and it is not real-time. Anyone who can write to your home directory can also rewrite an unsigned baseline. Since 0.2.0 you can sign it with baseline create --key <file> and check it with verify --key <file>; the signature only helps while the key stays private, so keep a copy off the machine. See signed baselines. Run verify yourself, not through the agent. See the limitations page.

Sources

  • OpenClaw skill supply-chain risk is the chance that a third-party skill, its update, or a link it depends on harms your agent. Where it enters and how to reduce it.
  • Verify a ClawHub skill in five steps: confirm the listing and publisher, read the scan status, read SKILL.md's setup and links, scan it, and record a baseline.
  • Ironheights misses payloads on linked sites, files over 1 MiB by default, runtime behavior, money-moving instructions and novel attacks. What to do about each.

All answers

Check the next skill before your agent reads it

Ironheights is a free, open-source, local-first scanner and integrity monitor for OpenClaw skills. It reports what its rules match; it cannot prove a skill is safe.