Using IronheightsUpdated

How do I install Ironheights?

Short answer

You need Node.js 20 or newer. Run npx ironheights scan with the path to a skill to use it without installing, or install the command globally with npm install -g ironheights; ih is a shorter alias for the same command. Get it only from the ironheights package on npm, the project's GitHub releases, or this site.

Run it once with npx

npx ironheights scan ./path/to/skill

npx downloads the package and runs it. Nothing else is set up, and the files you scan are read as data, never executed.

Install the command

npm install -g ironheights
ironheights --version

ironheights and ih are the same command. The current version is 0.3.0. It runs on macOS, Linux and Windows; Windows support is new in 0.2.0 and is tested in CI on Node.js 20.0.0 and 24.

A 60-second first run

npx ironheights doctor
npx ironheights scan ~/.openclaw/workspace/skills/some-skill
npx ironheights baseline create
npx ironheights verify

doctor prints which OpenClaw directories it found and whether your Node.js version fits the range OpenClaw itself requires (OpenClaw has stricter requirements than Ironheights). scan prints findings grouped by skill and a verdict. baseline create records your skills and agent files, and verify later reports what changed. The docs list every command, flag, exit code and config key. To check a ClawHub skill before it reaches your machine, use npx ironheights safe-install <owner>/<slug>, which installs only when the scan is clean. See the features page.

Only from official sources

Fake security tools are a documented lure. Public reports describe a malicious skill that posed as a skill security checker, and a security-auditing skill that carried an encoded download command. Install Ironheights only from:

Optional: the advisory OpenClaw skill

An optional skill tells your agent to run ironheights scan <path> --json before it installs or updates a skill, summarize the findings, and stop on a block verdict until you confirm. It asks for no network access and no secrets, and it expects the ironheights command to be installed already. It is advisory: it runs inside the agent, and a hostile skill can try to talk the agent out of it, so the CLI you run yourself is the trusted path. We explain why in this post.

Do not want to install anything?

The browser scanner runs the same content rules on a pasted SKILL.md in your browser. Integrity checks need the CLI.

If something does not work

Run ironheights --version; it should print 0.3.0. If the command is not found after a global install, check that npm's global bin directory is on your PATH, or keep using npx ironheights. If doctor reports that your Node.js version is outside OpenClaw's range, that affects OpenClaw, not Ironheights, which only needs Node.js 20 or newer. Version 0.1.0 printed nothing when started through npx or the installed command; that was fixed in 0.1.1 and every later release, so make sure you are not pinned to the older release. Report anything else as a GitHub issue.

Limits

Installing a scanner does not make skills safe. No findings means no rule matched; read the limitations before relying on a result.

Sources

  • Scan an OpenClaw skill before install with npx ironheights scan, or paste SKILL.md into the free browser scanner. What the verdicts mean, and what a scan misses.
  • Yes. The Ironheights CLI, rules and advisory skill are free and open source under Apache-2.0. Paid tiers are planned, their prices are hypotheses, none is on sale.
  • The Ironheights CLI has no telemetry and a scan makes no network call. Commands you choose, such as fetch, use the network. What the website records, with consent.

All answers

Check the next skill before your agent reads it

Ironheights is a free, open-source, local-first scanner and integrity monitor for OpenClaw skills. It reports what its rules match; it cannot prove a skill is safe.