Using IronheightsUpdated

What does Ironheights not detect?

Short answer

Ironheights only sees patterns its rules describe in the files it reads. It misses payloads hosted on a linked website or paste site, files over 1 MiB by default, behavior that appears only at runtime, instructions to move money, novel or heavily obfuscated attacks, and tampering by someone who can rewrite its baseline. No findings is not proof of safety.

The blind spots, with examples

Blind spotPublic exampleWhat Ironheights reports
Payload on a linked website or paste siteAbout 40 skills that only linked to a lookalike siteThe link, as a review finding (IH-NET-001)
Archive hosted on GitHubWindows steps in several campaignsNothing: GitHub is on the allowlist
File larger than 1 MiBA README padded to about 22 MBNothing inside the file with default settings; the scan is reported as incomplete (exit code 3)
Runtime and remote behaviorA skill that fetched affiliate links on every useThe remote host, not the behavior
Instructions to move moneyA scheme to pool cryptocurrency into the operator's walletNothing
Novel or heavily obfuscated phrasingNot measurable in advanceOnly what matches a rule
Compromised hostAn attacker who can write your home directoryverify trusts a baseline that can be rewritten

Each public example is a sourced entry in our malicious skill tracker, which marks whether the reported pattern is covered, partly covered, or not covered.

Why these gaps exist

Ironheights is a static, rules-only scanner. It reads files as text and never runs them, never fetches URLs while scanning, does not extract archives, and does not decide verdicts with a language model. An optional model review can add advisory notes (off by default, you choose the server); it never changes a verdict. Those choices keep it local, fast and predictable, and they define what it can see.

What to do about each

  • Linked payloads and archives: treat any unexplained link or archive in a setup step as a stop.
  • Large files: the CLI names every skipped file and directory (.git and node_modules are not entered unless you acknowledge them with a reason in ignoreDirs) and reports the verdict incomplete with exit code 3, so a padded file no longer reads as clean. Raise limits.maxFileBytes in your config to have the file scanned, and treat --allow-skipped as accepting the risk. The browser scanner shows "Incomplete scan" when it skips a file.
  • Runtime behavior and money: read what the skill tells the agent to do, run new skills without production keys or funded wallets, and require approval for transfers.
  • Novel attacks: read the skill yourself and consider a second tool with a different method.
  • Host compromise: keep the baseline somewhere harder to write, and investigate the machine itself.

Why we publish this list

A scanner that hides its blind spots invites false confidence, which is worse than no scanner. Every rule page on this site has its own "what it cannot catch" section, and we add to this list when we find a new gap.

How we measure it

Our benchmark is a small synthetic corpus written by us: a regression check, not a real-world detection rate. The full list is on the limitations page, and What our scanner cannot catch goes through each case in depth.

Sources

All answers

Check the next skill before your agent reads it

Ironheights is a free, open-source, local-first scanner and integrity monitor for OpenClaw skills. It reports what its rules match; it cannot prove a skill is safe.