FAQ

A free, open-source command-line scanner and integrity monitor for OpenClaw skills. It flags risky patterns in skill files with fixed rules and reports changes to installed skills and agent files against a baseline you save on your machine.

No. No findings means the rules did not match. Novel, heavily obfuscated, or runtime-only attacks can still get through. Treat a clean scan as one signal and still read the skill.

Not during a scan. Scans run locally, there is no telemetry, and no scan makes a network call. Only commands you run on purpose use the network: fetch and safe-install download a skill from clawhub.ai, advisories update (or --online) downloads a signed advisory feed from ironheights.dev, and scan --llm or review send capped, secret-scrubbed skill text to a model server you choose. The CLI prints each request first.

Yes, carefully. ironheights safe-install owner/slug downloads a ClawHub skill into a staging folder without running anything, scans it, and copies it into your skills folder only when the verdict is no-findings. Review installs only with --accept-review. Block and incomplete are never installed. No findings still does not mean a skill is safe.

No. The guard is an OpenClaw plugin that runs inside the agent process and checks a short list of tool calls: credential reads, download-and-execute commands, undeclared or high-risk hosts, and writes to agent identity files and skill folders. It starts in monitor mode, which only logs. A compromised skill that can edit your OpenClaw config can turn it off, and a quiet log is not proof of safety.

Yes, and ironheights coexist helps you check. It lists the other security tools it can see on your machine (skills, plugins, scanner commands, CI files), reports overlaps such as two guards on the same tool call, and suggests a fix for each. It reads files only. Detection is heuristic, so a renamed or unlisted tool is missed, and no findings does not prove that tools will not interfere.

Not yet. The CLI can download a signed advisory feed, verify its Ed25519 signature, and report matches as IH-ADV-001, but the feed is not published yet. Until it is, ironheights advisories update has nothing to download and scans report nothing from the feed. A skill missing from a feed would still not be proof that it is harmless.

Only if you agree. ironheights.dev uses Google Analytics after you choose Accept analytics in the consent banner; until then, and if you choose No thanks, the Google script never loads. It never receives skill text, file names, search terms, or anything you type. Change your choice any time with Cookie settings in the footer. The CLI has no telemetry. The in-browser scanner never sends your skill’s content anywhere; it runs in your browser. With your consent, the site records only the scan verdict (no content). Details are on the privacy page.

No. Skill files are read as data, up to a configured size. Archives are flagged, not extracted, and scripts are never executed. A skill downloaded by fetch or safe-install is written to disk and scanned, never run.

Node.js 20 or newer for Ironheights. OpenClaw itself has stricter requirements; ironheights doctor prints whether your runtime fits the OpenClaw range.

Only from the ironheights package on npm, the GitHub releases of Frank-Masciopinto/ironheights, or links on ironheights.dev. Fake “antivirus” skills are a known lure, so do not install Ironheights from anywhere else.

No. The advisory skill runs inside the agent, and a hostile skill can try to talk the agent out of it. The CLI you run yourself, or a process outside the agent, is the trusted path.

Yes. Use --json, --sarif, --md, or --html for reports, --since-baseline to fail only on new findings, and --fail-on to choose the severity that fails the job. A GitHub Action pinned to an exact version and a pre-commit hook are included. Exit codes are 0 for no findings, 1 for review, 2 for block, 3 for an incomplete scan (a file or directory was skipped), 64 for usage errors, and 70 for internal errors.

The Community edition is free under Apache-2.0. Pro, Team, a Threat Intel API, and Enterprise are planned; the prices on the pricing page are hypotheses and nothing paid is on sale yet.

Open a private security advisory on the GitHub repository. Include the rule id if there is one, a minimal synthetic skill that triggers the issue, and the output of ironheights --version.