Features
Version 0.3.0 checks how Ironheights sits beside the other security tools on your agent. The 0.2.0 release went beyond scanning: it can fetch and vet a skill before installing it, match skills against a signed advisory feed, sign your baseline, and watch an agent's tool calls. Each feature below says what it does, how to run it, and where it stops.
What is new in Ironheights 0.3.0?
Version 0.3.0 adds ironheights coexist, which finds other security tools on your machine and reports where they overlap with Ironheights, plus a guard priority setting. The 0.2.0 release added fetch and safe-install, signed baselines, an A to F grade, honest incomplete verdicts and an optional guard plugin that is not a sandbox. Detection is heuristic.
Every command below is in ironheights 0.3.0 on npm. Angle brackets such as <owner>/<slug> are placeholders you fill in. A scan reports what its rules match. No findings is not proof of safety, and none of these features changes that.
New in 0.3.0: next to your other security tools
Most agents that care about security already run something else. Ironheights now looks for it, tells you where the two would collide, and stays out of the way.
Works next to your other security tools
- It reads your OpenClaw config (plugin and hook entries), plugin manifests, skill and hook folders, known state folders, PATH, and CI or pre-commit files in a project. Each tool it lists shows the file that gave it away.
- Eleven checks, IH-COEX-001 to IH-COEX-011: two guards on the same tool call, Ironheights in enforce mode blocking another tool, two tools restoring the same files, shared state paths, a config that exempts a security tool by name, and more. Each has a severity and a fix.
- Text for people, --json for scripts, and --fail-on to exit 1 in CI when a finding reaches a severity.
- doctor prints a one-line summary, and the guard plugin writes one log line at startup when it sees another tool.
See what runs next to Ironheights
npx ironheights coexistFail a CI job on a medium or higher overlap
npx ironheights coexist --json --fail-on mediumInclude a project's CI and pre-commit files
npx ironheights coexist --repo <path-to-project>A guard that shares the hook
- Set plugins.entries.ironheights-guard.config.priority to an integer from -1000 to 1000. Higher runs first, and OpenClaw's own default is 0.
- The guard returns only block and blockReason. It never rewrites parameters and never asks for approval, so it cannot collide with another plugin's rewrite or prompt.
- Every block reason starts with ironheights:, so you can tell whose block you are reading.
- Its files all live under ~/.ironheights, apart from other tools' folders. coexist flags the case where IRONHEIGHTS_HOME points at a shared folder.
- At startup the plugin writes one log line when it sees other security tools. It has a three-second limit and cannot delay OpenClaw.
Plugin config with a priority
{ "plugins": { "entries": { "ironheights-guard": { "enabled": true, "config": { "mode": "monitor", "priority": 80 } } } } }Check mode, policy and log
npx ironheights guard statusSecurity tools are not trusted by name
- The note reads: name match only, not verified. Anyone can copy a name.
- Only injection and credential findings in Markdown files are affected. Scripts, config, binaries, network, obfuscation, persistence and exec findings are untouched.
- Nothing is allowlisted. If you trust one copy, review it, then baseline it, or add a suppression with a written reason for that file and line.
- coexist reports IH-COEX-010 when your own config exempts a path that carries the name of a security tool.
Scan a security skill and read the note
npx ironheights scan <path-to-skill>New in 0.2.0: protection beyond scanning
Checks before you install a skill, while your agent runs, and after something changes.
Fetch and safe-install
- Nothing that is downloaded is executed. Files are written readable only by you (mode 0600) and archives are never extracted.
- block and incomplete verdicts are never installed. A review verdict installs only if you add --accept-review.
- If a copy of the skill is already installed it is backed up first and restored if the new copy fails.
- The download goes to clawhub.ai over HTTPS, redirects are refused, and each file's size and sha256 must match what ClawHub lists. The CLI prints every URL before it asks.
Scan without installing
npx ironheights fetch <owner>/<slug>Install only if the scan is clean
npx ironheights safe-install <owner>/<slug>Pin a version and a folder
npx ironheights safe-install <owner>/<slug>@<version> --dir ~/.openclaw/workspace/skillsSigned advisory feed support
- The feed is checked with an Ed25519 signature. A bad signature is rejected and never cached.
- scan and fetch compare the skill name, file hashes and indicator hosts with the cached feed, offline. A match is critical, so it blocks safe-install.
- ironheights advisories update is the only command that downloads the feed. There is no telemetry and no client id.
- The CLI never invents severity. The status shown is the one the source stated.
Download and verify the feed
npx ironheights advisories updateShow what is cached
npx ironheights advisories showScan; a match is reported as IH-ADV-001
npx ironheights scan <path>Signed baselines
- Sign with an HMAC-SHA256 or an Ed25519 key file. Ironheights does not create or store the key for you, and on macOS and Linux it refuses a key file that other users can read.
- A baseline whose signature does not match is reported as a tampered baseline: a critical IH-INT-001 finding and exit code 2.
- A baseline rewritten so its hashes still agree with each other still fails the signature check.
Make a key file (run in a clone of the repository)
node scripts/generate-baseline-key.mjs --alg ed25519 --out ~/.ironheights/baseline.keyCreate a signed baseline
npx ironheights baseline create --key ~/.ironheights/baseline.keyVerify it, signature included
npx ironheights verify --key ~/.ironheights/baseline.keyGuard plugin for agent tool calls
- Credential reads: SSH, cloud and wallet folders, private keys, .env files, and OpenClaw credentials.
- Download-and-execute: curl or wget piped into a shell, and a downloaded file that is then run.
- Network: a request to a host that is not on your allowlist, or to a paste site, file-drop host, tunnel or raw IP address.
- Writes to the agent's identity and memory files, such as AGENTS.md, SOUL.md and MEMORY.md, and to skill folders.
- In enforce mode a matching call is blocked until your policy file has an allow entry with a reason.
Enable the plugin in OpenClaw
openclaw plugins install --link /path/to/ironheights --force
openclaw plugins enable ironheights-guardCheck mode, policy and log
npx ironheights guard statusRead the recent log
npx ironheights guard logA to F trust grade
- A is 90 to 100, B 80 to 89, C 70 to 79, D 60 to 69, and F 0 to 59.
- The grade uses the worst skill in the scan, after suppressions.
- scan --html writes one self-contained report with no scripts and a strict content security policy.
- Every grade is printed with the line “Absence of findings is not proof of safety.”
Scan and read the grade
npx ironheights scan <path>Write a shareable HTML report
npx ironheights scan <path> --html report.htmlHonest incomplete verdicts
- dist/ is scanned like any other folder, so a pipe-to-shell line there is a finding.
- .git and node_modules are listed in the text report, in JSON skippedDirectories and in SARIF.
- --allow-skipped keeps the warning and returns the finding verdict; the grade stays incomplete.
- ignoreDirs in config, with a written reason, acknowledges a folder so it no longer makes the scan incomplete.
A scan that skipped something exits 3
npx ironheights scan <path>; echo $?Accept the skipped folders, with the warning kept
npx ironheights scan <path> --allow-skippedPiped JSON that stays whole
- Applies to scan --json, scan --format html, and every other command that writes to stdout.
- A report written to a file with --sarif or --html was already complete.
Pipe a full report
npx ironheights scan --all --json | jq '.verdict'Also in 0.2.0
Smaller additions that make the scanner easier to fit into CI, other agents and your own config.
OpenClaw config audit
- Offline and read-only. Secret values are replaced with <redacted>.
- Rules IH-CFG-001 to IH-CFG-009, output as text, JSON or SARIF.
- It does not replace openclaw security audit, which also probes a running Gateway.
Audit your config
npx ironheights audit-config
npx ironheights audit-config --json --fail-on highMCP configuration rules
- Rules IH-MCP-001, IH-MCP-002 and IH-MCP-003.
- Works on Claude Code, Codex and Cursor skill folders too: point scan at the folder.
Scan a folder with an MCP config
npx ironheights scan <path-to-folder>Only what is new
- Works with an integrity baseline or a previous --json result.
- Omitted findings still count toward the grade.
Report only new findings
npx ironheights scan <path> --since-baseline previous.jsonScan a piece of text
- --stdin reads a pipe and returns a usage error on a terminal.
- Text scans are never sent to a model.
Scan pasted text
cat <email.txt> | npx ironheights scan --stdin
npx ironheights scan --text "<text to check>"Suppressions that need a reason
- A marker with no usable reason is listed and does not hide the finding.
- A comment applies to its own line and the next.
An inline suppression
# ironheights-ignore IH-CRED-001 reason="reviewed local demo"CI action, pre-commit hook and Windows
- The action needs an exact version, such as 0.3.0, and takes no token for scanning.
- Exit code 3 still means the scan was incomplete.
GitHub Actions step
- uses: Frank-Masciopinto/ironheights@v0.3.0
with:
version: '0.3.0'
path: .
fail-on: highOptional model second opinion
- A non-local server needs --llm-consent and an API key, and the exact request is printed before it is sent. --dry-run prints it without sending.
- Notes score zero. They never change the verdict, the grade or the exit code.
See what would be sent
npx ironheights review <path> --dry-runWhat none of this is
- The guard is not a sandbox, an antivirus, or a process outside the agent. A compromised skill that can edit your OpenClaw config can turn it off.
- A grade, a signature or a quiet log is not a safety rating. Absence of findings is not proof of safety.
- The advisory feed is not published yet, so a scan reports nothing from it today. When a feed is live, a skill missing from it is still not evidence that the skill is harmless.
- Detecting other security tools is heuristic. It reads files and names, can miss a renamed or unlisted tool, and cannot tell whether a plugin is loaded in a running Gateway. A name can be copied, so Ironheights never trusts a tool by name.
- The in-browser scanner runs the content rules only. MCP, advisory, config audit, guard and coexistence checks need the CLI.