What does IH-BIN-001 flag?
Flags executables and archives inside the skill folder, recognised by file extension or by the file's first bytes. Archives are never extracted.
- Executables: .exe, .dll, .msi, .dmg, .pkg, .so, .dylib and .apk, or an executable file header.
- Archives: .zip, .tar, .gz, .tgz, .7z, .rar, .bz2, .xz and .jar, or an archive file header.
Why it matters
A skill is instructions and small scripts. A bundled executable or archive can hide an installer, and one reported ClawHub skill shipped a Windows executable that antivirus engines flagged.
Severity: Executables are high (40 points). Archives are reported as medium (15 points), and password-protected zip files are called out in the message.
Examples
Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.
Can IH-BIN-001 fire on a safe skill?
- Skills that ship a legitimate native module or a .jar for a Java tool.
- Sample data archives.
How do I fix an IH-BIN-001 finding?
- Remove the binary.
- Document a package-manager install instead of bundling an executable or archive.
How do I tune or allow IH-BIN-001?
If a binary is expected, verify where it came from, then exclude that path with ignoreGlobs.
Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-BIN-001.
What can IH-BIN-001 miss?
- Executables downloaded later from a release page or website the skill links to. Several campaigns hosted password-protected archives in GitHub releases.
- What is inside an archive, because archives are not extracted.
- Scripts, which are text and are covered by the other rules.
No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.
In the tracker
Publicly reported cases where a synthetic copy of the reported pattern raises IH-BIN-001. Coverage is about the pattern, not a scan of the original files.
Related rules
ironheights rules list.