IH-CFG-001highOpenClaw config

Gateway bind is not loopback

gateway.bind is lan, tailnet, custom, auto, or an all-interfaces address, or gateway.tailscale.mode is funnel. OpenClaw's native check gateway.bind_no_auth covers a remote bind without a shared secret, and gateway.tailscale_funnel covers public Funnel. This rule only reads the config value. It does not probe the listener. auto is medium because the effective bind is chosen at runtime. Funnel and 0.0.0.0 are critical.

What does IH-CFG-001 flag?

Reads gateway.bind in your OpenClaw config and flags a Gateway that listens on more than the local machine, or that is exposed through Tailscale Funnel.

  • gateway.bind set to lan, tailnet, custom, auto, or an all-interfaces address.
  • gateway.tailscale.mode set to funnel.

Why it matters

A Gateway on a LAN or all-interfaces address can be reached by other devices. Public exposure through Funnel puts it on the internet. Both raise the cost of any weak setting elsewhere in the file.

Severity: High. auto is medium because the real bind is decided at run time. Funnel and an all-interfaces address are critical.

Examples

Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.

LAN bind
Flagged
gateway.bind: "lan"
Funnel
Flagged
gateway.tailscale.mode: "funnel"
Loopback
Not flagged
gateway.bind: "loopback"
Omitted
Not flagged
gateway.bind omitted (OpenClaw's default is loopback)

Can IH-CFG-001 fire on a safe skill?

  • A bind you deliberately expose behind your own firewall and authentication.

How do I fix an IH-CFG-001 finding?

  • Prefer gateway.bind loopback.
  • If the Gateway must leave the machine, require token or password auth and firewall the port.
  • Do not use Tailscale Funnel for a Gateway you have not locked down.

CLI guidance: Prefer gateway.bind "loopback". Run openclaw security audit for a live check.

How do I tune or allow IH-CFG-001?

audit-config reads the file only. Lower the severity or turn the rule off for a deliberate setup with ruleOverrides in your Ironheights config.

{
  "ruleOverrides": {
    "IH-CFG-001": {
      "enabled": false
    }
  }
}

Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-CFG-001.

What can IH-CFG-001 miss?

  • Whether anything is actually listening. The rule does not probe the port; openclaw security audit --deep does.
  • Settings that come from environment variables rather than the file.

No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.

Scores and thresholds shown are the CLI defaults; your config can change them. List every rule from the terminal with ironheights rules list.

All 35 rules