IH-CFG-002criticalOpenClaw config

Gateway auth is missing or a placeholder

gateway.auth.mode is none or trusted-proxy, a non-loopback bind has no auth object, or the token or password in the file is empty or a known placeholder. Native checks gateway.bind_no_auth, gateway.loopback_no_auth, gateway.token_placeholder_value, and gateway.trusted_proxy_auth overlap this rule. A loopback bind that omits auth is not flagged: OpenClaw's default is authenticated, and the token may live in OPENCLAW_GATEWAY_TOKEN, which this command does not read. trusted-proxy is critical because the proxy becomes the auth boundary; proxy IPs and headers are left to the native audit.

What does IH-CFG-002 flag?

Flags a Gateway whose authentication is off, trusts a proxy, is missing on a non-loopback bind, or uses an empty or placeholder token or password.

  • gateway.auth.mode is none or trusted-proxy.
  • A non-loopback bind with no gateway.auth.
  • A token or password in the file that is empty or a known placeholder.
  • Not reported: a loopback bind with auth omitted, because OpenClaw's default is authenticated and the token may live in an environment variable the command does not read.

Why it matters

Authentication is what stands between a reachable Gateway and anyone who can reach it. A copied placeholder token is as good as no token.

Examples

Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.

Auth switched off
Flagged
gateway.auth.mode: "none"
Placeholder token
Flagged
gateway.auth.token: "replace-with-<random-token>"
Token from the environment
Not flagged
gateway.auth.token: "${OPENCLAW_GATEWAY_TOKEN}"

Can IH-CFG-002 fire on a safe skill?

  • trusted-proxy is flagged because the proxy becomes the security boundary. If you run one on purpose, the finding is a reminder, not a fault.

How do I fix an IH-CFG-002 finding?

  • Set gateway.auth.mode to token or password.
  • Keep the secret in the environment or a SecretRef.
  • For trusted-proxy, run openclaw security audit and keep gateway.trustedProxies tight.

CLI guidance: Set gateway.auth.mode to token or password and store the secret in the environment or a SecretRef, not as a placeholder. This command never prints the secret.

How do I tune or allow IH-CFG-002?

Tune with ruleOverrides in your Ironheights config only for a setup you have reviewed. The command never prints the secret; evidence is the key path plus a redaction marker.

Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-CFG-002.

What can IH-CFG-002 miss?

  • Token strength or length.
  • Secrets supplied only through the environment.
  • Proxy addresses and headers; the native audit covers those.

No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.

Scores and thresholds shown are the CLI defaults; your config can change them. List every rule from the terminal with ironheights rules list.

All 35 rules