What does IH-CFG-007 flag?
Flags settings that give the agent broad command power: exec security set to full, exec approval switched off, or elevated tools enabled.
- tools.exec.security, or an agent's exec security, set to full.
- tools.exec.ask set to off while security is not deny.
- tools.elevated enabled, and critical when elevated allowFrom contains *.
Why it matters
If the agent can run any command without asking, a single injected instruction becomes code execution on your machine.
Severity: High, and critical for an elevated allowFrom wildcard or when full exec meets an open room.
Examples
Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.
Can IH-CFG-007 fire on a safe skill?
- A throwaway sandbox machine where the agent is meant to run anything.
How do I fix an IH-CFG-007 finding?
- Set tools.exec.security to deny or allowlist.
- Set tools.exec.ask to always.
- Keep tools.elevated.enabled false unless allowFrom is a named list without *.
CLI guidance: Set tools.exec.security to deny or allowlist, set tools.exec.ask to always, and keep tools.elevated.enabled false unless allowFrom is a named list without *.
How do I tune or allow IH-CFG-007?
Use ruleOverrides in your Ironheights config only for a machine where full exec is deliberate.
Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-CFG-007.
What can IH-CFG-007 miss?
- Interpreter allowlists, safeBins and approval-file drift; openclaw security audit covers those.
No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.
Related rules
ironheights rules list.