What does IH-CFG-008 flag?
Flags skills.load.extraDirs and skills.load.allowSymlinkTargets, which make OpenClaw load skills from folders outside the normal skill roots.
- skills.load.extraDirs or skills.load.allowSymlinkTargets is set.
- A home directory, a filesystem root, a drive root, or a path containing .. is critical. Other extra directories are medium.
Why it matters
Every extra directory is trusted as a source of instructions. A directory that points at your home folder or the filesystem root trusts everything inside it.
Severity: Medium, and critical for a home directory, a filesystem root, a drive root or a path containing ...
Examples
Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.
Can IH-CFG-008 fire on a safe skill?
- An extra folder you maintain and review yourself.
How do I fix an IH-CFG-008 finding?
- Remove extra directories you do not trust.
- Never point extraDirs or allowSymlinkTargets at ~, / or a drive root.
- Scan those directories with ironheights scan before OpenClaw loads them.
CLI guidance: Do not point extraDirs or allowSymlinkTargets at ~, /, or a drive root. Scan those directories with ironheights scan before loading them.
How do I tune or allow IH-CFG-008?
A folder you own and have scanned is a reasonable exception. Record it with ruleOverrides in your Ironheights config.
Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-CFG-008.
What can IH-CFG-008 miss?
- What is inside the extra directories. Use ironheights scan on them.
- Symlinks inside the workspace; openclaw security audit has a separate check for those.
No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.
Related rules
ironheights rules list.