What does IH-CRED-001 flag?
Flags any line that names a file where credentials usually live.
- SSH, AWS, GnuPG and Azure folders, with or without a trailing slash or a file name: ~/.ssh, ~/.ssh/, ~/.aws, ~/.gnupg, ~/.azure, and key names such as id_rsa and id_ed25519. A name like sshd does not match.
- Cloud credentials: .aws/credentials, .aws/config, application_default_credentials and .azure/.
- .env files that are named as a path (such as ~/.env, ./.env or --env-file .env), browser Login Data, Cookies and cookies.sqlite, login.keychain, and .bash_history or .zsh_history.
- OpenClaw files: openclaw.json, credentials/whatsapp and auth-profiles.json.
- Wallet files (.electrum, wallet.dat) and the phrase seed phrase.
- From 0.2.0, the CLI also recognizes Windows home paths: ~\.ssh, %USERPROFILE%\.ssh, and the AppData locations of Chrome, Firefox and the credential store. The in-browser scanner runs the 0.1.5 engine and does not match these Windows forms.
Why it matters
Infostealers delivered through ClawHub skills went after SSH keys, cloud credentials, browser stores, keychains and wallets. A skill rarely has a legitimate reason to name these paths.
Examples
Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.
Can IH-CRED-001 fire on a safe skill?
- Security guides and READMEs that tell people to protect these paths.
- A .env path in setup notes, such as ./.env or --env-file .env, matches. A bare mention of .env, as in copying .env.example to .env, and reading process.env or the word cookies, do not.
How do I fix an IH-CRED-001 finding?
- Do not read these paths from a skill.
- Use a narrowly scoped environment variable or the platform's secret store.
CLI guidance: Use a scoped environment variable or the platform secret store.
How do I tune or allow IH-CRED-001?
If a line only documents a path, exclude that docs file with ignoreGlobs. Avoid turning the rule off for skill instructions or scripts.
Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-CRED-001.
What can IH-CRED-001 miss?
- Paths assembled at run time or encoded.
- Credential stores that are not on the list, such as other wallets, password managers and app-specific token files.
- Secrets read through an API rather than a file path.
No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.
In the tracker
Publicly reported cases where a synthetic copy of the reported pattern raises IH-CRED-001. Coverage is about the pattern, not a scan of the original files.
Related rules
ironheights rules list.