IH-EXEC-002highExecution

Prerequisite install from an external URL

Skills sometimes tell the agent to install a tool from a URL or git link before doing anything else. Each command is reported once, on the line that contains it.

What does IH-EXEC-002 flag?

Flags setup steps that install a package straight from a URL or git link, or that present a download-and-run command as a required first step.

  • pip, npm, pnpm, yarn or brew followed by install or add and an http(s), git+ or github: source, on one line.
  • A curl, wget or iwr download of a URL that is run by a shell or runtime, when the same line or a line within two lines of it also says required, prerequisite, must run, run first, before you begin or install first.
  • One finding per command, on the line that contains it, with the command itself as evidence. A prerequisite phrase nearby raises the confidence; it does not add a second finding, and a blank line is never a finding.

Why it matters

Fake prerequisites were the lure in most reported ClawHub malware. The skill reads like ordinary documentation and the harm sits behind “install this first”. Registry installs are versioned and reviewable; installs from an arbitrary URL are not.

Examples

Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.

Package from a git URL
Flagged
Prerequisite: pip install git+<repo-url>
Registry package
Not flagged
npm install zod

Can IH-EXEC-002 fire on a safe skill?

  • Projects that only publish from git, such as pre-release tools and forks, match.
  • Contributor notes that explain how to install a development build from GitHub match.
  • A package name on one line with its source URL on the next (brew install widget, then Source: https://…) does not match, because the URL has to be on the same line as the install command.

How do I fix an IH-EXEC-002 finding?

  • Publish to the registry and install from it, pinned to a version.
  • If a git install cannot be avoided, pin a commit hash and say why in the skill.

CLI guidance: Install only from the language registry or the operating-system package manager, pinned to a version.

How do I tune or allow IH-EXEC-002?

Lower the rule's severity or turn it off for a project with ruleOverrides, or exclude a contributor-docs folder with ignoreGlobs.

{
  "ignoreGlobs": [
    "docs/known-example.md"
  ],
  "ruleOverrides": {
    "IH-EXEC-002": {
      "enabled": false
    }
  }
}

Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-EXEC-002.

What can IH-EXEC-002 miss?

  • An install command and its URL split across lines, such as a package manager call on one line and the git URL on the next.
  • A prerequisite that only links to a download page, a password-protected archive or a lookalike website, with no install command in the skill itself. Several reported campaigns worked this way.
  • Instructions in another language, or phrased without the trigger words.
  • Telling the user to download and open an executable by hand.

No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.

Scores and thresholds shown are the CLI defaults; your config can change them. List every rule from the terminal with ironheights rules list.

All 35 rules