IH-FS-001mediumFilesystem

Suspicious filesystem access

Symlinks that leave the skill, path traversal, and hidden files can read or hide data outside the skill.

What does IH-FS-001 flag?

Flags symlinks that leave the skill folder, path traversal, hidden dotfiles, and text that describes traversal or absolute symlinks.

  • Symlinks that point outside the skill folder, and symlink loops. Neither is followed.
  • File paths that contain a .. segment.
  • Hidden dotfiles inside the skill (low).
  • Lines with ../ or ..\ sequences, or ln -s with an absolute target.

Why it matters

Files that point outside the skill can read or hide data elsewhere on the machine, and dotfiles are easy to miss in a review.

Severity: Medium (15 points). A hidden dotfile on its own is reported as low (5 points).

Examples

Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.

Traversal
Flagged
../../etc/<file>
Inside the skill
Not flagged
./notes/today.md

Can IH-FS-001 fire on a safe skill?

  • Markdown links to a parent folder, such as ../README.md.
  • Ordinary dotfiles such as .gitignore (reported as low).

How do I fix an IH-FS-001 finding?

  • Keep every file inside the skill folder.
  • Do not use symlinks that point elsewhere, or dotfiles to hide content.

CLI guidance: Keep every file inside the skill directory. Do not use symlinks that point elsewhere or dotfiles to hide content.

How do I tune or allow IH-FS-001?

Exclude known-harmless dotfiles with ignoreGlobs.

{
  "ignoreGlobs": [
    "docs/known-example.md"
  ]
}

Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-FS-001.

What can IH-FS-001 miss?

  • Absolute paths read directly. IH-CRED-001 covers the sensitive ones.
  • Paths built at run time.

No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.

Scores and thresholds shown are the CLI defaults; your config can change them. List every rule from the terminal with ironheights rules list.

All 35 rules