IH-INT-004highIntegrity

Watched agent file changed

An agent instruction, personality, memory, or config file changed since the baseline.

What does IH-INT-004 flag?

Reports a change to a watched agent file, such as the agent's instructions, personality, memory or configuration, since the baseline.

  • A watched agent file whose content changed. Watched files come from agentFiles in the config; by default Ironheights uses the OpenClaw agent files it finds on the machine.
  • Reported by verify only.

Why it matters

Agent files steer everything the agent does. A skill that rewrites them can keep influencing the agent after it is removed, which is why memory and config tampering is treated as a high-severity change.

Examples

Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.

Changed agent file
Flagged
AGENTS.md changed
Unchanged
Not flagged
AGENTS.md matches baseline

Can IH-INT-004 fire on a safe skill?

  • Edits you made yourself, and memory files the agent updates during normal use.

How do I fix an IH-INT-004 finding?

  • Compare the agent file with a copy you trust before starting the agent again.

How do I tune or allow IH-INT-004?

Choose which files are watched with agentFiles, and record accepted edits with ironheights baseline update.

ironheights verify
ironheights baseline update

Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-INT-004.

What can IH-INT-004 miss?

  • Files that are not in agentFiles.
  • Harmful content that was already there when the baseline was saved.

No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.

Scores and thresholds shown are the CLI defaults; your config can change them. List every rule from the terminal with ironheights rules list.

All 35 rules