What does IH-NET-001 flag?
Lists every URL whose host is not on the allowlist. Raw IP addresses and known high-risk hosts, such as URL shorteners, paste sites, file-drop hosts, tunnels, request catchers, dynamic DNS, Discord webhooks and Telegram bot links, are raised to high.
- Any http://, https:// or protocol-relative // URL in a script, config or other text file, except the cases listed below.
- Hosts on the allowlist, and their subdomains, are skipped. Built in: example.com, example.org, example.net, localhost, the loopback addresses 127.0.0.1 and ::1, github.com, githubusercontent.com, npmjs.org, yarnpkg.com, pypi.org, pythonhosted.org and openclaw.ai. A skill can add its own hosts under metadata.ironheights.allowDomains in its SKILL.md frontmatter, which applies to that skill only.
- In a Markdown file, a URL is reported when the line makes or sends a request (curl, wget, iwr, fetch(, axios., or send, post, upload, forward wording), when it tells the reader to download, install, fetch, open or follow it (for example Download and install from https://…, or Fetch this URL https://… and follow it), when the URL stands alone on its line, or when the host is on the high-risk list.
- Raised to high, and always reported: IP-address hosts; shorteners such as bit.ly and tinyurl.com; paste sites such as pastebin.com, rentry.co, glot.io, dpaste.com, ghostbin.com and justpaste.it; file-drop hosts such as transfer.sh, file.io, gofile.io, catbox.moe, pixeldrain.com and anonfiles.com; tunnels such as ngrok and trycloudflare.com; webhook.site and hooks.slack.com; dynamic DNS such as duckdns.org; Discord webhook paths; Telegram bot API paths.
- Not reported: a homepage: frontmatter field, an XML namespace or schema link, a placeholder host (a host with an example label, or provider.com), a URL in a LICENSE file, and a Markdown URL that is only mentioned in prose, such as an official API host in a sentence, with no request, send or download wording on the line.
Why it matters
An unexpected host is where data leaves or where the next stage comes from. Reported ClawHub campaigns fetched payloads from a raw IP address and from paste sites, which avoids domain reputation checks.
Severity: Base severity is medium (15 points). A raw IP address or a known high-risk host is reported as high (40 points).
Examples
Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.
Can IH-NET-001 fire on a safe skill?
- Every legitimate API host you have not declared yet. Declare it in allowDomains, or for one skill in metadata.ironheights.allowDomains.
- Hosts in scripts and config files that the skill really contacts.
- Setup notes that tell the reader to download or install from a vendor's own site.
How do I fix an IH-NET-001 finding?
- Declare the hosts the skill really needs in allowDomains, or in metadata.ironheights.allowDomains for this skill only.
- Remove requests the skill does not need, and prefer the provider's official API host.
CLI guidance: Declare the host in allowDomains, or in metadata.ironheights.allowDomains for this skill only. Prefer the official API host.
How do I tune or allow IH-NET-001?
Add hosts to allowDomains; an entry matches the host and all of its subdomains. To quiet the rule for one project, lower its severity with ruleOverrides instead of turning it off.
Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-NET-001.
What can IH-NET-001 miss?
- Hosts built at run time from pieces, environment variables or decoded strings.
- Allowlisted hosts used for harm. GitHub is on the built-in allowlist, and several campaigns hosted payload archives in GitHub releases.
- Whether a host is actually malicious. The rule only knows that it is undeclared.
- A link in prose that does not use download, install, fetch, open or follow wording, such as a bare mention of a lookalike site inside a longer sentence, unless the host is on the high-risk list.
- A paste or file-drop host that is not on the list.
No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.
In the tracker
Publicly reported cases where a synthetic copy of the reported pattern raises IH-NET-001. Coverage is about the pattern, not a scan of the original files.
- money-radar (runtime affiliate injection)Palo Alto Networks Unit 42 · 23 June 2026Partly covered
- TradingView assistant skills delivering the cluw stealerPalo Alto Networks Unit 42 · 23 June 2026Partly covered
- Skills distributing an Atomic macOS Stealer variantTrend Micro · 23 February 2026Partly covered
- copywritings and airbnb by StveenLiCommunity reports on GitHub (loganaden) · 10 February 2026Partly covered
- google-qx4 (fake openclaw-core requirement)Snyk · 10 February 2026Partly covered
- Fake “OpenClawCLI” website lure (thiagoruss0, stveenli)OpenSourceMalware · 9 February 2026Partly covered
- More skills by zaycv: linkedin-job-application, autoupdater, deepresearchCommunity reports on GitHub (adrianwedd, hendrysadrak, rafadiasbsb) · 4 February 2026Covered
- Fake “ClawHub CLI” skills by zaycv (clawhub, clawdhub1)Snyk; GitHub issue by lycfyi · 2 February 2026Partly covered
- WhatsApp and security-check lookalikes by moonshine-100rzeCommunity reports on GitHub (diegofornalha, biagiom) · 2 February 2026Covered
- “AuthTool” trading skillsKoi Security · 1 February 2026Partly covered
- ClawHavocKoi Security · 1 February 2026Partly covered
- Malicious ClawHub skills targeting crypto and trading usersOpenSourceMalware (Paul McCarty) · 1 February 2026Partly covered
- Polymarket skills with a hidden reverse shellKoi Security; community report on GitHub (NCC-David) · 1 February 2026Covered
- rankaj (credential exfiltration)Koi Security · 1 February 2026Covered
Related rules
ironheights rules list.