What does IH-NET-002 flag?
Flags a sensitive path or an environment dump that sits within a few lines of an outbound request, or of an instruction to send it somewhere.
- A sensitive marker (the same list as IH-CRED-001, including a bare ~/.ssh, ~/.aws, ~/.gnupg or ~/.azure) or an environment dump such as printenv, process.env or os.environ.
- And, within two lines above or below, an outbound call (curl, wget, iwr or Invoke-WebRequest with an option or URL, fetch(, web_fetch(, axios., http.request, https.request, XMLHttpRequest, net.connect), or a line that tells the agent to send, post, upload, forward or transmit something to a URL.
- One finding per line that carries the request, with medium confidence. A URL on its own, with no call or send wording, does not count.
Why it matters
Reading a credential is not proof of theft, and neither is a network call. Both together is the shape of exfiltration, as in a reported ClawHub skill that read the bot's .env file and posted it to a request catcher.
Examples
Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.
Can IH-NET-002 fire on a safe skill?
- Any script that reads process.env for configuration and calls an API in the next few lines. This is common in legitimate integrations.
- Documentation that warns about ~/.ssh and shows a curl command nearby.
How do I fix an IH-NET-002 finding?
- Keep credential handling and network code apart.
- Pass a narrowly scoped token through the environment, and never send secrets to a remote host.
CLI guidance: Split credential access from network calls, and do not send secrets to a remote host.
How do I tune or allow IH-NET-002?
For integrations that legitimately read configuration from the environment, lower the rule's severity for that project with ruleOverrides and keep IH-CRED-001 on.
Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-NET-002.
What can IH-NET-002 miss?
- Reading and sending more than two lines apart, or split across two files or two skills.
- Exfiltration through the agent's own tools, such as sending an email or a chat message, instead of an HTTP call in the skill.
- Sensitive paths that are not on the list, or that are built at run time.
No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.
Related rules
ironheights rules list.