Security and disclosure

A security tool needs deep access to your machine, so it has to earn trust. Here is how we handle reports, releases, and research.

Report a vulnerability

Open a private security advisory on GitHub. Include the rule id if one exists, a minimal skill that triggers the issue, and the output of ironheights --version. Please give us time to ship a fix before writing about it in public. There is no bug bounty.

Do not send real secrets or live malware. A synthetic snippet that matches the pattern is enough.

Supported versions

Supported versions
VersionSupported
0.1.xYes

Official sources

Ironheights is distributed only through:

Copycat “antivirus” or “security” skills are a known way to spread malware. If you find one using our name, report it as a GitHub issue.

Malicious skill research

When we write up a malicious skill, we describe the technique and indicators without publishing a runnable payload, and we report live samples to the marketplace before we publish. Keep real samples on an isolated machine, on a read-only mount, and never run them.

No phone-home

Ironheights sends no telemetry, and a scan makes no network call. Only the commands you run on purpose (fetch, safe-install, advisories update, and the optional model review) use the network, and the CLI prints each URL first. A report you file on GitHub is the only disclosure channel. Read the SECURITY.md in the repository.