Runs in your browser Nothing uploadedrules from ironheights 0.1.5

Skill scanner

Check an OpenClaw skill before you install it. Paste a SKILL.md or drop the skill folder, and get the same verdict, rule ids, and evidence as the command-line scanner. It is a signal to read alongside the skill, not a guarantee.

Quick answerLast updated

How do I check a SKILL.md in my browser?

Paste a SKILL.md or drop a folder below. The scanner runs the 17 content rules from the Ironheights 0.1.5 engine inside this tab and returns no findings, review or block, with rule ids and line numbers. Your skill’s content is never sent anywhere. Integrity, MCP and advisory checks need the CLI. No findings is not proof of safety.

Skill input
Paste a SKILL.md, or drop a file or a whole skill folder anywhere on this card.
0 B / 1 MiB

Scan results

Results appear here
Paste a skill and press Scan, or try the risky example to see what findings look like. The verdict uses the CLI's thresholds: review at 15, block at 80 or on any critical finding.
Check that your skill never leaves
Your skill stays in this tab. You do not have to take our word for it.

Open your browser's developer tools, pick the Network tab, and scan. No request carries your text. You may see the site fetch its own pages ahead of time for faster navigation; those requests hold no input. Or load this page, turn off Wi-Fi, and scan: it still works.

The scanner uses no cookies and no storage. Share links keep the text after the # sign, which browsers never send to a server. With your consent, the site records only the scan verdict (no content).

What this cannot catch
17 content rules run here. No findings means none of them matched.
  • Pattern rules miss novel and heavily obfuscated attacks, and anything a skill downloads or builds at run time.
  • Nothing is executed. Behavior that only shows up when the skill runs is not observed.
  • Archives are flagged, never opened. Binaries are flagged by name and magic bytes, not analysed.
  • Pasting checks SKILL.md only. Scripts and other files in a skill matter too, so drop the whole folder when you have it.
  • The four integrity rules (IH-INT) need a baseline on your machine. They run in the CLI only.
  • Your config is not applied here: default allowlist, default limits, no rule overrides. A host the skill declares itself under metadata.ironheights.allowDomains is honored, as in the CLI.
  • For pasted text there is no folder, so the folder-name half of IH-META-001 is skipped.
  • Files larger than 1 MiB are not scanned. The CLI skips them too and reports verdict incomplete with exit code 3 (--allow-skipped accepts them); this page shows the same Incomplete scan result and names every file it skipped for size.
All limitations
Run it locally
The CLI scans whole skill folders, every installed skill, and changes since your baseline.
npx ironheights scan ./path/to/skill
npx ironheights scan ./skills --sarif results.sarif --fail-on high

Questions about the browser scanner

No. The Ironheights rule engine is compiled into this page and runs in your browser tab. The scanner never sends your skill's content anywhere: the page has no upload endpoint and makes no network request with your input. With your consent, the site records only the scan verdict (no content). To check, open your browser's developer tools on the Network tab while you scan, or load the page, go offline, and scan.

Yes for content rules. The page uses the rule code from ironheights 0.1.5 unchanged, and a test runs the same fixtures through both and requires identical rule ids, lines, evidence, scores, and verdicts. The CLI adds integrity checks against a local baseline, your config file, and folder scans of installed skills.

Each finding adds points by severity: critical 100, high 40, medium 15, low 5. Block means a critical finding or a score of 80 or more. Review means a high or medium finding, or a score of 15 or more. No findings means no rule matched, which is not proof that a skill is safe.

The pasted text is compressed into the part of the link after the # sign. Browsers do not send that part to the server, so the skill travels inside the link itself. Anyone with the link can read the skill, so do not share links for private skills.