lov-clash-tun-doctor

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script uses subprocess.run to quit and restart the Clash Verge application using osascript and the open utility. These commands are executed with predefined application names and do not involve shell execution or user-controlled command strings.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from application logs and network connection metadata to generate firewall rules. This creates an indirect prompt injection surface if log content is manipulated, though the script performs hostname validation and uses structured YAML serialization to mitigate risks.
  • Ingestion points: Log files and runtime connection data read in scripts/clash_tun_doctor.py via the discover_direct_list and recent_log_findings functions.
  • Boundary markers: Not present for the processed data strings.
  • Capability inventory: File system write access for configuration files and application lifecycle management via subprocess in scripts/clash_tun_doctor.py.
  • Sanitization: Hostnames are validated against the strict HOSTNAME_RE regex, and rules are serialized using json.dumps before being merged into YAML files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:06 PM
Security Audit — agent-trust-hub — lov-clash-tun-doctor