lov-clash-tun-doctor
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script uses
subprocess.runto quit and restart the Clash Verge application usingosascriptand theopenutility. These commands are executed with predefined application names and do not involve shell execution or user-controlled command strings. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from application logs and network connection metadata to generate firewall rules. This creates an indirect prompt injection surface if log content is manipulated, though the script performs hostname validation and uses structured YAML serialization to mitigate risks.
- Ingestion points: Log files and runtime connection data read in
scripts/clash_tun_doctor.pyvia thediscover_direct_listandrecent_log_findingsfunctions. - Boundary markers: Not present for the processed data strings.
- Capability inventory: File system write access for configuration files and application lifecycle management via
subprocessinscripts/clash_tun_doctor.py. - Sanitization: Hostnames are validated against the strict
HOSTNAME_REregex, and rules are serialized usingjson.dumpsbefore being merged into YAML files.
Audit Metadata