Back to skill

Security audit

Clash Controller

Security checks across malware telemetry and agentic risk

Overview

This skill appears to control Clash as advertised, but it can change proxy routing from broad commands without confirmation and includes under-scoped proxy security guidance.

Install only if you intentionally want an agent to control Clash for Windows. Before use, replace the hardcoded controller secret with your own private configuration, avoid enabling allow-lan unless you understand the exposure, and issue explicit Clash-specific commands when changing proxy state.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad and include common terms like '代理', '状态', and '切换节点', which can be invoked during ordinary conversation without clear user intent to run the skill. Because this skill can alter system proxy behavior, accidental activation could change network routing, interrupt connectivity, or redirect traffic through an unintended proxy configuration.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The examples include ambiguous short triggers such as '状态', which lack scope constraints and can easily collide with unrelated user requests. In a skill that controls system proxy settings, such ambiguity increases the risk of unintended execution and unauthorized environment changes from casual conversation or prompt injection via nearby text.

Missing User Warnings

Medium
Confidence
82% confidence
Finding
The skill performs state-changing operations against a local privileged control API immediately based on loose keyword matching, without confirmation or other guardrails. In an agent setting, ambiguous or adversarially induced prompts could unintentionally disable the proxy or reroute traffic, affecting user privacy, connectivity, and trust boundaries.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.