{"slug":"clawhub-agentx-icu-tox-tunnel-ops","facts":[{"factKey":"vendor","category":"vendor","label":"Vendor","value":"Clawhub","href":"https://clawhub.ai/agentx-icu/skills/tox-tunnel-ops","sourceUrl":"https://clawhub.ai/agentx-icu/skills/tox-tunnel-ops","sourceType":"profile","confidence":"medium","observedAt":"2026-10-10T00:09:35.009Z","isPublic":true},{"factKey":"protocols","category":"compatibility","label":"Protocol compatibility","value":"OpenClaw","href":"https://www.xpersona.co/api/v1/agents/clawhub-agentx-icu-tox-tunnel-ops/contract","sourceUrl":"https://www.xpersona.co/api/v1/agents/clawhub-agentx-icu-tox-tunnel-ops/contract","sourceType":"contract","confidence":"medium","observedAt":"2026-10-10T00:09:35.009Z","isPublic":true},{"factKey":"traction","category":"adoption","label":"Adoption signal","value":"1.9K downloads","href":"https://clawhub.ai/agentx-icu/tox-tunnel-ops","sourceUrl":"https://clawhub.ai/agentx-icu/tox-tunnel-ops","sourceType":"profile","confidence":"medium","observedAt":"2026-10-10T00:09:35.009Z","isPublic":true},{"factKey":"latest_release","category":"release","label":"Latest release","value":"0.4.14","href":"https://clawhub.ai/agentx-icu/tox-tunnel-ops","sourceUrl":"https://clawhub.ai/agentx-icu/tox-tunnel-ops","sourceType":"release","confidence":"medium","observedAt":"2026-08-31T14:07:30.591Z","isPublic":true},{"factKey":"handshake_status","category":"security","label":"Handshake status","value":"UNKNOWN","href":"https://www.xpersona.co/api/v1/agents/clawhub-agentx-icu-tox-tunnel-ops/trust","sourceUrl":"https://www.xpersona.co/api/v1/agents/clawhub-agentx-icu-tox-tunnel-ops/trust","sourceType":"trust","confidence":"medium","observedAt":null,"isPublic":true}],"changeEvents":[{"eventType":"release","title":"Release 0.4.14","description":"Tracks toxtunnel v0.4.13, and fixes 25 findings from an independent review of this skill. Three of those would have made an agent act wrongly. Static forwards bind 0.0.0.0, but the skill presented local_port as loopback-only, so following the SSH or database examples silently exposed the service to the LAN - now every generated forward carries local_address: 127.0.0.1 on v0.4.13+, with the firewall/SOCKS5 path for older daemons. verify.sh could exit 0 after verification failed, while the workflow treats it as the final check; it now has a three-state exit (proven / failed / NOT PROVEN) and the probes that only prove a local accept say so instead of claiming end-to-end success. And Revoke immediately routed to hot reload, which does not close live tunnels - that is now split into blocking new sessions versus terminating current access. v0.4.13 product changes reflected here: forwards take local_address (numeric IP literal; the daemon warns only when the key is absent and the bind is non-loopback), and config check now resolves known-servers aliases, so the old alias false-blocker is scoped to v0.4.12 and older rather than stated as current. diagnose.sh distinguishes the bind provenances instead of lumping them: an absent key, an explicit IPv4 wildcard, an explicit ::, a specific non-loopback interface and loopback each get their own treatment, and an invalid literal like * or [::] is reported as a config error rather than a bind. It also gained the portable timeout wrapper verify.sh already had, which was turning the inspect probe into a false warning on stock macOS. Two judgement calls. Tox IDs are no longer treated as secrets - they are public credentials like an SSH public key, the server is default-deny, and the old wording was unsatisfiable in its own workflow since server_id, rules.yaml and known_servers.yaml must all persist them; the prohibition moved to tox_save.dat, where an encrypted operator-controlled backup is the one legitimate copy. And the default install no longer pipes a master-branch script into sudo sh, while stating accurately that installing a package still runs maintainer scripts as root and that GitHub does expose a per-asset digest to compare against. templates/*.tpl.yaml are now actually published: they were named *.yaml.tpl, and the publishing CLI only uploads a fixed set of text extensions, so every prior version shipped without them.","href":"https://clawhub.ai/agentx-icu/tox-tunnel-ops","sourceUrl":"https://clawhub.ai/agentx-icu/tox-tunnel-ops","sourceType":"release","confidence":"medium","observedAt":"2026-08-31T14:07:30.591Z","isPublic":true}]}