Skip to content
Back to skills

Vpn Check

BSecurity

Verify that all torrent and Soulseek traffic goes through the ProtonVPN tunnel and cannot leak to the home IP, including the kill switch. Use when asked whether the VPN is working, whether torrents are safe or private, or after any change to gluetun, qBittorrent or slskd.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 1, 2026
devopspythongobashdockergitapi

Works with

  • cli
  • api

Security analysis

B84/100
  • mediumUses curl or wget to download content
  • criticalDownloads and executes remote scripts — classic supply chain attack

Pro shows the line behind each finding and how to fix it

Scanned October 1, 2026

npx -y skills add bugrauluyurt/homelab-media-stack --skill vpn-check --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Vpn Check?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Vpn Check
[![Security: B — Skills Directory](https://www.skillsdirectory.com/api/skills/bugrauluyurt-vpn-check/badge)](https://www.skillsdirectory.com/skills/bugrauluyurt-vpn-check)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: vpn-check
description: Verify that all torrent and Soulseek traffic goes through the ProtonVPN tunnel and cannot leak to the home IP, including the kill switch. Use when asked whether the VPN is working, whether torrents are safe or private, or after any change to gluetun, qBittorrent or slskd.
---

# VPN and kill-switch check

Read-only. P2P must never leave from the home IP, so treat any leak as urgent and
say so plainly.

## 1. Exit IP and forwarded port

```bash
STACK=${MEDIA_STACK_DIR:-$(git rev-parse --show-toplevel 2>/dev/null)}; [ -x "$STACK/scripts/stack-health" ] || STACK=~/homelab-media-stack
"$STACK/scripts/vpn-leak-test"
```

PASS means qBittorrent's public IP differs from the host's and matches gluetun's,
and Proton's forwarded port is wired into qBittorrent.

## 2. Structural checks (a snapshot can't prove these)

```bash
G=$(docker inspect -f '{{.Id}}' gluetun)
for c in qbittorrent slskd; do echo "$c: $(docker inspect -f '{{.HostConfig.NetworkMode}}' $c | grep -q "$G" && echo inside gluetun || echo NOT IN TUNNEL)"; done
docker exec gluetun wget -qO- -T 10 https://ipv4.icanhazip.com        # slskd shares this exit
docker exec qbittorrent curl -s http://127.0.0.1:8080/api/v2/app/preferences | python3 -c 'import json,sys;p=json.load(sys.stdin);print("bound:",p["current_network_interface"],p.get("current_interface_address"))'
docker exec qbittorrent sh -c 'curl -s -m 8 --interface eth0 https://ipv4.icanhazip.com && echo LEAK || echo "bypass blocked"'
docker exec gluetun sh -c 'iptables -S OUTPUT | head -1; cat /proc/sys/net/ipv6/conf/all/disable_ipv6'
```

Expected:
- Both P2P clients are inside gluetun.
- qBittorrent is bound to `tun0`.
- Going around the tunnel via eth0 is blocked.
- The firewall's default is `-P OUTPUT DROP` and IPv6 is disabled (`1`).

## Report

A table with each check against what's expected, then one conclusion. Mention
that the indexer searches (Prowlarr, the *arr apps, Byparr) are ordinary HTTPS from
the home IP and not P2P, unless the user has already chosen to route them through
the VPN. Don't change VPN settings without asking. The VPN must never exit in
the US; it uses `VPN_COUNTRIES` from `.env`.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…