One interpreter, many script allowlists
Without launchers, every script shares the interpreter’s permissions. Launchers split that so an approved python3 cannot run an unapproved script.
Overview: Without Secure Script Launchers, every Python, Perl, or PHP script would share the interpreter’s permissions — if python3 is allowed to access the network, every Python script can access the network. Secure Script Launchers solve this by giving each script its own allowlist entry, so you control exactly what each script can do. The Dashboard presents this when script interpreters are detected on the system.
Secure Script Launchers is row 4 on the Lockdown Checklist. The Suggested Next Step stays on Launchers ([s]) while interpreters are pending. Skipping activation does not mark the row complete. Once launchers are activated, or the row is not applicable, the Suggested Next Step goes to File Access ([f]) if that queue still has items — see Allowlisting Basics.
Without launchers, every script shares the interpreter’s permissions. Launchers split that so an approved python3 cannot run an unapproved script.
Activate Secure Script Launchers for Python, Perl, and PHP so each script is reviewed on its own, not as the interpreter.
Secure Script Launchers included with Root Lock. The Dashboard offers them when it finds the matching interpreter.
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.