High-risk tools in Xcode
5 of the 18 tools in Xcode are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
build_projectExecuteBuilds the active Xcode project using the specified configuration and scheme.
-
compile_asset_catalogExecuteCompiles an asset catalog using 'actool'.
-
run_lldbExecuteLaunches the LLDB debugger with custom arguments.
-
run_testsExecuteExecutes tests for the active Xcode project.
-
run_xcrunExecuteExecutes a specified Xcode tool via 'xcrun'.
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.