CloverSec-CTF-Build-Dockerizer
Warn
Audited by Snyk on Mar 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill explicitly instructs the agent to execute local scripts, render/modify files (with --fix-write), run docker build/run and scaffold images that enable sshd/create users and change file permissions—actions that modify host filesystem and run privileged containers, so it can change the machine state and potentially introduce compromises.
Audit Metadata