phase-running

Warn

Audited by Snyk on Mar 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.90). The skill authorizes an autonomous background agent to read arbitrary plan files, create/edit files, and run verification commands and fixes specified by the plan — enabling potentially system-level changes (e.g., editing privileged configs, modifying services, creating users) even though it doesn't explicitly mention sudo.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 02:19 AM