agent-development

Warn

Audited by Snyk on Mar 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (medium risk: 0.40). The prompt explicitly encourages granting agents Bash/Write/Edit tools, instructs them to "FIX issues found" and to modify user config files (e.g., ~/.bashrc, .claude/settings.json) and run shell commands, so it promotes autonomous modifications of the host environment even though it does not request sudo or system-level changes.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 03:48 AM