github-actions-workflows

Warn

Audited by Snyk on Mar 5, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.70). The skill includes explicit steps that write SSH private keys and kubeconfig into the runner's home (~/.ssh, ~/.kube), modify known_hosts and run SSH/remote commands and Terraform apply — actions that change local sensitive configuration and could compromise the host if executed by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 5, 2026, 02:08 PM