gentleman-e2e

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill's Dockerfile pattern creates a new user and explicitly appends a NOPASSWD sudoers entry (modifying /etc/sudoers), which grants passwordless sudo and modifies system-level files, so it instructs actions that can compromise the machine's state.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 10:43 AM