copilot-cli
Warn
Audited by Snyk on Mar 4, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 0.70). This skill actively recommends running the Copilot CLI with permissive flags (e.g., --allow-all-tools, --allow-all-paths, --yolo) and even uses --allow-all-tools as the base example, which can enable broad filesystem and tool access able to modify system state—even though it also cautions to prefer least privilege.
Audit Metadata