devcontainer-workflow

Warn

Audited by Snyk on Feb 18, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 1.00). The prompt explicitly instructs creating system users, adding sudoers NOPASSWD entries, modifying groups/permissions, chowning files, and mounting the host Docker socket/SSH keys — all actions that change system state and can require or expose elevated privileges.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 18, 2026, 02:39 PM