kcli-vm-operations

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.80). The skill includes explicit privileged host commands (e.g., "sudo virsh start/list", direct root SSH usage) and instructions that enable/modify services and inject files, which push the agent to perform privileged state-changing operations on the machine it runs on.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 10:44 AM