skills/mukul975/anthropic-cybersecurity-skills/collecting-volatile-evidence-from-compromised-host/Snyk
collecting-volatile-evidence-from-compromised-host
Warn
Audited by Snyk on Mar 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 1.00). The prompt explicitly instructs running privileged live-forensic commands (e.g., insmod LiME, dd /proc/kcore, registry exports, mounting devices, creating evidence dirs) that require root/admin and modify kernel/system state, so it directs actions that change the host state.
Issues (1)
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata