nocobase-plugin-development
Warn
Audited by Snyk on Apr 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 0.80). The skill explicitly instructs the agent to run high-impact commands (yarn pm create and yarn pm enable) that create files in the user's project and modify database/plugin state — i.e., it directs the agent to modify machine/project state — so it should be flagged.
Issues (1)
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata