credential-manager

Warn

Audited by Snyk on Feb 19, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.70). The skill instructs the agent to scan, create, modify, back up and delete credential/config files across the user's home (~/.config, ~/.openclaw, ~/.env), change file permissions and gitignore entries and enforce fail‑fast behavior — all actions that modify the machine's state and could materially alter or remove sensitive files even though they don't require sudo.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 19, 2026, 01:51 AM