codex

Warn

Audited by Snyk on Mar 3, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (medium risk: 0.40). The prompt explicitly enables profiles that grant "network or broad filesystem access" and autonomous write/edit capabilities (including "danger-full-access"), which could modify the machine's state even though it does not explicitly request sudo, system configuration changes, or user creation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 3, 2026, 01:34 AM