codex-cli

Warn

Audited by Snyk on Mar 12, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (medium risk: 0.60). The skill explicitly enables and documents high-impact sandbox modes (workspace-write and especially --sandbox danger-full-access with --full-auto) that permit broad local and network changes which could modify machine state, even though it defaults to read-only and requires asking the user before using those flags.

Issues (1)

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 12, 2026, 12:04 PM
Issues
1