NYC

asc-notarization

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (medium risk: 0.60). The skill instructs the agent to run commands that modify system trust/keychain settings and perform code-signing/notarization operations (including removing trusted certs), which change the machine's security state and may require elevated privileges, so it does push the agent to modify sensitive system state even though it doesn't explicitly request sudo or account creation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 12:20 AM