task-manager
Warn
Audited by Snyk on Mar 4, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (medium risk: 0.60). The skill instructs the agent to modify files under /root/.openclaw (add/update task-queue.json) and run scripts that perform system actions (including SCP/cache purge), which changes the host's state even though it doesn't request sudo escalation or create users.
Audit Metadata