task-manager

Warn

Audited by Snyk on Mar 4, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (medium risk: 0.60). The skill instructs the agent to modify files under /root/.openclaw (add/update task-queue.json) and run scripts that perform system actions (including SCP/cache purge), which changes the host's state even though it doesn't request sudo escalation or create users.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 4, 2026, 12:58 PM