claude-code-reference

Warn

Audited by Snyk on Mar 9, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (medium risk: 0.40). The prompt does not explicitly instruct creating users or editing system-level configs, but it encourages granting broad Bash/Edit permissions (e.g. Bash(*), Edit) and documents modes like "bypassPermissions"/"dontAsk" that skip permission checks, which could enable system-modifying or privileged actions if misused.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 9, 2026, 01:29 AM