codex

Warn

Audited by Snyk on Feb 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.85). The skill explicitly instructs bypassing safety checks ("Always use --skip-git-repo-check"), endorses broad access modes (--sandbox danger-full-access, --full-auto) and suppresses stderr, which together push the agent toward bypassing security mechanisms and taking high-impact actions on the host.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 17, 2026, 10:18 PM