preflight-permissions
Warn
Audited by Snyk on Apr 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 0.90). This skill directs creation and import of a self-signed, trusted code‑signing certificate into the user's login keychain and changes persistent build signing/settings (modifying system trust and keychain state), which is a security‑sensitive, persistent modification of the machine even though it doesn't request sudo or programmatic TCC bypass.
Issues (1)
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata