ultrawork

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (medium risk: 0.40). The skill can perform background package/docker operations, search for sensitive "auth files", and even self-apply schema changes (modifying agent config/files), which could read or alter sensitive system state — but it does not explicitly request sudo, create users, or direct edits to systemctl/ssh/system files.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 01:11 AM