github-ssh-token-workflow
Warn
Audited by Snyk on Apr 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill instructs generating SSH private keys, modifying ~/.ssh/config, and sourcing/use of tokens from ~/.env (including non-passphrased keys), which alters persistent user files and credentials on the host and thus compromises machine state.
Issues (1)
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata