k7-total-security-unlock-patch
Fail
Audited by Snyk on Jul 6, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.90). The repository explicitly advertises "unlock patches" / activation key tooling (license circumvention) and includes features that can exfiltrate sensitive data to third‑party endpoints (AI providers, webhooks, syslog/Elasticsearch) and auto‑generate executable containment scripts — together these indicate intentional malicious/abusive intent and high risk of data leakage or misuse.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 0.80). The skill provides CLI and code that run k7-console with administrative credentials, apply security profiles to endpoints, update feeds, and even generate PowerShell/Bash containment scripts (and references "unlock patches"), which instruct the agent to perform privileged changes to system/endpoint configuration and thus modify machine state.
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata