orbstack-cli

Warn

Audited by Snyk on Jun 19, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill instructs the agent to manage and modify OrbStack and its VMs (create/delete/clone/export/import, change config including engine JSON, restart services, factory reset, run commands as root) which can modify or destroy the host machine state and disable admin prompts, so it clearly pushes actions that can compromise the machine.

Issues (1)

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 19, 2026, 12:17 AM
Issues
1
Security Audit — snyk — orbstack-cli