evenhub-upload

Warn

Audited by Snyk on Jul 5, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.70). This skill instructs the agent to read and update an account-wide credentials file (~/.config/evenhub/credentials.yaml), refreshing and writing tokens back to the user's home, which modifies machine state and handles sensitive auth data (even though no sudo is requested), so it should be flagged.

Issues (1)

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 5, 2026, 01:14 PM
Issues
1
Security Audit — snyk — evenhub-upload