command-development

Warn

Audited by Snyk on Aug 19, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (low risk: 0.30). The document describes and permits running arbitrary bash commands (including examples with Bash(*) and executing plugin scripts), which gives the agent the capability to modify machine state, but it does not explicitly instruct obtaining sudo, editing system-level configs, or creating users—so the risk is present but indirect.

Issues (1)

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 19, 2026, 05:30 PM
Issues
1
Security Audit — snyk — command-development