sonar-list-projects

Warn

Audited by Snyk on Jul 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.80). The skill tells the agent to invoke the sonar-integrate skill to install/update the sonarqube-cli and "re-configure the integration for this agent, including the SonarQube MCP server and secrets-scanning hooks", which directs the agent to perform system changes and installations that can modify the machine state and may require elevated privileges.

Issues (1)

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 15, 2026, 09:15 AM
Issues
1
Security Audit — snyk — sonar-list-projects