codeagent

Warn

Audited by Snyk on Jun 19, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.70). The prompt includes explicit bypass controls (CODEX_BYPASS_SANDBOX, CODEAGENT_SKIP_PERMISSIONS and --skip-permissions) and a writable "develop" agent with Bash/Write tooling that enable and encourage bypassing permission/sandbox protections and making system changes, even though it does not explicitly request sudo or creation of system users.

Issues (1)

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 19, 2026, 05:20 PM
Issues
1
Security Audit — snyk — codeagent