cawplan-coding-commit

Warn

Audited by Socket on Sep 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the workflow is broadly consistent with a reporting/upload skill, but its trust model is not. It relies on an unverifiable `cawplan` CLI for collection, browser assignment, report upload, and ticket updates, likely forwarding authenticated cloud actions and user/session data through a black-box binary. Purpose alignment is mostly coherent, but install/execution trust and hidden data-flow details elevate the risk substantially.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Sep 1, 2026, 02:23 AM
Package URL
pkg:socket/skills-sh/cawcut%2Fskill-cawplan%2Fcawplan-coding-commit%2F@ed26b5ebdd3eee9ff15d8a85c2893d08e7aff8a2b2a4001e50efb87388c3d81c
Security Audit — socket — cawplan-coding-commit