cawplan-coding-commit
Warn
Audited by Socket on Sep 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the workflow is broadly consistent with a reporting/upload skill, but its trust model is not. It relies on an unverifiable `cawplan` CLI for collection, browser assignment, report upload, and ticket updates, likely forwarding authenticated cloud actions and user/session data through a black-box binary. Purpose alignment is mostly coherent, but install/execution trust and hidden data-flow details elevate the risk substantially.
Confidence: 84%Severity: 82%
Audit Metadata