cawplan-internal-qa-coding-humaninputs-sample
Warn
Audited by Socket on Sep 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's purpose and capabilities mostly align, but trust is weakened by dependence on an unverified local `cawplan` CLI, possible transitive GitHub-based skill installation, and serving sensitive internal QA data via a plain local HTTP server. This looks more like an internal tooling skill with medium security risk than confirmed malware; the main concerns are install trust and data exposure, not overt exfiltration.
Confidence: 80%Severity: 62%
Audit Metadata