cawplan-internal-qa-coding-humaninputs-sample

Warn

Audited by Socket on Sep 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose and capabilities mostly align, but trust is weakened by dependence on an unverified local `cawplan` CLI, possible transitive GitHub-based skill installation, and serving sensitive internal QA data via a plain local HTTP server. This looks more like an internal tooling skill with medium security risk than confirmed malware; the main concerns are install trust and data exposure, not overt exfiltration.

Confidence: 80%Severity: 62%
Audit Metadata
Analyzed At
Sep 1, 2026, 02:24 AM
Package URL
pkg:socket/skills-sh/cawcut%2Fskill-cawplan%2Fcawplan-internal-qa-coding-humaninputs-sample%2F@3a8abcf1918bff9155962c9a5326b4edb61f4ea71f5f18b30aaeb1f1d14b5ac1
Security Audit — socket — cawplan-internal-qa-coding-humaninputs-sample