cawplan-internal-qa-coding-session-test
Warn
Audited by Socket on Aug 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s stated purpose is coherent and mostly read-only, but it depends on an opaque cawplan CLI that is not publicly verifiable from the provided evidence. The main risk is supply-chain and internal-data access through that unverifiable binary, plus moderate prompt-injection exposure from summarizing untrusted conversation content with Bash available.
Confidence: 84%Severity: 78%
Audit Metadata