cawplan-internal-qa-coding-session-test

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose is coherent and mostly read-only, but it depends on an opaque cawplan CLI that is not publicly verifiable from the provided evidence. The main risk is supply-chain and internal-data access through that unverifiable binary, plus moderate prompt-injection exposure from summarizing untrusted conversation content with Bash available.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Aug 27, 2026, 01:27 AM
Package URL
pkg:socket/skills-sh/cawcut%2Fskill-cawplan%2Fcawplan-internal-qa-coding-session-test%2F@f46f34deb33cf8fd1e9bd8b6657dd737f3b0b4aac4ec67aaef7195d287385b54
Security Audit — socket — cawplan-internal-qa-coding-session-test