cawplan-plan-create

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a vendor-specific CLI tool (cawplan) to perform administrative tasks such as listing products, creating versions, and updating tickets. These operations are restricted to the functionality of the project management platform and are consistent with the skill's primary purpose.
  • [INDIRECT_PROMPT_INJECTION]: The workflow allows for the ingestion of untrusted external content in the form of pasted OKRs or stage goals to generate task lists.
  • Ingestion points: Pasted text input in Workflow B.
  • Boundary markers: The skill instructions do not specify explicit delimiters for the input text.
  • Capability inventory: The agent can create versions and tickets or update existing backlog items via the cawplan CLI.
  • Sanitization: The skill incorporates a mandatory preview step and requires explicit human confirmation before any execution commands are issued, effectively preventing the automatic execution of potentially malicious instructions embedded in the input data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:18 AM
Security Audit — agent-trust-hub — cawplan-plan-create