cawplan-product-insights

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute cawplan CLI commands. These commands dynamically incorporate user-supplied parameters such as product names and date ranges, which are used to query external services.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external feedback and metrics sources, creating a potential vector for indirect prompt injection.
  • Ingestion points: Data is ingested via the output of cawplan metrics, cawplan analytics, and cawplan critical as described in SKILL.md.
  • Boundary markers: Absent. The instructions do not specify the use of delimiters or provide the agent with guidance to ignore instructions embedded within the retrieved data.
  • Capability inventory: The skill uses the Bash tool to perform product searches and data retrieval operations.
  • Sanitization: Absent. There is no evidence of validation or filtering applied to the external content before it is processed by the agent to generate the final summary.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:18 AM
Security Audit — agent-trust-hub — cawplan-product-insights