cawplan-product-insights
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to executecawplanCLI commands. These commands dynamically incorporate user-supplied parameters such as product names and date ranges, which are used to query external services. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external feedback and metrics sources, creating a potential vector for indirect prompt injection.
- Ingestion points: Data is ingested via the output of
cawplan metrics,cawplan analytics, andcawplan criticalas described inSKILL.md. - Boundary markers: Absent. The instructions do not specify the use of delimiters or provide the agent with guidance to ignore instructions embedded within the retrieved data.
- Capability inventory: The skill uses the
Bashtool to perform product searches and data retrieval operations. - Sanitization: Absent. There is no evidence of validation or filtering applied to the external content before it is processed by the agent to generate the final summary.
Audit Metadata