cawplan-product-report
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is strictly scoped to using the
cawplancommand-line interface for reporting tasks. The workflows follow standard data retrieval patterns and include human-in-the-loop steps (asking the user to pick between multiple matches) for identity and product resolution. - [INDIRECT_PROMPT_INJECTION]: The skill processes ticket data, history, and user information returned by the
cawplantool (SKILL.md). While this represents a data ingestion surface, the risk is minimized as the skill does not possess high-privilege capabilities such as arbitrary network access or local file writing, and its output is primarily descriptive reporting.
Audit Metadata