cawplan-product-report

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is strictly scoped to using the cawplan command-line interface for reporting tasks. The workflows follow standard data retrieval patterns and include human-in-the-loop steps (asking the user to pick between multiple matches) for identity and product resolution.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes ticket data, history, and user information returned by the cawplan tool (SKILL.md). While this represents a data ingestion surface, the risk is minimized as the skill does not possess high-privilege capabilities such as arbitrary network access or local file writing, and its output is primarily descriptive reporting.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 02:56 AM
Security Audit — agent-trust-hub — cawplan-product-report