cawplan-ticket-report-generate

Warn

Audited by Socket on Aug 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s behavior is largely consistent with its stated QA-report purpose and its data flow appears limited to internal reporting endpoints, but it depends on an unresolved `cawplan` CLI trust boundary plus other external CLIs executed via Bash. Because a required, unverifiable CLI likely receives credentials/auth context for Portal access, this is a high security-risk skill even without evidence of confirmed malicious exfiltration.

Confidence: 85%Severity: 82%
Audit Metadata
Analyzed At
Aug 28, 2026, 10:14 AM
Package URL
pkg:socket/skills-sh/cawcut%2Fskill-cawplan%2Fcawplan-ticket-report-generate%2F@a2bdcf87885a0a7b8d72d8a2998d12188b011316c7ff79c0b2de1745384fbc05
Security Audit — socket — cawplan-ticket-report-generate