cawplan-ticket-report-generate
Warn
Audited by Socket on Aug 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s behavior is largely consistent with its stated QA-report purpose and its data flow appears limited to internal reporting endpoints, but it depends on an unresolved `cawplan` CLI trust boundary plus other external CLIs executed via Bash. Because a required, unverifiable CLI likely receives credentials/auth context for Portal access, this is a high security-risk skill even without evidence of confirmed malicious exfiltration.
Confidence: 85%Severity: 82%
Audit Metadata