cawplan-ux-tracking

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses the cawplan CLI tool which is a well-known internal vendor resource for the 'cawcut' organization. All commands (cawplan tickets search, cawplan products list, cawplan versions list, etc.) are standard operational commands for fetching project metadata and ticket statuses.
  • [SAFE]: No external network requests are made outside of the documented cawplan toolset. No remote scripts are downloaded or executed.
  • [SAFE]: The instructions for data processing (resolving product names, matching IDs) use standard string matching and filtering logic without evidence of prompt injection or deceptive metadata.
  • [SAFE]: Secret management follows best practices, specifically instructing the user to avoid creating or updating tickets or setting statuses directly through these specific tracking workflows, and focusing only on retrieval/search operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:17 AM
Security Audit — agent-trust-hub — cawplan-ux-tracking