commerce-app-review

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches submission guidelines from the official AdobeDocs organization on GitHub (raw.githubusercontent.com/AdobeDocs). This is a trusted source consistent with the skill author's vendor profile.
  • [COMMAND_EXECUTION]: The skill uses the 'aio' CLI tool to perform authentication and check for local environment setup, which is standard for Adobe Commerce development workflows.
  • [DATA_EXFILTRATION]: Audit results and IMS tokens are sent to a documentation API hosted on an Adobe-controlled Azure Front Door endpoint (commerce-docs-prod-endpoint-d0ctgyebe7bec8e6.a02.azurefd.net). This service provides enriched remediation guidance based on the audit results.
  • [CREDENTIALS_UNSAFE]: Hardcoded secrets are present in 'evals/files/security-issues-app/actions/get-catalog/index.js'. These are documented as test cases for the auditing logic and do not affect the skill's own security posture.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 01:43 PM
Security Audit — agent-trust-hub — commerce-app-review