commerce-app-review

Warn

Audited by Socket on Aug 22, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. Most local file reads and guideline fetches fit an Adobe app review skill, but the enrichment step forwards an Adobe IMS token to a less-verifiable `azurefd.net` endpoint. The capability mostly matches the purpose, yet credential routing is not sufficiently transparent, making the skill medium-high risk despite otherwise coherent scope.

Confidence: 84%Severity: 74%
SecurityMEDIUM
evals/files/security-issues-app/actions/get-catalog/index.js

No clear malware/backdoor behavior is present in this fragment, but it has serious security issues: hardcoded API credentials and unvalidated use of an externally supplied COMMERCE_URL to form the outbound request destination. If COMMERCE_URL can be influenced, the code can leak the embedded Authorization/X-Secret values to an arbitrary host. Additionally, error logging/return may expose sensitive diagnostic information.

Confidence: 84%Severity: 86%
Audit Metadata
Analyzed At
Aug 22, 2026, 11:09 PM
Package URL
pkg:socket/skills-sh/adobe%2Fskills%2Fcommerce-app-review%2F@134c8b2604ffd480edab06e1a08822ffc0f2e25301c4c441841f2ffa34217905
Security Audit — socket — commerce-app-review