commercevault-edd-commerce-orchestrator
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill directs the user to clone a repository from
github.com/dhapat3927/mcp-edd-analytics-vantage.git. This source is a public repository managed by an individual user and is not associated with a verified or well-known organization. - [PROMPT_INJECTION]: The skill processes untrusted data from an external e-commerce platform, which creates a surface for indirect prompt injection.
- Ingestion points: Data is ingested from the WordPress Easy Digital Downloads REST API, specifically from fields such as customer names, emails, and order notes.
- Boundary markers: The skill documentation does not provide specific instructions or markers to distinguish between system prompts and external data retrieved from the API.
- Capability inventory: The skill possesses network capabilities to interact with the EDD API and Redis servers, and it can perform sensitive operations like order creation and license generation.
- Sanitization: There is no evidence of explicit sanitization or filtering of data retrieved from the API before it is processed or displayed in the agent's context.
Audit Metadata