commercevault-edd-mcp-server

Warn

Audited by Gen Agent Trust Hub on Jun 30, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to clone a repository from an unverified personal GitHub account (github.com/dhapat3927/mcp-edd-analytics-vantage) as part of the setup process.
  • [COMMAND_EXECUTION]: The installation guide requires running 'npm install' or 'pip install' on external code and executing the resulting server with 'node' or 'python', which allows arbitrary code execution on the user's system.
  • [PROMPT_INJECTION]: The skill ingests untrusted data such as product titles, customer names, and order details from the EDD API. (1) Ingestion point: EDD_API_URL REST endpoint. (2) Boundary markers: None present to distinguish data from instructions. (3) Capability inventory: Access to store data, analytics, and order management. (4) Sanitization: No evidence of input filtering or escaping for data processed from the WordPress site.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 30, 2026, 02:55 PM
Security Audit — agent-trust-hub — commercevault-edd-mcp-server